The Threat Briefing
From Stasi to scale
The Stasi's Zersetzung, the covert dismantling of a person's life, was a craft: a dedicated team of officers, an informer network years in the making, one target at a time. Artificial intelligence could extend that craft through automation, synthetic content, and faster coordination. This briefing sets out what changes, capability by capability, and what the evidence currently supports.
01 · The Transformation
What the Stasi needed, and what an algorithm needs
A sustained operation in East Germany drew on officers, informers, surveillance, and repeated human decisions. By 1989 the Stasi employed roughly 91,000 full-time staff and relied on about 189,000 unofficial informers. Every target cost the Stasi people and time, and that cost limited what it could attempt.
Digital data, synthetic media, and automated messaging can reduce the effort needed for parts of a campaign. An attacker still needs reliable information about the target, a way to influence their environment, and effective coordination. Each remains a significant constraint.
02 · Capabilities
The six capabilities
These capabilities each open a plausible route to misuse, though they differ in how available, accurate, and effective they are. Combining them into a sustained campaign against a particular person remains a scenario. The evidence does not yet show that anyone has done so, or with what effect.
1 · Psychological profiling
From a person's posts and other accessible data, an attacker can infer their interests and relationships. Those inferences can be wrong, and sensitive information is not always within reach. Recent research is testing how far that limit still holds: language models can now link pseudonymous accounts to real identities at a cost of a few dollars each (see Developments).
2 · Synthetic media
Fabricated audio, video, and imagery can simulate a betrayal, manufacture an indiscretion, or place words in a mouth that never spoke them. To fake a compromising photograph, the Stasi had to stage the encounter; generative models produce tailored fabrications on demand. And beyond any single forgery lies the deeper injury: the corrosion of trust in recorded reality itself, which taints even authentic evidence.
3 · Coordinated inauthentic behaviour
Networks of synthetic personas can manufacture the appearance of organic social rejection — the pile-on, the quiet unfollowing, the consensus that someone is "difficult" or "unwell". Where the Stasi positioned informers inside a target's circle, a modern operation can surround the circle itself and turn the person's own community into the delivery mechanism.
4 · Algorithmic manipulation
Interference with what a target sees — feeds, search results, recommendations — can distort their picture of the world without a single fabricated artefact. Such a curated reality would arrive through channels the target has every reason to trust, updated continuously, and invisible to anyone standing beside them looking at a different screen. Researchers have now demonstrated how a page's content could be altered on one person's screen (see Developments).
5 · Social graph disruption
Knowing who a target is close to could help an attacker choose which relationships to disrupt. Which relationship matters most, and what disrupting it would do to the person, are both hard to predict.
6 · Closed-loop adaptation
An automated campaign could watch how its target responds, through signals such as their posting activity, and adjust its next move. Those signals are imperfect guides to the target's state of mind, and nobody has shown that such feedback gets the operator the effect they want.
03 · Force Multipliers
Three properties change the threat class
Cost collapse
Parts of what once required a state security budget can now be assembled from commodity tools. The capability floor may drop from "intelligence agency" towards "any actor with modest resources and a grievance".
Many targets at once
Zersetzung worked one target at a time. Automation could let an attacker run more operations side by side. The evidence cited here does not show how far that scales, or whether sustained, individually tailored campaigns would stay effective across many targets.
Deniability squared
Zersetzung was deniable because acts looked like misfortune. AI-enabled operations add a second layer: even when a pattern is found, attribution to an operator can be forensically hard.
Attribution requires connecting incidents to an operator and testing alternative explanations. Automation may complicate that work, but it can also leave technical records useful to investigators.
04 · The Evidence
What is documented, and what is inferred
The sources summarised below document coordinated harassment campaigns, psychological operations in hybrid warfare, unsafe responses from AI companions in testing, and automated unmasking of pseudonymous accounts. They do not establish an integrated, closed-loop system conducting individually targeted psychological decomposition at scale.
- Documented: coordinated harassment and intimidation campaigns against journalists, researchers, and public figures, combining doxxing, impersonation, synthetic imagery, and inauthentic amplification — reported by press-freedom and platform-integrity investigations across multiple countries, among them the ICFJ and UNESCO global study The Chilling.
- Documented: psychological operations in contemporary hybrid warfare, including targeted intimidation of named individuals and their families.
- Documented: unsafe responses when researchers posing as teenagers tested consumer AI companions, including sexual content and discussion of self-harm, violence, and drug use. Stanford Medicine's account reports the testing separately from individual cases of harm.
- Documented: language models linking pseudonymous accounts to real identities, and to each other, at a few dollars per profile and with high precision. The research is summarised under Developments below.
- Inferred: the integration of these components into closed-loop, individually targeted campaigns at scale. This is the trajectory the Psychosecurity Framework exists to get ahead of, not a documented present.
05 · Developments
Ongoing developments to watch
A running record of research that changes what the capabilities above cost, or how well they work. Each entry is a published result or demonstration, reported with the authors' own caveats. None shows a psychological campaign being run against a person; together they show the groundwork getting cheaper and harder to see.
Inferring personal attributes from ordinary posts. Researchers at ETH Zurich found that language models could infer attributes such as location, income, and gender from real Reddit profiles, with up to 85% top-1 accuracy, at about a hundredth of the cost and a 240th of the time a human analyst would need. Text anonymisation and model alignment did little to prevent it. Staab et al., Beyond Memorization, ICLR 2024. Capability 1: profiling.
Automated profiling feeds personalised deception. In a study with 101 participants, AI agents built profiles of targets from public information that were accurate and useful in 88% of cases, then wrote spear-phishing emails. The fully automated emails drew the same 54% click-through rate as those written by human experts, against 12% for generic phishing. Heiding et al., Evaluating Large Language Models' Capability to Launch Fully Automated Spear Phishing Campaigns. Capability 1; force multiplier: cost collapse.
Redacted interviews re-identified. Anthropic published partially redacted transcripts of interviews with scientists about their use of AI. An off-the-shelf agent with web search linked six of twenty-four transcripts it was run on to the participants' published work. Li, Agentic LLMs as Powerful Deanonymizers. Capability 1.
Pseudonymity stops being protection. Researchers at ETH Zurich, with MATS and Anthropic, showed that language models can unmask pseudonymous accounts at scale from what people write, with no structured data needed. Given only a summary of someone's posts, a web-searching agent identified 226 of 338 Hacker News users (67%) at 90% precision, for $1–4 per profile, in minutes rather than the hours a human investigator would need. It also identified an estimated 9 of 33 genuinely anonymous interview participants. A separate pipeline that matches accounts to each other across platforms reached up to 68% recall at 90% precision, and still found about 55% of matches among 89,000 candidates; the classical method it replaces scored near zero. The authors caution that their test profiles, drawn from users who had once linked their real identity, are easier to unmask than accounts kept carefully anonymous. They conclude that "the practical obscurity protecting pseudonymous users online no longer holds", and they did not release their code. Lermen, Paleka et al., Large-scale online deanonymization with LLMs, USENIX Security 2026. Capabilities 1 and 5; force multiplier: cost collapse.
Rewriting what appears on the screen. The security researchers behind nDiligence's Attack the Glass project describe a class of attack in which a compromised third-party script, loaded by a site people trust, changes what the page displays just before it reaches the screen. Their twenty demonstrations, all set in invented organisations, include a news story rewritten for one reader, a payment approved for one amount and sent for another, a prescription showing the wrong dose, and an election results page on which every number is correct but the layout points to the wrong winner. According to the researchers, the changes take place in the device's memory and disappear when the display moves on, leaving neither the reader nor the site's operator a record. The work is self-published and reports no confirmed cases in the wild; the authors say they have no fix for it and are not selling one. nDiligence, Attack the Glass and its demonstrations. Capability 4: algorithmic manipulation; force multiplier: deniability.
The unmasking results matter most to the people pseudonymity has long shielded: dissidents, abuse survivors, whistleblowers, and anyone keeping a sensitive part of their life apart from the rest. If the effort that kept them hidden now costs a few dollars, it can no longer be relied on as protection, and the defences built around it need rethinking.
Continue reading: the agent inside — when the attacker holds your credentials →