BlackCore: Inside the Alleged Israeli Influence-for-Hire Network Targeting Elections

BlackCore is an alleged Israeli influence-for-hire network linked to covert election campaigns using fake accounts, AI content, and deceptive websites.
Dark infographic showing user profile cards connected around a central target, with a crowd of people silhouettes below and a checklist panel on the right.
Contents

Updated July 21, 2026

BlackCore is the name of an opaque, apparently Israeli influence operation that French authorities have linked to covert attempts to manipulate political debate around the country’s 2026 municipal elections.

It does not appear to operate like an ordinary political consulting company. According to France’s foreign-interference watchdog, VIGINUM, the infrastructure associated with BlackCore was built to manufacture convincing online identities, create deceptive websites, infiltrate social-media communities, spread false allegations, coordinate thousands of interactions, and make political narratives appear more popular or organic than they really were.

The most disturbing part of the reported operation was not simply that it promoted one political position. French investigators concluded that the network appeared to manufacture both sides of a conflict: conservative or nationalist personas on one side and supposedly radical Islamist personas on the other. The objective was apparently to intensify hostility, frighten different communities, and make political division look larger and more dangerous than it actually was. (sgdsn.gouv.fr)

BlackCore has also been connected through overlapping accounts, infrastructure, or operating patterns to activity involving Scotland, Angola, Togo and the 2025 New York City mayoral election. Colombia’s outgoing president, Gustavo Petro, separately accused BlackCore in July 2026 of deploying hundreds of thousands of fake accounts during his country’s presidential election. That Colombian claim, however, has not yet been supported by a publicly released forensic report comparable to the French investigation. (sgdsn.gouv.fr)

That distinction matters. Some findings concerning BlackCore are supported by detailed technical evidence. Others remain reasonable investigative hypotheses. Still others are political allegations that have not been independently proved.

No responsible investigation should erase those boundaries.

The central findings

Based on the currently available evidence:

  • French authorities documented a real covert influence campaign. Six deceptive websites were supported by coordinated fake or misleading social-media accounts targeting French political candidates and communities.
  • The infrastructure was technically linked to BlackCore. VIGINUM found foreign technical indicators pointing toward Israeli operators and a wider network of influence-automation tools.
  • The legal entity behind BlackCore remains unclear. Investigators could not verify its corporate registration, owners, employees, precise operational structure or clients.
  • The French campaign appears to have had limited reach. VIGINUM classified it as foreign digital interference but reported that most of its content received very little authentic public attention.
  • No public evidence shows that BlackCore hacked voting machines or changed election results.
  • No public evidence establishes that the Israeli government directed the operation.
  • The identities of the people or organizations that paid for the French campaign remain unknown.
  • The Colombian allegation is serious but unverified. President Petro publicly accused BlackCore of deploying 500,000 bots, but no public technical dossier has yet demonstrated that attribution.

The resulting picture is troubling but incomplete: BlackCore appears less like a conventional company than an operational label attached to a concealed influence infrastructure whose true ownership and customers remain hidden.

What is BlackCore?

BlackCore presented itself online as an influence, cybersecurity and technology firm serving governments and political campaigns. Before its public website and LinkedIn presence disappeared, it reportedly described itself as an elite company built for modern “information warfare.” Reuters could not independently identify its owners, verify a headquarters or find a corresponding registration in Israel’s corporate records. BlackCore did not answer requests for comment. (The Times of Israel)

VIGINUM reached a similar conclusion. Its researchers identified a BlackCore domain registered in August 2025, several connected subdomains and promotional material describing services for governments. But the agency could not verify BlackCore’s legal status or determine whether it was a formally incorporated company, a project operated inside another company, a temporary brand or a front used by a collection of contractors. (sgdsn.gouv.fr)

That ambiguity may be intentional.

A conventional company leaves an accountability trail:

  • Corporate registrations
  • Named executives
  • Office addresses
  • Employees
  • Contracts
  • Tax filings
  • Publicly identifiable clients
  • Legal representatives

An influence operation benefits from the opposite. It can distribute different parts of a campaign among developers, content producers, advertising intermediaries, fake-account managers and subcontractors. Each participant can claim to understand only one narrow piece of the work.

The result is organized deniability.

What was Operation Rokh Solis?

In March 2026, VIGINUM detected a coordinated foreign information operation that it named Rokh Solis. The campaign targeted France’s municipal elections and initially revolved around four websites created within approximately ten days in February 2026. Investigators later connected two additional websites to the same broader operation. (sgdsn.gouv.fr)

The sites were not presented as openly partisan campaign pages. They were designed to resemble independent civic initiatives, investigative projects, local information outlets or community organizations.

They were then promoted through coordinated accounts on TikTok, Instagram, Facebook and X. These accounts displayed indicators of inauthenticity, including artificial profile photographs, inconsistent personal histories, synchronized behavior and repeated engagement with the same material. One website was supported by roughly 500 pages or accounts, according to VIGINUM’s analysis. (sgdsn.gouv.fr)

The campaign’s political targets

The operation focused heavily on politicians affiliated with the French left-wing party La France Insoumise, including municipal candidates or prominent figures connected to Marseille, Toulouse and Roubaix.

The deceptive content circulated severe accusations involving sexual crimes, violence, child exploitation, support for Hamas and other inflammatory allegations. In one case, the operation reportedly impersonated or appropriated the identity of a child-protection organization to make its content appear credible. (sgdsn.gouv.fr)

These were not ordinary political criticisms. They were accusations designed to trigger immediate moral disgust before readers had time to examine their origins.

A false claim about tax policy may persuade or confuse voters. A fabricated allegation involving rape, pedophilia or terrorism can socially destroy a person before any correction reaches the same audience.

Artificial credibility through search engines

The operators did not rely only on social media. VIGINUM reported that they paid a press-release distribution service to circulate an article promoting one of the deceptive sites. That content then appeared across a collection of legitimate-looking web properties and content aggregators.

This tactic exploits a common weakness in online information systems: repetition is often mistaken for verification.

A claim may begin on a fabricated website. A distribution service then republishes it across multiple domains. Search engines discover those copies. A person searching the accusation sees several results and concludes that different news organizations have independently confirmed it.

In reality, the apparent corroboration can all originate from one paid submission. (sgdsn.gouv.fr)

This is not merely search-engine manipulation. It is the industrial production of counterfeit credibility.

BlackCore’s apparent operating model

The French investigation provides a partial picture of how an operation connected to BlackCore may function.

1. Create synthetic people

The network used or developed systems capable of creating large numbers of online identities. BlackCore promotional material reportedly claimed access to approximately 1,600 “avatars” across Facebook, Instagram and TikTok.

In this context, an avatar is more than a profile picture. It can include:

  • A name
  • A fabricated biography
  • A geographic location
  • A political identity
  • A profile photograph
  • A posting history
  • Group memberships
  • Behavioral instructions

VIGINUM identified interfaces apparently built to generate and manage avatar data. One was labeled “Avatar Data Generator by Galacticos AI.” Investigators also found tools designed to help operators locate relevant Facebook groups using large language models. (sgdsn.gouv.fr)

The purpose is to make fake participants appear socially embedded rather than newly created.

2. Place the accounts inside real communities

A fake account becomes more useful once it enters an authentic community: a neighborhood group, religious discussion, local political forum, parent network or campaign page.

The account does not necessarily begin by spreading propaganda. It may first behave normally, comment on local issues or establish a believable history. When a political operation begins, the profile can introduce or amplify the desired narrative from inside a trusted environment.

That is more persuasive than an obvious advertisement because the message appears to come from another ordinary member of the community.

3. Build deceptive evidence

The operation can then create the material that the accounts will distribute:

  • Fabricated investigative websites
  • AI-generated images
  • Misleading videos
  • False civic organizations
  • Impersonated advocacy groups
  • Pseudo-news articles
  • Manufactured screenshots
  • Paid press-release placements

The fake accounts do not have to persuade people through argument. They can simply point to the manufactured material and say, in effect, “Look what has been uncovered.”

The website validates the account, and the account validates the website.

4. Manufacture engagement

Operators can coordinate likes, shares, comments and replies to create the appearance of public interest.

This practice is often called coordinated inauthentic behavior. Meta defines it primarily by deceptive coordination rather than by the political viewpoint being expressed. In other words, the problem is not that several people agree. The problem is that one hidden operator is pretending to be many independent people. (About Facebook)

Artificial engagement serves several purposes:

  • It can move content into recommendation systems.
  • It can make journalists believe a story is gaining traction.
  • It can pressure real users to take a claim seriously.
  • It can create the illusion of a social consensus.
  • It can intimidate political targets.
  • It can provoke genuine users into joining the conflict.

A small number of operators can therefore simulate a much larger public movement.

5. Manufacture both sides of the conflict

The most intellectually important finding in the French report is that the network did not appear to support only one political tribe.

VIGINUM identified two apparently antagonistic ecosystems. One portrayed itself as conservative, nationalist or concerned about Islamic extremism. The other presented itself as aggressively Islamist or communally radical. Investigators concluded that this opposition appeared staged and that both ecosystems were being used to intensify division around Muslims and French politics. (sgdsn.gouv.fr)

This reveals the difference between persuasion and destabilization.

A persuasion campaign wants people to believe a particular claim.

A destabilization campaign may be satisfied when people hate one another, lose trust in institutions and come to believe peaceful coexistence is impossible.

The operator can provoke one group with the fabricated behavior of another, then use the resulting anger as new content. Each side receives apparent proof that its worst assumptions about the other side were correct.

The conflict becomes self-sustaining even after the hidden operator withdraws.

The BlackCore-linked international footprint

VIGINUM’s investigation extended beyond the French municipal campaign. Researchers found overlapping infrastructure, accounts or behavioral patterns connected to several other countries.

These links differ in evidentiary strength. They should not all be treated as equally proved.

Scotland

VIGINUM identified coordinated activity targeting Scottish First Minister John Swinney, the Scottish National Party and Scottish government accounts between January and May 2026.

The report counted at least 256 accounts and approximately 1,400 comments. Hundreds of those comments were directed at Swinney and SNP-related accounts. French authorities concluded that this activity appeared connected to the same broader operating ecosystem. (sgdsn.gouv.fr)

That does not necessarily mean the operation had a major effect on Scottish public opinion. It does show that the network’s methods were not limited to one French election.

New York City

Some accounts examined in the French investigation had previously participated in Facebook groups connected to New York City and the 2025 mayoral election.

The accounts joined political and neighborhood groups and, in October 2025, two of them shared posts from Andrew Cuomo’s Facebook page. (sgdsn.gouv.fr)

This finding must be interpreted carefully.

It does not demonstrate that Cuomo, his campaign or anyone associated with him hired BlackCore. It does not establish what outcome the accounts were attempting to produce. It also does not prove that the activity changed the election.

What it establishes is narrower: accounts later identified as part of an inauthentic network had participated in political communities during an American municipal election.

That alone justifies further investigation, especially because U.S. law restricts foreign-financed election spending and foreign participation in election-related decision-making.

Angola

VIGINUM identified a cluster of approximately 48 accounts with Portuguese-language identities and apparently AI-generated photographs. The accounts coordinated their interactions and amplified material favorable to Angola’s government and the ruling MPLA party.

The BlackCore infrastructure also contained an “Angola plan” subdomain referring to training or operational activity involving the Angolan government. VIGINUM treated a direct client relationship as a hypothesis rather than an established fact. (sgdsn.gouv.fr)

The distinction is crucial. A technical artifact suggesting an Angola-focused project is evidence worth investigating. It is not, by itself, a verified contract or proof that a government official knowingly commissioned an illegal operation.

Togo and Gabon

The French report also identified signs of content-production work aimed at audiences in Togo and Gabon. These included outsourced AI-generated videos and infrastructure connections involving companies or domains within the same wider ecosystem. (sgdsn.gouv.fr)

Again, this supports the existence of a transnational influence marketplace. It does not automatically establish who paid for each campaign or whether every contractor understood the full operation.

The “Sadaqah Palestine” website

A server associated with the investigated infrastructure hosted a website called Sadaqah Palestine, presented as a charitable initiative for Palestinians.

VIGINUM found inauthentic multilingual comments, AI-generated profile images and similarities with accounts involved in the French candidate-targeting campaigns. (sgdsn.gouv.fr)

The public report does not prove that donations were stolen or establish a completed financial fraud. The defensible conclusion is that the pseudo-charity displayed technical and behavioral links to the influence infrastructure.

That is concerning because humanitarian causes provide emotionally powerful material for identity harvesting, audience building, political targeting and possible financial exploitation.

Colombia: a serious accusation that remains unproved

On July 10, 2026, Colombian President Gustavo Petro publicly accused BlackCore of interfering in Colombia’s presidential election. He alleged that the company deployed approximately 500,000 bots or false profiles to spread lies about Petro and left-wing candidate Iván Cepeda.

The allegation followed a narrow runoff victory by conservative candidate Abelardo de la Espriella. Colombian election authorities defended the security and transparency of the vote-counting system and rejected separate allegations involving unauthorized changes to election servers. (Anadolu Ajansı)

As of July 21, 2026, the publicly available evidence does not place the Colombian allegation on the same footing as France’s Rokh Solis investigation.

Petro’s accusation is politically significant, but the public has not been shown:

  • A list or representative sample of the alleged 500,000 accounts
  • Technical indicators connecting them to BlackCore
  • Domain-registration or server evidence
  • Platform findings
  • Payment records
  • Client communications
  • A forensic methodology
  • An independent government or judicial report establishing attribution

European Union observers had also rejected earlier, separate claims that Colombia’s first-round tabulation had been manipulated, describing the observed counting process as transparent and orderly. That finding does not disprove the possibility of a social-media influence campaign. It does demonstrate why claims about online propaganda must not be conflated with claims that ballots or voting systems were altered. (The Washington Post)

Three different questions must remain separate:

  1. Was misleading political content distributed online?
  2. Was it coordinated through fake accounts?
  3. Was the actual vote count compromised?

Evidence for one does not automatically prove the others.

The Colombian government, election authorities, social-media platforms and independent researchers should release enough evidence for outside experts to evaluate the BlackCore attribution. Until that happens, the responsible description is a major presidential accusation that has not yet been publicly substantiated.

Who is actually behind BlackCore?

VIGINUM mapped BlackCore into a broader Israeli cyber and influence ecosystem. Its report identified technical or professional connections involving names such as Galacticos AI, SNI, Iron Mind, Electric Marinade and Omri Systems.

Some of those entities apparently had identifiable legal existence. Others did not. Investigators found shared infrastructure, related tools, professional connections and overlapping technical markers. (sgdsn.gouv.fr)

These relationships are investigative leads, not a guilt map.

A domain sharing infrastructure with another domain does not always mean every associated person participated in the same operation. A developer may build a tool without knowing each customer’s purpose. An investor may have no operational role. A consultant may work on one lawful project while other people use related infrastructure for covert activity.

The proper investigative task is to determine:

  • Who registered and controlled each domain?
  • Who paid for hosting and advertising?
  • Who wrote or approved the campaign plans?
  • Who created and managed the fake accounts?
  • Who purchased the content-distribution services?
  • Which clients selected the targets?
  • Who authorized the false allegations?
  • Which participants knew the identities were fabricated?
  • Where did the money originate?
  • Which companies retained logs that can establish individual conduct?

Until those questions are answered, it is legitimate to investigate the ecosystem but irresponsible to declare every connected person criminally liable.

What has been proved, and what has not?

A useful way to understand the BlackCore story is to place its claims into evidentiary categories.

Documented by an official technical investigation

France’s VIGINUM documented:

  • Six deceptive websites associated with the French operation
  • Coordinated inauthentic accounts across multiple platforms
  • Fabricated or misleading allegations targeting politicians
  • Impersonation or appropriation of a child-protection identity
  • AI-generated visual material
  • Coordinated amplification
  • Paid online content distribution
  • A strategy involving staged ideological opposition
  • Technical indicators connecting infrastructure to BlackCore
  • Overlapping activity involving Scotland, Angola and other countries

These findings do not constitute a criminal conviction, but they are supported by a detailed government technical report. (sgdsn.gouv.fr)

Strongly supported but not judicially established

The available evidence strongly supports the assessment that:

  • BlackCore was associated with an influence-for-hire infrastructure.
  • The infrastructure was probably operated from or substantially connected to Israel.
  • Related accounts or technical systems were reused across national campaigns.
  • Operators were capable of managing synthetic personas and coordinating political engagement at scale.

These remain attribution assessments rather than findings from a completed criminal trial.

Alleged or unresolved

The public evidence does not yet establish:

  • The legal owners of BlackCore
  • The full list of employees or contractors
  • The clients who commissioned the French operation
  • The involvement of any Israeli government agency
  • The purpose or customer behind the New York activity
  • A knowing relationship with the Cuomo campaign
  • A confirmed BlackCore operation involving 500,000 Colombian accounts
  • The theft of charitable donations
  • The hacking of voting machines
  • A measurable change in any election result
  • Criminal guilt by every person or company in the wider technical ecosystem

These are not minor details. They determine who can lawfully be sanctioned, sued or prosecuted.

Did the French campaign actually work?

VIGINUM reported that the French assets received very limited visibility despite their artificial amplification. (sgdsn.gouv.fr)

That may seem reassuring, but reach is not the only measure of danger.

An unsuccessful burglary still reveals a burglar’s tools, methods and intended target. Similarly, a low-impact influence campaign can demonstrate an operational capability that may later be improved, sold or deployed during a more vulnerable political moment.

A campaign may also have secondary effects that are difficult to quantify:

  • A candidate is forced to respond to a fabricated allegation.
  • Journalists spend time investigating invented evidence.
  • Community organizations must deny involvement.
  • Search engines retain traces of the accusation.
  • Political activists repeat the content without knowing its origin.
  • Public trust falls even after the original story is debunked.

The absence of proven electoral impact should prevent exaggeration. It should not produce complacency.

Why BlackCore-style operations are dangerous to democracy

The democratic harm is deeper than “people might believe something false.”

Democracy depends on citizens being able to evaluate not only what is being said but also:

  • Who is speaking
  • Who paid for the message
  • Whether apparent supporters are real
  • Whether a controversy emerged naturally
  • Whether sources are independent
  • Whether political groups actually hold the positions attributed to them

A covert influence network counterfeits all of those signals.

It counterfeits identity

A fake account pretends that a real citizen exists where none does.

This is not comparable to lawful anonymity. A whistleblower or dissident may hide a real identity for protection. A synthetic political persona invents a person in order to deceive the public about the source and scale of political sentiment.

It counterfeits popularity

People use social proof to judge what deserves attention. A post with hundreds of supportive comments appears more credible and socially important than an identical post with none.

Coordinated accounts corrupt that signal. They make one operator look like a crowd.

It counterfeits independent confirmation

A deceptive website, fake civic organization, paid press release and coordinated social-media accounts can all cite or reinforce one another.

To an ordinary reader, this looks like evidence coming from several directions. In reality, the entire information chain may have been designed by the same operation.

It weaponizes moral urgency

Accusations involving children, sexual violence, terrorism or communal danger are chosen because they encourage immediate reaction.

The emotional intensity is not incidental. It reduces the likelihood that people will pause to verify the source before sharing it.

It converts political outsourcing into deniability

A campaign, government, wealthy individual or interest group may avoid direct responsibility by hiring an intermediary, which hires another contractor, which purchases technical services from still another company.

When exposed, every layer can deny knowledge of the others.

This creates a market in which the customer buys not only propaganda but distance from the propaganda.

It can turn pluralism into paranoia

The staged conflict identified by French authorities is especially corrosive. When the same operator manufactures both a threatening radical persona and the outraged response to it, citizens are no longer arguing with their actual political opponents. They are reacting to fictional extremists created to make compromise appear foolish or dangerous.

The operation does not merely enter a democratic conversation.

It secretly writes multiple characters in that conversation and then invites real people to fight them.

Why Americans should care

The United States is particularly vulnerable to commercial influence-for-hire operations because political communication is decentralized, social-media use is extensive and constitutional protections for speech are broad.

Those protections are essential. The solution cannot be a general government power to decide what is true and imprison people for political falsehoods.

The First Amendment protects a significant amount of false or mistaken speech. In United States v. Alvarez, the Supreme Court rejected the idea that false statements, simply because they are false, automatically fall outside constitutional protection. Narrower laws can still punish fraud, defamation, impersonation, threats and other conduct tied to identifiable harm. (Legal Information Institute)

That means American accountability must focus on conduct, not merely disliked content.

Foreign election spending

Federal law prohibits foreign nationals from making contributions, donations, expenditures, independent expenditures or related disbursements in connection with federal, state or local elections. It also prohibits foreign nationals from participating in certain election-related decision-making and bars others from knowingly providing substantial assistance. (FEC.gov)

A foreign influence firm secretly spending money to affect an American election could therefore create serious legal exposure, depending on the facts, intent and jurisdiction.

Knowing and willful violations can result in substantial civil penalties and, in qualifying criminal cases, imprisonment. But prosecution would require evidence showing who paid, who spent, what the expenditure supported and whether the defendants knowingly violated the law. (FEC.gov)

Foreign-agent disclosure

The Foreign Agents Registration Act, or FARA, requires certain people acting in the United States on behalf of foreign principals to disclose their relationships, activities, receipts and expenditures.

FARA does not automatically apply to every foreign company that comments on American politics. Its application depends on agency, direction or control, the activities performed, location, statutory exemptions and other facts. (Department of Justice)

Hacking, fraud, threats and identity crimes

Other laws may apply when an influence operation uses:

  • Unauthorized access to computers or accounts
  • Stolen identities
  • Fraudulent fundraising
  • Threatening communications
  • Criminal impersonation
  • Money laundering
  • Sanctions evasion
  • Forged documents
  • Trademark abuse
  • Defamatory factual accusations
  • Conspiracies to conceal illegal expenditures

The Justice Department has previously disrupted foreign influence operations through domain seizures, criminal indictments and charges based on offenses such as money laundering, unauthorized access, threats, sanctions violations and trademark-related fraud. (Department of Justice)

The legal principle is straightforward: the government should not invent a vague “bad information” crime. It should investigate the concrete acts used to produce, finance and conceal the operation.

Should everyone involved go to jail?

People who knowingly commit serious crimes should face prosecution, regardless of whether they are executives, political clients, account operators or technical specialists.

But imprisonment cannot lawfully begin with the conclusion that everyone associated with a company is guilty.

Criminal responsibility is individual. Prosecutors must prove:

  • The defendant’s identity
  • The acts the defendant committed
  • The defendant’s knowledge and intent
  • The applicable jurisdiction
  • Each required element of the offense
  • Guilt beyond a reasonable doubt

A person who knowingly invents rape accusations against political candidates is differently situated from a hosting provider that unknowingly rents server space. A client who orders illegal foreign election interference is differently situated from a graphic designer told that the work is for an ordinary advertising campaign.

Maximum accountability and due process are not opposing principles. Due process is what separates lawful accountability from political revenge.

The correct standard should be:

Investigate the entire network, preserve every available record, prosecute every provable crime, impose civil and commercial consequences where criminal elements cannot be established, and do not assign guilt merely through association.

What governments should do

1. Preserve the evidence immediately

Platforms, registrars, hosting companies, payment processors and advertising services may hold the records needed to identify operators and clients.

Governments should rapidly seek lawful preservation of:

  • Login records
  • IP histories
  • Account-creation data
  • Payment information
  • Advertising purchases
  • Domain-registration records
  • Internal platform messages
  • Device identifiers
  • Administrator permissions
  • Account-recovery information

Fake accounts can be removed publicly while relevant evidence is retained for authorized investigators.

2. Follow the money

Influence operations require infrastructure:

  • Hosting
  • Domain registrations
  • Contractors
  • Advertising
  • Account acquisition
  • AI services
  • Payment processing
  • Content distribution
  • Translation
  • Video production

Financial records may reveal the customer even when technical infrastructure is intentionally fragmented.

3. Coordinate investigations across borders

BlackCore-linked activity reportedly touched multiple jurisdictions. A server may be in one country, a contractor in another, a client in a third and the targeted electorate in a fourth.

National investigations conducted in isolation will repeatedly see only fragments. Prosecutors, election authorities, cybersecurity agencies and financial-intelligence units should create lawful mechanisms for rapid evidence sharing.

4. Require transparency from political influence contractors

Political consulting and public-relations companies operating across borders should face stronger disclosure rules when they use:

  • Automated accounts
  • Synthetic identities
  • Paid political influencers
  • AI-generated political material
  • Mass targeting
  • Covert community infiltration

The European Union’s political-advertising regulation already requires extensive sponsor, funding and targeting disclosures for covered political advertisements directed into the EU. It also restricts certain services involving third-country sponsors close to elections. (EUR-Lex)

Transparency rules will not eliminate covert operations, but they make lawful political communication easier to distinguish from concealed manipulation.

5. Exclude offenders from public contracts

A firm found, through a fair legal or administrative process, to have conducted covert election manipulation should not simultaneously receive government cybersecurity, intelligence, public-relations or defense contracts.

Possible consequences can include:

  • Procurement bans
  • License restrictions
  • Contract termination
  • Loss of government accreditation
  • Mandatory beneficial-ownership disclosure
  • Enhanced compliance monitoring

These measures can disrupt the commercial incentives behind influence-for-hire operations even when a criminal case is difficult.

6. Use targeted sanctions where authorized

Where evidence establishes responsibility for significant foreign election interference, governments can consider sanctions against identified individuals and entities.

Sanctions should be evidence-based and reviewable. Their purpose should be to restrict access to financial systems, travel, technology and government contracts—not to punish an entire nationality or industry.

7. Create civil remedies for victims

Political candidates, impersonated organizations and private citizens targeted with fabricated accusations should have realistic ways to seek:

  • Identification of anonymous operators through court process
  • Removal or correction orders
  • Monetary damages
  • Preservation of evidence
  • Disclosure of campaign sponsors
  • Recovery of litigation expenses in proven malicious cases

Speed matters. A legal remedy delivered two years after an election may vindicate a person’s reputation without repairing the democratic damage.

What technology platforms should do

Platforms routinely investigate coordinated inauthentic behavior, but the BlackCore case illustrates the limitations of platform-by-platform enforcement.

An operation can move among Facebook, Instagram, TikTok, X, websites, press-release services and search engines. Each company sees only part of the campaign.

Platforms should:

  • Share technical indicators associated with confirmed covert networks.
  • Preserve evidence for lawful investigation.
  • Label state-linked and commercial influence operations accurately.
  • Publish meaningful reports describing tactics and geographic targets.
  • Provide qualified independent researchers with privacy-protected access.
  • Detect clusters of AI-generated identities rather than evaluating accounts one at a time.
  • Examine coordinated behavior across accounts, pages, groups and external domains.
  • Maintain searchable political-advertising archives.
  • Notify users who interacted with confirmed covert operations.
  • Offer meaningful appeal systems to protect lawful activists and anonymous speakers.

Meta reportedly removed the France-focused network after identifying coordinated inauthentic behavior originating in Israel. Google and TikTok also identified or acted against portions of the operation. Those interventions are valuable, but public explanations remain necessary so researchers can distinguish routine moderation from evidence-based disruption of a coordinated network. (Journal Chrétien)

What journalists and civil society should do

Governments and platforms cannot be the sole guardians of political truth. They have their own interests, blind spots and potential for abuse.

Civil society can make influence operations less effective by changing how suspicious narratives are handled.

Investigate the distribution chain

Before reporting that a scandal is “going viral,” journalists should ask:

  • Where did it originate?
  • Which accounts first shared it?
  • Were those accounts created recently?
  • Do they behave independently?
  • Is the source a real organization?
  • Who registered the website?
  • Are apparently separate articles copies of one press release?
  • Is engagement authentic?

Reporting on a false campaign without explaining its manufactured reach can unintentionally provide the amplification the operators wanted.

Correct the mechanism, not only the claim

A correction should not merely say, “This allegation is false.”

It should explain how the deception was built:

  • The organization was fabricated.
  • The profile photographs were artificial.
  • The accounts coordinated their behavior.
  • The articles came from one paid distribution source.
  • The apparent ideological conflict was staged.

Teaching the mechanism makes readers more resistant to the next operation.

Protect independent researchers

Researchers who expose covert influence networks can face legal threats, harassment and account suspensions. Democracies should support transparent research access, strong anti-SLAPP protections and responsible security procedures.

Strengthen local journalism

Influence operations thrive in information gaps. When local reporting is weak, a deceptive website can more easily impersonate a community news source or civic organization.

Funding independent local journalism is therefore not merely a media-policy issue. It is part of democratic infrastructure.

The danger of treating this as an Israeli problem

The evidence points toward an Israeli commercial and technical ecosystem, but nationality is not the offense.

Israel has developed a large cybersecurity industry, most of which conducts lawful security, software and intelligence work. Israeli journalists have also helped expose controversial influence-for-hire businesses. The BlackCore investigation does not justify treating Israeli citizens, Israeli technology companies or Jewish communities as collectively responsible.

Nor does the available evidence establish that the Israeli government commissioned Rokh Solis. French authorities asked Israel for explanations and assistance, while Israeli representatives reportedly denied having an interest in interfering in French politics. The sponsor remained unidentified. (UOL Notícias)

The appropriate target is the conduct:

  • Concealed foreign political interference
  • Fabricated identities
  • Coordinated deception
  • Malicious impersonation
  • False criminal allegations
  • Undisclosed clients
  • Potentially illegal election expenditures

The same standards should apply whether the operator is Israeli, Russian, Iranian, American, Chinese, European or domestic.

BlackCore is part of a larger industry

BlackCore did not emerge in a vacuum.

In 2019, Meta removed hundreds of Facebook and Instagram assets connected to the Israeli company Archimedes Group. The network used fake accounts posing as local citizens and news organizations while targeting countries in Africa, Latin America and Southeast Asia. Meta reported approximately $812,000 in advertising spending and millions of followers across the removed assets. (About Facebook)

In 2023, the international “Story Killers” investigation exposed a separate Israeli group commonly called Team Jorge. Undercover reporting documented claims that the group had interfered in dozens of elections and offered hacking, sabotage and automated disinformation services. Some of the group’s claims could not be independently verified, and its leader denied wrongdoing. No public evidence establishes that Team Jorge and BlackCore are the same operation. (OCCRP)

These cases nevertheless reveal a recognizable market:

  1. Political actors want influence without attribution.
  2. Private contractors offer technical deniability.
  3. Synthetic identities create artificial constituencies.
  4. Cross-border structures make enforcement difficult.
  5. Failed campaigns disappear while successful methods are reused.
  6. The true customer remains hidden.

The democratic threat is therefore not one mysterious brand. It is the normalization of political deception as an export service.

Frequently asked questions

Is BlackCore a real registered company?

BlackCore operated publicly as a brand and maintained a website and LinkedIn presence. French investigators and Reuters were unable to verify a corresponding Israeli corporate registration, ownership structure or headquarters. It may have been a company, an internal project, a contractor collective or a front. (sgdsn.gouv.fr)

What did BlackCore allegedly do in France?

French authorities linked BlackCore infrastructure to deceptive websites, false accusations against political figures, coordinated fake accounts, AI-generated content, community infiltration and a strategy designed to intensify conflict around Muslims and French politics.

Did BlackCore hack French or American voting machines?

No public evidence reviewed for this article shows that BlackCore hacked voting machines or altered vote counts.

Did BlackCore change an election result?

That has not been established. VIGINUM reported that the French operation had very limited visibility, despite artificial amplification. (sgdsn.gouv.fr)

Who hired BlackCore?

The client or sponsor behind the French campaign remains unknown. Apparent links to specific countries or political environments do not, by themselves, identify the paying customer.

Was the Israeli government responsible?

No public evidence currently establishes that the Israeli government directed the operation.

Was BlackCore involved in the New York City mayoral election?

Accounts associated with the investigated network participated in New York political and neighborhood groups and shared political content during the 2025 election period. The evidence does not establish who directed that activity, what its objective was or whether any American campaign knew about it.

Did BlackCore operate 500,000 bots in Colombia?

President Gustavo Petro made that allegation in July 2026. No comparable public forensic investigation has yet demonstrated the claimed number or technically attributed the accounts to BlackCore.

Is using a fake social-media account always illegal?

Not necessarily. Legality depends on conduct and jurisdiction. A pseudonymous account used for privacy differs from a coordinated synthetic identity used for fraud, illegal foreign spending, threats, impersonation or other unlawful activity.

Can the United States prosecute a foreign company?

Potentially. Jurisdiction may exist when conduct targets U.S. elections, uses American infrastructure, involves U.S. financial systems, victimizes people in the United States or violates applicable federal statutes. A successful prosecution would still require identified defendants, admissible evidence and proof of each offense.

Final assessment

BlackCore should not be described as a proven all-powerful election-stealing machine. The public evidence does not support that conclusion.

It should be understood as something more precise and, in some ways, more instructive: an alleged influence-for-hire infrastructure capable of manufacturing identities, websites, political communities and artificial public reaction across national borders.

France’s investigation provides substantial evidence of a BlackCore-linked operation. It also leaves major questions unanswered. The company’s legal identity is unclear. Its clients are unknown. Its precise personnel remain unidentified. Some international connections are well supported, while others—most notably the Colombian allegation—require far more public evidence.

None of that justifies inaction.

Authorities should identify the human beings behind the accounts, preserve platform and financial records, trace the customers, prosecute every provable crime and impose serious civil, commercial and diplomatic consequences on entities shown to have knowingly participated.

But the goal must be justice rather than collective punishment.

A democracy cannot defend itself from manufactured reality by abandoning evidence, individual responsibility or due process. Those principles are not obstacles to accountability. They are the reason democratic accountability is worth defending.


References and further reading

Primary and official sources

Reporting on BlackCore

The wider influence-for-hire industry

Free speech and legal accountability

More to think on...