Submit incident
Documented

Iran's Cotton Sandstorm Hijacked Streaming Services with Deepfake News Anchors

January 1, 2024
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiaaic:AIAAIC1392View source ↗
LinkedInX

What happened

In February 2024, hackers operating under the Islamic Revolutionary Guard Corps broke into streaming platforms serving viewers in the United Arab Emirates, the United Kingdom, and Canada and replaced live programming with fabricated news broadcasts. The segments featured a synthetic news anchor, built using AI, presenting unverified images that claimed to show Palestinian civilian casualties. Audiences in all three countries saw the content before any platform pulled it.

Microsoft tracked the operation and attributed it to a group it named Cotton Sandstorm. The company described the campaign as part of a broad and accelerating expansion of Iranian influence operations that began after the start of the Israel-Hamas conflict in late 2023. The choice of subject matter was deliberate. The Gaza conflict had drawn sustained global attention, and the hackers used that attention as framing for content that no news organization had sourced, reviewed, or sanctioned.

The synthetic anchor was the operational core of the attack. Deepfake technology applies machine learning to produce realistic video and audio of people who may not exist or who are not present. At the fidelity that tools can now produce, a viewer watching on a standard screen has no reliable way to distinguish a generated anchor from a real one. Cotton Sandstorm deployed that ambiguity inside a distribution channel that audiences associate with credentialed broadcast journalism.

The operation landed at a moment commentators found particularly dangerous. Dozens of national elections were scheduled globally in 2024, many in countries already contending with coordinated disinformation. Microsoft's analysis flagged this incident as one marker of AI becoming a meaningful accelerant in state-sponsored messaging. The concern was not speculative: the infrastructure had been penetrated, the synthetic content had aired, and the correction came after the audience had already been exposed.

What no platform in the three affected countries had at the time was a mechanism to verify the origin of what they were broadcasting. There is no current standard requiring a streaming service to confirm that a news segment it carries was produced by a credentialed source, reviewed by a human editor, or generated using declared methods. A provable record of what a system actually broadcast, who authorized it, and how the content was produced would not have prevented the intrusion, but it would have made the synthetic origin detectable immediately rather than after the fact, when the audience had already seen the anchor and taken the images as real.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AIAAIC Repository
Also catalogued in
Iran's Cotton Sandstorm Hijacked Streaming Services with Deepfake News Anchors
2024