In tense political periods and during public debates on social networks, allegations of the use of fake profiles, automated accounts, and coordinated interventions aimed at influencing public opinion in the digital space are increasingly reported.
Recently, allegations of such activities have also been raised in Kosovo, in the context of the pre-campaign for the June 7 elections, where political actors have reported suspected interference in online public discussion, bringing back into focus the debate on the phenomenon of digital manipulation and the use of social networks as a space for organized influence on public opinion.
Democratic League of Kosovo (LDK) has expressed concern for what it calls an “organized cyber attack” and a coordinated campaign of digital manipulation against the public communication of its leader, Lumir Abdixhiku, as well as the call for a unity rally. In the response published on social media, the LDK claims that within a few minutes thousands of suspicious profiles and automated accounts have intervened in a synchronized manner on social media, with the aim of distorting public perception and creating “a false atmosphere of rejection and polarization”, describing this as part of what it calls “hybrid warfare” and propaganda operations in the digital space.
Likewise, the acting Minister of Justice, Donika Gërvalla, has declared that her official Facebook page has been targeted by a coordinated attack with thousands of fake profiles, which she says have used fake “hearts” to damage her reputation and create a manipulated impression on the platform. She announced that the suspicious accounts have been blocked, while Facebook has also been notified of the appropriate measures, emphasizing that “such attacks do not scare us and do not stop us,” at a time when, according to her, social networks are increasingly faced with the use of bots and automated accounts in political contexts.
Cyberattack or coordinated inauthentic behavior (CIB)?
In the technical-professional aspect of cybersecurity, the cases reported by LDK through its leader Lumir Abdixhiku, as well as by the acting Minister of Justice Donika Gërvalla, where thousands of suspicious profiles, "hearts" or automated reactions and synchronized interventions on social networks are spoken of, are not automatically classified as a "cyberattack" in the narrow technical sense.
Cybersecurity expert Halil Berisha emphasizes that "from a technical-professional perspective, simply sending a mass of fake reactions or comments is not automatically classified as a cyberattack. If there is no evidence of technical interference in systems, attack on accounts, viruses, phishing, botnets or DDoS, then the term 'cyberattack' is incomplete and inaccurate."
According to him, these cases mostly fall into the categories of manipulation of public opinion through digital means and inauthentic engagement. Also, platforms like Meta/Facebook address these phenomena through the concept of “Coordinated Inauthentic Behavior”.
On the other hand, professor at the Faculty of Electrical and Computer Engineering at the University of Pristina, Mërgim Hoti, in a technical assessment of the cases reported by LDK and the acting Minister of Justice, emphasizes that this is a form of digital manipulation that can fall into the category of cyberattacks in a broader sense, but not in the classic sense of interference in systems.
"This form of manipulation through fake profiles falls into the category of cyber attacks and manipulations, but not attacks that aim to stop the service or gain access to the service offered by the actors," said Hoti.
According to him, this is a sophisticated technique that uses bot automation to create coordinated accounts, which generate predetermined comments or reactions, often with negative content or oriented according to a certain data scenario.
"So, technically, it is categorized as an attack in the sense of manipulating semantics and public perception, but not as an attack that aims to interfere with or slow down the service," he adds, clearly distinguishing this phenomenon from traditional attacks such as DDoS, phishing or account compromise, which aim to block or gain access to the system.
So, according to professional assessments, these cases are more related to operations to influence and manipulate public perception in the digital space, rather than to classic cyberattacks aimed at compromising systems or technically interfering with them.
What is CIB?
In the digital age, social networks have become a central part of everyday life and have changed the way information is consumed and opinion is formed. However, this development has been accompanied by the growth of disinformation, often described through the concept of “Coordinated Inauthentic Behavior” (CIB), which refers to coordinated actions of accounts or pages that aim to manipulate public opinion through fabricated or artificially amplified content. Platforms such as Facebook, with billions of users, have become the object of these practices, where fake or automated accounts are also used to influence political and social debates. This has raised concerns about their impact on public opinion and democracy, making identifying and combating these phenomena a significant challenge in the digital space. (here)
In the way major digital platforms define it, the CIB phenomenon is treated as a form of coordination of accounts or actors that act covertly to deceive, manipulate, or influence public opinion. (here)
On the platform Meta (Facebook and Instagram), CIB is defined as a network of inauthentic accounts or “assets,” controlled by the same individual or group of individuals, that act in a coordinated manner to deceive the platform or community and evade enforcement of its rules. Meta does not have a specific mechanism for reporting CIB as a single phenomenon, but addresses it through reporting fake accounts, content that violates community standards, and general moderation tools.
At Google and YouTube, there is no unified definition of CIB, but the platform speaks of “coordinated influence operations,” especially when actors conceal their identities in political content or issues of public interest. YouTube and Google Search treat this as deceptive or disinformation behavior intended to manipulate users, and reporting is done through general mechanisms for violations of community guidelines.
On TikTok, CIB is primarily mentioned in the context of election integrity and covert influence operations, where networks of accounts collaborate to manipulate public discourse or platform systems. TikTok’s approach focuses on analyzing account behavior and identifying coordination, while reporting is done through general reporting features for content and accounts that violate community guidelines.
On X (formerly Twitter), the phenomenon is associated with “information operations,” “CIB,” and “influence campaigns,” while the platform’s policy clearly prohibits inauthentic activities, including the use of fake accounts, automation, and coordinated actions aimed at manipulating or harming public debate.
According to EU Disinfo Lab, Coordinated Inauthentic Behavior (CIB) is defined as a manipulative communication strategy that relies on the falsification of the distribution and amplification of content in a coordinated and non-organic manner. This practice can use authentic accounts, fake accounts, or a combination of both, while the circulation of content is always carried out in a coordinated manner, whether fully, partially, or even without automation.
Major digital platforms agree that the CIB phenomenon focuses on three main elements: first, COOrdiNATiON, where the activity is carried out through a network of accounts or pages that exploit social networking systems with the clear intent to deceive; second, inauthenticity, where malicious actors hide their real identity, location, or true intent; and third, the behavior, where the focus is on the manner of action and not necessarily on the content, which is not always false or in direct violation of the platform's rules.