Episodic vs Industrial Disinformation
In short. Episodic disinformation is a single, point-in-time attack, such as the deepfake video call that tricked engineering firm Arup into transferring US$200 million. Industrial disinformation is a sustained campaign of false narratives spread in the market over time, often by a professional disinformation-for-hire industry. Gartner's Dave Aron says the two demand different defences.
Episodic: the $200 million deepfake call
The vivid version of disinformation is the one-off con. Gartner’s Dave Aron, co-author of World Without Truth, tells the story of Arup, a British design and engineering firm. Someone in their Hong Kong office was asked to join a video conference and, by the end of it, “was tasked with transferring $200 million to a third party.” The catch: “no one else on that video conference was a real human. They were avatars powered by AI that were convincingly behaving as their colleagues.”
That is episodic disinformation, in Aron’s words “a single episode,” and as he notes, “in a way it’s a little bit similar to a cyber threat.” It is point-in-time, it targets a specific decision, and the defences are recognisable: content authenticity and deepfake detection, plus process controls on high-value actions.
Industrial: the slow narrative
The kind most companies never see coming is the other one. Industrial disinformation, Aron says, “is a completely different animal. It often happens completely outside your company,” as “narratives spread in the market that say things that are wrong or unfair or bad that cause damage to you, your company, your executives, your industry, your country.” It is the disinformation that happens beyond your firewall.
His example is the campaign against plant-based meat: a series of messages, “even a Super Bowl advert,” pushing the line that plant-based proteins are unhealthy or part of a conspiracy. No system was breached. No single moment gave it away. The narrative simply accumulated until it shaped how a market thought, the way a manufactured boycott does.
Not a teenager in a hoodie
The instinct is to picture a lone troll. Aron corrects it directly: this is “not conducted by a teenager in a hoodie in their bedroom.” The disinformation industry, he says, “is actually a very serious industry that allows people to create these industrial disinformation campaigns through shell companies, anonymously, over time,” and to be “very, very effective.”
That professionalisation is the part boards underestimate. Industrial disinformation is a service you can buy: persistent, deniable, and engineered to look organic. It is an adversary with a business model, not a prank, and one of three distinct layers of enterprise narrative risk.
Why the difference matters for defence
The two attacks fail differently, so they have to be defended differently. Episodic attacks are about authenticity in the moment: is this video, voice or document real, and should this transaction proceed. Industrial attacks are about coordination over time: is this surge of “organic” sentiment actually an orchestrated campaign.
Most monitoring tools are built for neither. Social listening reads content and sentiment, so it tells you what is being said and how loudly, but not whether the volume is manufactured. By the time an industrial campaign registers as a sentiment spike, it has already done its work.
Where AI Uniti fits
AI Uniti is built for the industrial kind, the domain of narrative threat intelligence. Signal monitors narratives across platforms and scores the coordination behind them, the timing, network and account behaviour that betray an orchestrated campaign rather than an organic one, and raises explainable alerts 6 to 12 hours before content-led monitoring sees a spike. PulseCheck identifies the inauthentic accounts doing the amplifying on a bot-to-human spectrum. The method is behavioural: we read the coordination, not just the words, which is exactly what an industrial campaign is designed to hide.
For the episodic, deepfake side, content-authenticity detection is the right tool, and it is on the AI Uniti roadmap as a corroborating signal: a coordinated cluster amplifying synthetic media is a stronger, more explainable verdict than either signal alone. Authenticity confirms the media; behaviour confirms the campaign.
The attack you will not see in your logs is the one spreading in the market. See how Signal detects industrial disinformation 6 to 12 hours early, or book a 15-minute demo.
Frequently Asked Questions
What is the difference between episodic and industrial disinformation?
Episodic disinformation is a single, point-in-time attack targeting a specific decision, like the deepfake video call that cost Arup US$200 million. Industrial disinformation is a sustained campaign of false narratives spread in the market over time, often by professional operators. Gartner's Dave Aron distinguishes the two because they need different defences.
Is deepfake fraud the same as a disinformation campaign?
No. A deepfake fraud is usually episodic: one convincing fake aimed at one transaction. A disinformation campaign is usually industrial: many coordinated messages over time shaping how a market thinks. They overlap when a campaign amplifies synthetic media.
Who runs industrial disinformation campaigns?
Per Aron, a professional industry, not lone actors: operators who run campaigns through shell companies, anonymously and persistently, and sell the service. It is an adversary with a business model.
Why doesn't social listening catch industrial disinformation?
Because it reads content and sentiment, not coordination. It can tell you a narrative is loud, but not that the volume is manufactured. Behavioural detection reads the orchestration itself, which is what surfaces the attack early.