The Missing Layer in Disinformation Resilience: Why Organisations Need the Ability to Prove What They Actually Said
From a hacked AP tweet that wiped $140 billion from the market, to deepfaked central bank governors, disinformation exploits the gap between what looks authoritative and what can be independently verified. A look at why proof-of-origin is becoming a necessary layer of institutional resilience.
Matthew Davis · · 8 min read
How long does a lie need to survive, before it stops mattering whether it was ever true?
The answer, of course, depends on the context, and on how convincingly the lie wears the signals of authority. Take a concrete case: in 2013, a single tweet falsely claimed that explosions had struck the White House. It took only minutes for automated trading systems to react to the claim, briefly wiping around $140 billion from the US market before it was disproved and the market recovered. What made the tweet so effective, however, was not its content, but as one account of the incident put it, “What jolted investors and traders was the source: The Associated Press, which describes itself as ‘one of the largest and most trusted sources of independent newsgathering.’ The tweet was sent from its ‘verified’ Twitter account” (Johnson, 2013).
Setting aside the economic fallout, one of the key issues that is raised by such events, revolves around the ‘trust’ dimension. As is still the case with many media platforms, ‘verified’ badges may make a message appear authoritative, but they do not give the reader independent evidence that either the account, or the individual post, is genuinely what it claims to be. In this case, the hacked AP account retained all the familiar signals of authority, even though the information it distributed was false.
These signals of authority, or ‘trust’, can be undermined in far less ‘official’ ways too. A recent report on information influence, economic disinformation and financial stability, provides several further examples of what this can mean for organisations and institutions in practice (see Almqvist, 2026). In one such case, false rumours that a Swedish bank operating in the Baltics was approaching bankruptcy spread through text messages and social media, contributing to Latvian customers withdrawing approximately 130 million SEK from their accounts (Ekman, 2012). And here, the bank did not necessarily need to be insolvent for the information to produce a real effect, it only needed enough customers to believe that others might act on the rumour, and therefore conclude that they should withdraw their own money first.
Malicious actors, unsurprisingly, will exploit whatever vulnerability presents itself: a logo can be copied, a website can be imitated, and even an executive's voice can be cloned. In another more recent case, deepfaked videos began circulating widely, showing the governor of Sweden's central bank endorsing a fraudulent high-yield investment scheme, and forcing the bank to release an official statement publicly warning the public not to invest money in it (Svergies Riksbank, 2025).
Taken together, these three cases arrive at the same underlying problem by rather different routes, and with rather different outcomes. The AP tweet and the Swedbank rumour caused real, measurable damage before they could be corrected, whereas the Riksbank case appears to have had limited impact, most likely because the bank moved quickly enough to warn the public. What unites the three is not the mechanism, nor even the outcome, but the underlying vulnerability: in each case, there was no independent way to establish, at the moment it mattered, whether the message in question could be trusted, and the usual signals of authority were either absent, imitated, or simply insufficient to settle the question.
Stepping back from the specifics, this points to something broader about how we tend to frame the disinformation problem in the first place. We often talk about it as though it were principally a problem of false content: a misleading post, a fabricated image, or an invented quotation. What the examples above suggest however, is a harder and less discussed problem underneath: the traditional signals we have relied upon to distinguish trustworthy information are becoming increasingly easy to imitate.
What happens when the line between authentic communication and fabricated content becomes difficult to establish in the first place?
Information that appears to come from a trusted source is, quite rightly, treated differently from an anonymous claim circulating online. Yet, as the cases above illustrate, the markers that once supported this judgement are no longer reliable on their own. Compromised social media accounts, fabricated press releases, and imitation news sites can introduce false information into the same channels through which authentic communication ordinarily travels, where an ever-hungry 24-hour news cycle may amplify it before its origins have been properly verified. And this is not only a question of separating true claims from false ones after the event; it is increasingly a question of being able to prove who originally published a piece of communication, and what it actually said, regardless of where it later resurfaces.
The general consensus is that institutions need to think about information integrity in broader terms; cybersecurity remains essential, of course, as do fraud prevention, staff training, and clear crisis communication procedures. However, as a recent lecture we attended on information warfare and business risk argued, neither technical measures nor communication measures are sufficient in isolation (Prokhorova, 2026). Institutions need technical security, media monitoring, source awareness, clear internal responsibilities, and a rehearsed crisis communication strategy. They also need to know who makes decisions, how an incident is escalated, and which channels will be used to communicate with the public.
What is notably absent from that list, however, is any means of proving, independently, that the communication itself is genuine once it is issued. A rehearsed statement, sent through the correct internal channels, is still only as credible as the signals the audience can use to verify it, and those are exactly the signals that a sophisticated incident is designed to imitate.
This is the broader problem space we are working on at Witnis. Our interest is in how public and institutional communication can remain connected to its authoritative source, as it travels between websites, newsrooms, social platforms, and AI systems. Verifiable communication does not replace cybersecurity, fact-checking, journalism, or crisis management, but it does provide an increasingly important capability within that layered response: a way to independently establish the provenance and integrity of important communication.
From our perspective, correcting false information and proving authentic information are related, but they are not quite the same thing. A correction asks an audience to accept a new statement in place of the false one, whereas verification should provide the evidence through which an audience can establish that the communication in question actually originated from the organisation represented. This distinction becomes especially important when an organisation's normal signals of authority are themselves under dispute, as was the case in our earlier examples.
At the same time, we also see a change across the broader information space that makes this issue somewhat more urgent. With the rapid rise of generative AI, people increasingly encounter institutional information through an answer that has already been summarised, translated, or combined with material from several sources. Even where the answer is broadly accurate, the connection between the claim and the original communication may be difficult for the user to see. And so, as this information moves through more and more intermediaries, source verification and machine-readable signals of authenticity become an imperative part of maintaining information integrity.
The relevant question for communication directors and institutional leaders is therefore along the following lines: if a plausible announcement appeared in your name tomorrow, how quickly could journalists, citizens, employees, or AI systems establish what you had actually said?
Could they verify the original communication without relying solely on its appearance? Could they distinguish an authentic news story from an altered copy? Would your organisation still be able to provide credible evidence if your social media account or website were itself a part of the incident? And is there a defensive capability incorporated into your crisis communication strategy, or would it need to be improvised once the false narrative had already begun to take hold?
This is not an argument for abandoning trust, nor for treating every institutional communication with suspicion; a society cannot function that way. It is, however, an argument for recognising that trust in a digital environment increasingly needs an evidential backstop; proof-on-demand, built in before it is ever needed, rather than improvised once a crisis has already begun.
Sources
- Almqvist, G. (2026) Informationspåverkan, ekonomisk desinformation och Sveriges finansiella stabilitet. Karlstad: Swedish Psychological Defence Agency. Available at: mpf.se (Accessed: 26 June 2026).
- Ekman, K. (2012). Swedbank-rykte utreds av polis, SVT Nyheter. Available at: https://www.svt.se/nyheter/inrikes/swedbank-rykte-utreds-av-polis (Accessed 26 Jun. 2026).
- Johnson, S. (2013). False White House tweet exposes instant trading dangers. Reuters. Available at: https://www.reuters.com/article/business/false-white-house-tweet-exposes-instant-trading-dangers-idUSBRE93M1FE/ (Accessed: 26 June 2026).
- Prokhorova, M. (2026) Information warfare and business risk: a strategic communication perspective. [Lecture], 25 May. Stockholm School of Economics, Stockholm.
- Svergies Riksbank. (2025) Varning för fejkade videor med riksbankschefen. [Press release], 25 August. Available at: https://www.riksbank.se/sv/press-och-publicerat/nyheter-och-pressmeddelanden/varning-for-fejkade-videor-med-riksbankschefen/ (Accessed: 27 June 2026).