Research Methodology and Attribution Standards
EK Strategies conducts open-source research into foreign information manipulation and interference, influence operations and related information threats. These standards explain how we define research scope, verify source material, distinguish observations from assessments, evaluate attribution and describe confidence.
About these standards
They apply to research articles, investigations, monitoring reports and data-led analysis published after 12 September 2026. Not every publication uses every method. Each substantial publication should disclose the scope, data window, collection method and limitations that are specific to that work.
These standards do not mean that EK can observe every relevant platform, channel or audience. They establish a minimum process for claims we choose to publish.
Definitions and applicability
We use FIMI as a behaviour-focused analytical concept. A false or politically aligned statement is not, by itself, evidence of a coordinated influence operation. We examine observable behaviour, infrastructure, distribution patterns, relationships and context before classifying activity.
An incident is a bounded set of observed activities. A campaign is a connected set of activities assessed to pursue a shared objective. Coordination is an assessment that actors or assets are acting in a connected manner. Attribution is the separate assessment that activity can be linked to a particular actor or controlling structure.
Where useful, we distinguish official, state-controlled, state-linked, state-aligned and unattributed sources. State-aligned describes repeated alignment supported by observable indicators; it is not equivalent to demonstrated control or attribution.
Scope and sampling
For each substantial study, we define the research question and the boundaries of the available dataset. Where it is material to the finding, we identify the observation period and time zone, countries or regions, platforms, languages, account or content types, and the unit of analysis.
Where it is relevant to the finding, we also describe how material was discovered, such as monitored channels, search terms, seed accounts, referrals, platform tools, APIs, third-party datasets or manual research, together with the inclusion and exclusion rules, the sample size and whether the analysis covers all accessible material or a selected sample.
Known gaps are part of the result. Closed groups, deleted posts, inaccessible archives, API restrictions, language limitations and uneven platform access may affect what can be observed. We do not generalise findings beyond the disclosed sample without additional evidence.
Source verification and evidence preservation
We seek the original document, post, account or earliest verifiable publication rather than relying on a repost. For evidence used in a material claim, we record the source URL or internal evidence identifier, account or publisher, platform, publication date and time where available, language, access date and relevant context.
Verification may include checking account identity, comparing independent sources, examining surrounding posts, validating quotations and translations, and reviewing available metadata. Image or video verification may include reverse search, geolocation, chronolocation or provenance checks when those methods are relevant and the available material supports them.
We preserve an internal copy or reliable archive where this is lawful, safe and proportionate. A screenshot without its source, timestamp and context is not treated as sufficient standalone evidence. When a source cannot be disclosed for safety or legal reasons, we explain the limitation and avoid presenting the claim as fully reproducible from public evidence.
Classification and attribution standards
Our analysis separates what is directly observed from what is inferred. We first document the asset, content, behaviour or technical relationship. We then assess whether the evidence supports manipulative behaviour, coordination, a shared campaign or attribution to a specific actor.
Attribution may draw on technical infrastructure, ownership and funding records, organisational relationships, official acknowledgements, historical continuity and repeated behavioural patterns. Content similarity, ideological alignment, simultaneous posting or mutual amplification alone is not sufficient to demonstrate common control.
For material attribution claims, we consider plausible alternative explanations and identify the evidence that strengthens or weakens them. Terms such as controlled by, orchestrated by, proven or confirmed are reserved for conclusions supported by direct and independently verifiable evidence.
Confidence language
We use confidence language to describe the strength of an analytical assessment, not the importance of the subject.
Verified or confirmed fact: directly observed or documented information that can be independently checked.
High confidence: multiple consistent and substantially independent indicators, including at least one strong form of linkage, with reasonable alternatives assessed as materially weaker.
Moderate confidence: the combined indicators support the assessment, but a direct link is incomplete or meaningful alternative explanations remain.
Low confidence or preliminary: limited or indirect evidence. We use this language only with an explicit caveat and where publication serves a clear public interest.
Unattributed or insufficient evidence: the available information does not support a responsible link to a specific actor.
We do not convert these terms into numerical probabilities unless a separately documented and calibrated model is used. Publications should briefly explain the evidence, the principal gap and what new information could change the assessment. The Research Editor, not the author, decides the confidence level applied to a publication.
Metrics, reach and impact
We distinguish activity from audience exposure and impact. Observed activity may include the number of posts, accounts, domains, platforms or repeated messages in the stated research window.
Potential reach is the audience to which content could theoretically have been available, often based on follower counts or similar proxies. It is not the same as views, impressions or unique people. Platform-reported views, reach and impressions are labelled as platform metrics and recorded with the date and known limitations.
Engagement describes interactions such as reactions, comments or shares. Amplification describes distribution across accounts, channels or platforms. Neither, by itself, demonstrates persuasion, attitude change or behavioural effect.
We use outcome or impact language only when the research design can evaluate a change in knowledge, attitudes, behaviour, policy or security and can address baselines, comparison and plausible alternative causes. Estimates, proxies and overlapping audiences are labelled and are not presented as unique observed reach.
AI and automation
EK may use automated tools to identify candidate material, remove duplicates, perform OCR, transcribe audio, support translation, cluster similar items or assist with preliminary coding. These tools help researchers organise evidence; they do not replace source verification or editorial judgment.
An AI output, automated classifier or synthetic-media detector is not used as the sole evidence for classifying activity, establishing coordination, identifying an author or attributing an operation. A human researcher reviews material claims, quotations, translations, classifications, citations and confidence language before publication.
Sensitive or protected information is not submitted to an external AI service without an approved privacy and security basis.
Ethics, safety and data minimization
We collect and retain only information necessary for the stated research purpose. Public availability does not automatically justify republishing personal data. We consider the public interest, the safety of individuals, the risk of amplifying harmful material and the needs of independent verification.
Where appropriate, we redact unnecessary identifiers, protect minors, vulnerable people and uninvolved third parties, and use archived or non-clickable references when a direct link could create a material safety risk. Retention, access controls and individual rights are governed by our Privacy Policy.
We avoid reproducing manipulative content more extensively than necessary to document the finding. Images, headlines and quotations should provide context without becoming an additional distribution channel for the material under examination.
Limitations, corrections and challenges
Every substantial publication should state the limitations that are specific to its data and method. A general disclaimer does not replace disclosure of missing platforms, incomplete archives, translation uncertainty, sampling bias or evidence that could not be independently reproduced.
We correct material errors transparently. A correction note should identify what changed, when it changed and whether the change affects the central finding or confidence assessment. New evidence may cause us to revise an attribution or confidence level while preserving a record of the earlier assessment.
Methodological questions, evidence-based challenges and correction requests may be sent to corrections@ekstrategies.org. They are reviewed by the Research Editor. A source’s failure to respond is not treated as confirmation of an allegation.
Evidence and citation practice
Material factual and attribution claims are cited at the point where they appear. Numbered references in the text link to a Sources entry that points to the primary material, with the publisher or platform and the publication date where these are known.
For social-media or Telegram material, the record identifies the account or channel, the stable post URL or post identifier, and the date, time and language where these are available. Secondary reporting may provide context, but it does not replace an accessible primary source for a key factual claim.
Governance and version history
The Research Editor owns these standards and coordinates review within our small research team. We review the methodology from time to time and whenever a material change occurs in our taxonomy, data sources, research tools, attribution process or legal and safety requirements. Where a change materially affects the interpretation of earlier work, we retain or describe the previous standard.
Version history
Version 1.0 — 12 September 2026 — Initial publication.
Contact and related policies
Questions about these standards or a specific methodological decision may be sent to corrections@ekstrategies.org.
Learn more about EK Strategies on our About page. Information about personal and research data handling is available in our Privacy Policy.