You are currently viewing How Disinformation Evolved from a National Security Concern into a Strategic Business Risk

How Disinformation Evolved from a National Security Concern into a Strategic Business Risk

On June 12, 2026, SpaceX went public, in what was the largest IPO in history, raising roughly $75 billion and giving the aerospace company an initial valuation of $1.77 trillion, eclipsing Saudi Aramco’s 2019 record. Some believed the IPO had the potential to attract even further interest and capital had speculation that the company might list before any formal announcement not rattled investors. According to Bitdefender, fraudsters exploited market hype and investor expectations from the listing through scams and false information, in an effort to profit from the IPO even before the listing went live. Investigators saw familiar elements of an organised disinformation campaign.

That same month, in a very different news story, U.S. Director of National Intelligence Tulsi Gabbard, declassified documents relating to US funding of overseas biological laboratories. That decision followed a very public debate on the matter, fuelled by a longstanding Kremlin narrative alleging that Washington was conducting research into biological weapons targeting Russia. Whatever the true reason for the declassification, the episode demonstrated how a persistent false narrative can shape public debate and even, under certain circumstances, compel an institutional response. For Europe, where governments are increasingly concerned with foreign information manipulation and interference alongside conventional security threats, the commercial implications of such campaigns are becoming equally difficult to ignore.

The New Role of the Private Sector Puts It on the Menu

These examples show both the effectiveness of modern information warfare and its growing relevance to the private sector. The challenge is no longer confined to the circulation of a single false claim. Increasingly, malicious actors construct coherent narratives made up of mutually reinforcing claims, documents, articles and social-media posts. Their reach and credibility can build incrementally. These become far harder to counter once they have taken hold.

The commercial spillover from conflict often leaves companies operating in sensitive industries exposed. In this regard, the Atlantic Council has described the private sector as a “sixth domain” of warfare. In Ukraine, for example, private cybersecurity companies have played an important role in strengthening national defences and keeping essential information-technology networks functioning, and at the same time, found themselves on the receiving end of Russian information warfare tactics. European companies have become increasingly central to the same strategic ecosystem as the EU expands defence production, critical infrastructure protection and economic-security policy.

Sanctions create a further layer of exposure. Some companies are directly bound by particular regimes because of their jurisdiction, ownership or operations. Such differences can create commercial advantages and with that, competitive imbalances. They may also provide an incentive for state-backed actors and commercial rivals to portray a company as politically compromised, suspect, or non-compliant. And their efforts may succeed even if the underlying evidence is weak or fabricated.

The increasing ease and accessibility of generative artificial intelligence makes these methods even more of a threat. Creating and amplifying hostile content is easier than ever before. As the private sector retains its strategic role in future conflicts, these practices are likely to become more common. For the EU, this means that economic security and information security can no longer be treated as entirely separate policy areas.

The Convergence of National Security and Business Risk

As the boundary between national security and private enterprise becomes increasingly porous, threats to individual companies can quickly acquire wider strategic consequences. A PwC report described how cybercriminals replicated a US Department of Defense memorandum claiming that Broadcom’s proposed acquisition of CA Technologies had raised national-security concerns. The outcome of the false document was significant and contributed to declines in both companies’ share prices. The potential consequences are even greater today, given the scale of technology-sector valuations and acquisitions. Gartner has estimated that corporate spending on counter-disinformation measures will exceed $30 billion by 2028. Disinformation has therefore evolved from a conventional public-relations problem into a strategic business risk. That evolution also has implications for Europe’s wider push towards strategic autonomy, since companies expected to underpin defence, technology and industrial resilience are themselves increasingly exposed to information attacks.

A comparable case involved the French infrastructure group Vinci. In 2016, false press releases alleging accounting irregularities and the dismissal of the company’s finance director were distributed using impersonated email addresses. After the claims were repeated by news agencies, Vinci’s share price fell by more than 18 per cent before recovering following an official denial. The episode showcased how fabricated corporate documents can move markets, particularly when apparently credible information is circulated faster than the ability to verify or disprove that information.

Aviation and aerospace companies are especially vulnerable. The SpaceX example shows how excitement surrounding a prominent aerospace business can be exploited by fraudsters even when the company itself is not directly responsible for the misleading claims. The sector’s importance to defence manufacturing makes it an attractive target for such politically charged narratives.

The case of Aerospace Technical Services, known as ATS, an aviation company operating in the UAE and Jordan serves as a prime example. ATS and its chief executive, Mahdi Suliman Hamed Al Tahaineh, were targeted by a coordinated disinformation campaign alleging that the business had violated international sanctions regimes. The campaign reportedly included falsified documents, hostile online articles and the dissemination of inflammatory claims by third parties with a commercial interest in damaging the company.

The narrative also confused Aerospace Technical Services with an unrelated business trading under the name ATS Heavy Equipment. Beyond the similarity in their names, the two companies have no connection. This form of identity conflation is particularly difficult to counter online because repeated references can make unrelated entities appear connected. However implausible the allegation, they can nonetheless result in severe reputational damage.

The case of ATS illustrates the challenges that targets of disinformation often face. A targeted company may need to respond simultaneously through legal, regulatory, communications and digital channels, but there is no comprehensive framework through which victims can rapidly authenticate records or correct false associations with relevant authorities. Without such mechanisms, innocent targets can face significant costs in disproving allegations and restoring confidence.

Safety concerns further amplify the threat across aviation and aerospace. A false claim involving defective parts, for example by a commercial competitor, can easily disrupt complex supply chains. As a time-sensitive industry governed by strict manufacturing and certification deadlines, even unsubstantiated allegations may require systems to be suspended, potentially causing millions in daily losses.

To defend against these risks, companies need to treat information resilience as a core corporate capability alongside cybersecurity and physical-infrastructure protection. The present moment offers the European Union an opportunity to develop a more coherent response. The European Commission’s July 3, 2026, proposal to create five joint defence projects to strengthen Europe’s industrial capabilities could incorporate a counter-disinformation function focused on strategic industries. This could be embedded across the projects or established as a dedicated capability within the Eastern Flank Watch initiative. As Europe asks private companies to invest, expand production and accept greater strategic exposure, it must also provide mechanisms to help them withstand coordinated information attacks.