WHAT IS DISINFORMATION AND HOW CAN IT AFFECT DIFFERENT TYPES OF ORGANISATION?

One-minute read: An overview of what disinformation is and how it can affect private and public sector organisations.

A summary by Greydient Analytics

3/6/20234 min read

What is disinformation, and how can it affect different types of organisation?

Most organisations still treat disinformation as something that happens to societies and elections: a backdrop to the news rather than a line item on the risk register. That framing is the vulnerability. Disinformation is increasingly directed at organisations, by actors with specific intent, and it lands not on the network but in the information environment the organisation depends on.

The question is no longer whether false or weaponised information can reach an audience that matters to you. It demonstrably can, and the cases below show it has, moving share prices, emptying bank branches and setting infrastructure alight. The useful question is how it reaches different types of organisation, what it does when it arrives, and what preparation actually changes the outcome.

What disinformation is, and what it is not

Precision matters here, because the right response depends entirely on naming the thing correctly. The most workable model remains the information disorder framework, which separates three categories that are routinely, and unhelpfully, collapsed into one.

To understand more about how you or your company may be exposed to disinformation campaigns, please get in touch.

Disinformation is false information created and circulated with the intent to deceive or cause harm. Misinformation is also false, but shared without that intent, frequently by people who believe it and pass it on. Malinformation is the category most often missed: it is true information weaponised: a genuine document leaked at a damaging moment, a real quote stripped of its context, an accurate fact timed to maximise reputational injury. The distinction is operational, not academic. Correcting a falsehood and managing a true-but-damaging leak are entirely different problems.

It is also worth saying what disinformation is not. It is not a communications or public-relations problem, because PR functions are built to project a chosen message, not to detect an adversary shaping the field around it. And it is not a cyber-security problem, because the compromise occurs in the information domain rather than on the network: no system needs to be breached for a fabricated press release to move a share price. Treating an information-domain attack as either a comms wobble or an IT incident is how organisations lose the early, recoverable hours.

How disinformation reaches an organisation

A threat is easier to see once you understand its shape. We assess the attack surface across three dimensions: what is exploitable, who might use it, and how. The third dimension carries a point that is consistently underestimated: adversaries do not only distort what already exists. They fabricate. A press release that was never issued, an executive video that was never recorded, an event that never happened: the absence of any real underlying material is no protection at all.

The what includes leadership profiles, brand assets, market events, genuine-but-sensitive information, and prevailing sentiment about the organisation. The who ranges from competitors and activists to disgruntled insiders, financially motivated groups and state-aligned actors, each with different intent, capability and tolerance for exposure. The how spans coordinated inauthentic behaviour, narrative seeding and laundering, and increasingly synthetic media. Mapping that surface honestly is the starting point; it is the subject of our Online Attack Surface Assessment.

How it affects different types of organisation

There is no sector that is structurally immune, because the common factor is not industry: it is the presence of an audience whose belief or behaviour an adversary wants to move. That said, the mechanism of harm differs by organisation type, and recognising your own mechanism is half the battle.

Listed companies

Where value is marked to market continuously, a single fabricated claim can be priced in within minutes. The harm is fast, mechanical and sometimes irreversible in its second-order effects even after the price recovers: regulatory scrutiny, investor confidence and counterparty caution all outlast the intraday chart.

Banks, insurers and others built on confidence

Financial institutions are uniquely exposed because their stability is partly a belief. A rumour that enough customers act on can become self-fulfilling, regardless of the institution's actual position. The information attack does not need to be true; it only needs to be believed for long enough to change behaviour.

Consumer brands, pharma and regulated manufacturers

Here the target is trust in the product or the company's intentions. A fabricated claim about safety, pricing or conduct can trigger boycotts, regulatory questions and lasting brand damage, and the correction rarely travels as far as the original.

Critical infrastructure and public bodies

When disinformation attaches to infrastructure, the consequences can leave the screen entirely. Conspiracy narratives have produced physical attacks on equipment and abuse of frontline staff: an operational and safety problem, not merely a reputational one.

SMEs, NGOs and charities

Smaller organisations are not too small to be targeted; they are often less able to absorb the hit. A single coordinated campaign can consume the leadership of an organisation that has no dedicated function to meet it, which is precisely why preparation, rather than scale, is the determining factor.

The cases, and what they cost

Each of the following is a documented disinformation or influence operation against a real, recognisable organisation: fabricated or weaponised information aimed at shaping perception and behaviour, not a fraud carried out by other means. Each was reported by mainstream media, and several by financial regulators or threat-intelligence teams. They span 2016 to 2024, and the trajectory matters as much as any single example: the World Economic Forum's Global Risks Report has, in both 2024 and 2025, placed misinformation and disinformation among the most severe short-term global risks facing the world.

A fabricated press release, sent from a spoofed email domain and linking to a mirror of Vinci's own website, claimed the French construction group was sacking its CFO and restating its accounts for accounting irregularities. Bloomberg and other agencies relayed it before verifying it.

The release was entirely invented. No breach occurred: the attackers impersonated the company rather than hacking it. The apparent motive was activist protest against Vinci's operations abroad.

Recorded impact

Shares fell more than 18% intraday, with trading briefly suspended, before closing roughly 4% down, momentarily wiping an estimated $5bn of market value. France's market regulator (AMF) later sanctioned Bloomberg for relaying the hoax; the fine was reduced to €3m on appeal.

Construction

Company: Vinci

November 2016

Contact us

Whether you have a request, a query, or want to work with us, use the form below to get in touch with our team.