European UnionFunded by the European Union · Horizon Europe · GA 101132671
FIMI Attribution Event Dataset · Deliverable D4.2 · release v2.4.3

The DE-CONSPIRATOR FIMI Attribution Event Dataset

The dataset records 3,029 incidents of foreign information manipulation that 97 European and allied institutions attributed in 534 published documents. Each record carries the source document, the page and the sentence that support the attribution. The dataset measures how European institutions attribute: which institutions publish, how quickly, about which targets and actors, and how often they corroborate one another. It does not measure how much manipulation takes place.

3,029 incidentsDISARM-codedquotation on every record1903 to 2026open data · CC BY 4.0
Scope of the data. An incident enters the dataset when an institution detected it, judged the evidence sufficient and published an attribution. Every distribution on this page therefore describes the published record of European institutions. A country with many incidents may be heavily targeted, closely observed, or both, and the dataset cannot separate the two; the counts are not a measure of exposure to manipulation.
0 of 0 incidents
01 · Summary measures

Concentration, corroboration, publication delay and recorded response

The four measures are recalculated for the current selection. Each describes the published record of European institutions, and none describes the behaviour of any foreign state.

02 · Time

Incidents by year of occurrence and year of publication

The occurrence series counts incidents by the year in which they took place; the publication series counts them by the year in which an institution first published an attribution. The difference between the two is the delay before an incident enters the public record.

Incidents by year

Series
Group by
The chart shows incidents dated 2010 or later; 84 earlier incidents enter the dataset through retrospective reporting. Grouped views stack the categories. The series describe published attribution and not the incidence of manipulation.

Publication delay

Compare
03 · Actors and techniques

Attributed states, actor categories and DISARM techniques

The attributed state is the state the source named. The actor category and the DISARM techniques record how the source characterised the operation. All three describe published attributions, and none estimates the behaviour of a state.

Attributed states

Incidents by the state the source named. Selecting a bar filters every panel.

Actor categories

Incidents by the controlled actor category assigned in the dataset.

Event types

Incidents by the type of episode the source described. An incident may carry more than one type.

Most frequently coded DISARM techniques

Techniques appearing in published attributions. Codes derive from analytical labels applied during extraction; a per-incident coding pass remains outstanding. Selecting a technique filters every panel.

Techniques by attributed state

Share of each state's attributed incidents that carry the technique. Columns are attributed states; rows are the 16 most frequent techniques.

A dark cell indicates that the technique appears in a large share of the incidents attributed to that state.

Technique co-occurrence

Two techniques are linked when they appear in the same incident. Node size is the number of incidents carrying the technique; link width is the number of incidents carrying both. Hovering over a node lists the techniques that most often accompany it.

Minimum shared incidents
04 · Attributing institutions

Attribution frequency, concentration, corroboration and jurisdiction

This section describes the institutions that publish attributions: how many incidents each contributes, how concentrated the record is among them, how often two institutions independently attribute the same incident, and which jurisdictions report on which countries.

Attributing institutions

Incidents by canonical parent institution. A jointly authored document counts for each institution behind it.

Concentration of the record

Cumulative share of incidents with an identified reporting institution, by number of institutions ranked from the largest contributor.

Institution type by publication year

Share of each year's published attributions by type of attributing institution, 2015 onwards.

Corroboration measures

Three nested measures of agreement between institutions.

Independent corroboration requires separate documents from separate parent institutions. Joint authorship of one document and several documents from one institution are counted separately.

Corroboration between institutions

Two institutions are linked when they attributed the same incident independently in separate documents. Node size is the number of the institution's published attributions; link width is the number of independently corroborated incidents the two share.

Attribution matrix

Rows
Cell

Each cell counts attributed incidents. In the first view the diagonal holds jurisdictions reporting on their own information space and the other cells hold attributions about another country. Hovering over a cell shows the institution types, attributed states and publication delay for that cell.

Rows and columns are limited to the 22 largest by incident count; Multinational groups NATO, EU and other bodies without a single national jurisdiction.

Attribution flows between jurisdictions

Every country appears once. Ribbons run from the jurisdiction of the attributing institution to the country the incident concerned; a ribbon that loops outside the ring is a country reporting on itself. Hovering over a segment isolates its flows, and selecting a segment keeps them isolated.

Minimum incidents2
Attribution about another countryReporting on own countryPublishes attributionsOnly appears as a target
05 · Geography

Target countries, domestic reporting and attributing institutions by country

Incident counts by target country reflect institutional capacity as well as exposure. The second measure gives the share of each country's record that its own institutions published; the third gives the number of independent institutions that attribute incidents against the country.

Measure

Most recorded target countries

Incidents by target country. The blue segment is the share of the country's record published by its own institutions.

06 · Comparison

Comparison of two attributed states, target countries or institutions

The table compares two values of one dimension over the current selection. Any filter on the chosen dimension is ignored for this table.

Dimension AB
07 · Incident records

Incident records with source document, page and supporting quotation

Every row names its source document and page and carries the sentence that supports the attribution. Selecting a row opens the full record. The documents themselves are not yet linked, so verification requires retrieving the document by its identifier.

Sort
YearIncidentTargetAttributed toPublished byConfidenceEvidence
08 · Methodology and data

Data collection, coverage, licence and downloads

Data collection

We leave the judgement of what constitutes foreign information manipulation with the institutions that make it publicly and answer for it, and we confine our own work to reading their published documents and recording every attribution we find in a common schema, together with the sentence that supports it. A language model reads each passage under a fixed instruction set; every record must carry a verbatim quotation, fields stay empty where the source is silent, and the actor is recorded as the source names it. We normalised institution names through a curated alias table, linked duplicate descriptions conservatively, and coded actors by category.

We tested the alternative, in which a language model reads news archives and decides for itself what counts as manipulation, and rejected it. Genuine incidents are rare relative to the volume of news, so a classifier at the measured agreement rates would produce roughly 51 false flags for every incident correctly identified, and a system that labels published speech as foreign interference needs an accountable author. Deliverable D4.2 sets out the test and the design in full.

Coverage

Five correction-register items remain open and are conditions on use: publication years are parsed from document identifiers, so the delay figures are provisional; the dataset awaits a repository record and identifier; a five-record source verification awaits a route to the documents; the charts on this page are mouse-driven; and the 60-record validation sample awaits human ratification. The corrections sheet of the registries workbook carries all 47 items.

Licence, citation and downloads

We release the data and the codebook under the Creative Commons Attribution 4.0 International licence. The codebook lists every figure we report with the expression that reproduces it from the released file, and the script reproduce_figures.py in the supporting materials runs those expressions in full. Cite as: DE-CONSPIRATOR Consortium (2026). The DE-CONSPIRATOR FIMI Attribution Event Dataset, release v2.4.3. Deliverable D4.2, Horizon Europe Grant Agreement 101132671. Until the dataset has a persistent identifier of its own, 10.3030/101132671 identifies the project alone.

SHA-256 of DCFIMIEvent_v2_4_3.csv: . Any institution or individual named in the dataset may contest a record; write to info@deconspirator-project.eu and the correction will be recorded in the corrections sheet.