The Shift From Fake Accounts to Hijacked Ones
Early voting begins on 26 August. On 13 September, Swedes go to the polls for the Riksdag as well as regional and municipal councils. Between those two dates sits a window that security teams across the Nordics should be paying attention to and not only the ones advising political parties. The biggest AI-enabled threat is no longer the fake account, it is the genuine one someone else is holding.
The reason is a shift in how influence operations are being run. At the last general election in 2022, the dominant concern was fake accounts pushing false narratives at scale such as networks of fabricated profiles, detectable if you knew what to look for, spreading content a careful reader could trace back to nowhere. That threat has not disappeared. However, the centre of gravity has moved to the hijacking of authentic accounts belonging to real opinion formers, parties and institutions.
The logic is uncomfortable and simple. Influence depends on credibility and credibility takes years to build. A fake account has to earn attention before it can spend it. A hijacked account already has the followers, the verification badge, the reporting relationships with journalists and the accumulated trust of an audience that has never had reason to doubt it. An attacker who takes it over inherits all of that instantly.
What the Swedish Authorities Are Actually Saying
The Swedish Psychological Defence Agency (MPF) has been consistent in its assessment through 2026. Its position is that Sweden and Swedish elections are not currently a priority target for Russian information influence while noting that the 2026 elections take place in a serious security environment marked by considerable uncertainty which can affect the risk of election interference. MPF also notes that the volume of information influence directed at Sweden over the past year has been substantially lower than in 2022 and 2023 when Sweden was subject to two larger campaigns.
That is a measured picture, not a crisis warning. But MPF pairs it with a second observation that deserves more attention than it usually gets. The technical threshold for conducting information influence has dropped sharply and today’s generative AI lets individual users rapidly produce material that is not only overwhelming in volume but also credible. The agency’s point is that threat actors can now generate and edit hostile images and video that spread organically and achieve wide reach without coordinated networks or botnet amplification at all.
In other words, the capability barrier has collapsed even where the intent is not currently concentrated on Sweden. MPF’s own framing is that Sweden could become a target and the situation can change quickly.
Sweden has built structure around this. Amendments to the Elections Act took effect on 1 December 2025 giving the Election Authority an explicit responsibility to coordinate election protection and requiring county administrative boards, municipalities and overseas missions to promptly report incidents that could affect the conduct of an election. A permanent national election network now brings together the Security Service, the Police, MPF, the Agency for Civil Defence, the National Cyber Security Centre, PTS and the Tax Agency.
What the European Record Shows
Two cases explain why account takeover has become the technique to watch.
In Romania, the Constitutional Court annulled the first round of the December 2024 presidential election after intelligence was declassified. Documents released on 4 December alleged that one candidate had benefited from coordinated accounts, algorithmic amplification and paid promotion on TikTok. Less widely reported and more relevant to security teams is what the same material said about infrastructure, one document detailed more than 85,000 attempted cyber attacks against election websites and IT systems concluding that the attacker had resources characteristic of a state. The information operation and the technical operation were running in parallel.
In April 2025, the X account of Czech Prime Minister Petr Fiala was taken over. False posts appeared claiming that Russian forces had attacked Czech units deployed near the Kaliningrad border. Fiala’s own account of the incident is the part every security team should read twice. He stated that despite thorough security measures including two factor authentication, the attackers still managed to reach the profiles and publish fake posts. Similar content appeared on the account of Spolu, the political alliance that includes his party and a member of the Czech parliament’s security committee suggested the breach may have involved someone with administrative access to both accounts.
That last detail is the lesson. The compromise did not defeat the Prime Minister’s personal password. It appears to have travelled through shared administrative access to multiple accounts. Most organisations have exactly this pattern somewhere, a social media management platform, an agency with posting rights, a former employee whose access was never revoked, a service account nobody owns.
Why This Is Not Only a Political Story
If you run security for a Swedish or Nordic business, the natural response is that none of this is your problem. It is worth resisting that.
The technique is content neutral. The same capability that publishes a false resignation announcement from a party account can publish a false profit warning from a listed company’s account, a fabricated product recall or a fraudulent payment instruction that appears to come from a verified corporate channel.
An election period concentrates attention, shortens verification windows and raises the value of a few hours of confusion. Public interest is elevated, journalists are working at speed and tolerance for waiting is low. A false statement attributed to your organisation during a news cycle this crowded will be amplified well before it can be corrected.
The Credential Problem Underneath All Of It
Account takeover is not an exotic attack. It is the industrialised end of a credential economy that has been scaling for years.
Verizon’s 2025 Data Breach Investigations Report, analysing single sign-on provider logs, found credential stuffing accounted for a median 19 percent of all daily authentication attempts. The same report found compromised credentials were the initial access vector in 22 percent of breaches and that 88 percent of attacks against basic web applications involved stolen credentials. The supply comes increasingly from infostealer malware harvesting credentials from infected devices.
These attacks are quiet by design. They typically try each stolen credential only once against a given account so they blend into ordinary login traffic and rarely trigger lockout defences built for brute force. The detection consequence is severe. IBM’s 2025 breach cost research found that breaches originating from compromised credentials took the longest to identify and contain at roughly 292 days.
Multi factor authentication remains essential and as Fiala’s case demonstrates, is not sufficient on its own. The bypass routes that matter in practice are MFA fatigue, phishable one time codes, SIM swapping, session token theft, OAuth consent abuse and weak account recovery processes. Account recovery in particular is the door most organisations forget to lock. It exists precisely to let someone back in when they have lost their credentials which makes it the most attractive endpoint in the whole authentication flow.
Practical Controls Worth Checking This Month
For any organisation with a public voice, the following are worth verifying before the campaign reaches its final weeks.
- Inventory who can publish as you: Every account, every scheduling tool, every agency, every individual with posting or admin rights. Most organisations discover at least one entry they cannot justify.
- Move privileged and public facing accounts to phishing resistant authentication: Passkeys or hardware security keys rather than SMS or app generated codes for anyone who can post publicly.
- Treat account recovery as a privileged pathway: Test it the way you would test a login. Confirm that helpdesk procedures cannot be talked around by someone with a plausible story and publicly available personal details.
- Monitor for anomalous session behaviour, not just failed logins: Successful authentication from an unexpected location, device or time is the signal that matters when the attacker holds a valid credential.
- Rehearse the response: Decide now who confirms whether a post is authentic, who contacts the platform, who issues the correction and through which channel. Establish a verification path your audience already trusts and that is not the compromised channel itself.
- Brief your people on synthetic media: Voice cloning and video manipulation have moved from demonstration to routine use. Staff who can authorise payments or issue public statements need to know that a familiar voice on a call is no longer proof of identity.
A New Regulatory Backdrop
There is one more reason this election is different. Article 50 of the EU AI Act which sets transparency obligations for providers and deployers of generative and interactive AI systems including deepfakes, applies from 2 August 2026. The obligations cover marking and detection of AI generated content and labelling of deepfakes and certain AI generated publications on matters of public interest. Non compliance carries fines of up to 15 million euro or 3 percent of total worldwide annual turnover whichever is higher.
The Swedish general election is therefore the first national vote in the country held under this regime, three weeks after it took effect. The rules bind legitimate actors rather than hostile ones which limits what they will prevent. What they change is the baseline expectation. Unlabelled synthetic content is now a compliance question for organisations operating in the EU, not only an ethical one.
The Point Is Verification, Not Prediction
Nobody can say with confidence what will happen in the three weeks before 13 September. MPF’s assessment suggests a lower likelihood of a concentrated campaign against Sweden than in some previous years and it deserves to be taken seriously rather than talked past.
What can be said with confidence is that the cost of attempting this kind of operation has fallen sharply, that a hijacked authentic account carries far more credibility than anything fabricated from scratch and that the organisations which come through such an incident well are the ones that decided in advance how they would prove what is real.
Detection at machine speed matters and the vendors making that case have a point. But the work that decides how one of these incidents ends is less glamorous, knowing who holds the keys to your public voice and being able to say so quickly when someone asks.
This post is also available in: