Security1 distinct publisher3 min readUpdated
Recorded Future logged three CopyCop impersonations against the US-Armenian Firebird AI data center in a 20-day window, the last of them fabricating an Iranian military case for hitting it.
The Watch · Security desk
Compiled by The WatchSomething wrong?
Follow any of these and your For You feed starts watching them — no settings page required.
Recorded Future's Insikt Group reports that the Russian influence network CopyCop, also tracked as Storm-1516, very likely targeted the joint US and Armenian-backed Firebird AI data center in Hrazdan, Armenia, and documented three separate media impersonations aimed at the facility between June 24 and July 13, 2026, ahead of its scheduled July 2026 opening [1]. That is three fabrications inside a 20-day window against one construction site [1], which puts influence-operation monitoring on the project risk register alongside geotechnical surveys and grid interconnects.
The sequence escalated. According to Insikt Group, the first instance, beginning June 24, was a CopyCop amplifier account on a major Western social media platform sharing a video impersonating TechCrunch, headlined "Armenia AI Hub at Risk, Authorities Warn of Major Quake," which claimed a magnitude 7.4 earthquake could imminently strike Kotayk Province and threaten the facility [2]. The second cast doubt on the project's economic and infrastructure viability [1]. The third impersonated official Iranian military communications justifying treatment of the data center as a legitimate military target [1]. Reach grew from limited initial engagement to more than 1.6 million combined views by the third instance [3].
The target explains the effort. Firebird, a US and Armenia-based AI cloud and infrastructure company, is building the Caucasus region's first large-scale AI data center in Hrazdan, Kotayk Province, as a public-private effort with the US and Armenian governments and NVIDIA [4]. Phase One is roughly a $500 million investment hosting more than 6,000 NVIDIA Blackwell GPUs, up to 110.6 exaflops at 18 megawatts [5]. Phase Two takes the commitment to about $4 billion and adds more than 41,000 GPUs, which Recorded Future says would place Armenia among the top five countries globally for AI computing infrastructure [6]. That is an increment of roughly $3.5 billion, about eight times the Phase One figure [2], and a built-out fleet of more than 47,000 GPUs [3].
It is also a diplomatic pillar. The project rests on an August 2025 US-Armenia framework on semiconductors and AI [7]; US Vice President JD Vance announced Phase Two during a February 2026 visit to Yerevan [8]; and in May 2026 Secretary of State Marco Rubio, the first sitting Secretary of State in the South Caucasus since 2012, signed a Charter on Comprehensive Strategic Partnership and a critical minerals and rare earths framework [9]. Armenia has frozen participation in the Russia-led CSTO since February 2024, with Prime Minister Nikol Pashinyan calling the shift "irreversible" in December 2024, and the Kremlin has signaled that Armenia's preferential gas pricing depends on staying inside Russia's regional integration frameworks [10]. The Firebird campaign follows CopyCop's multi-month operation against Armenia's June 7, 2026 parliamentary elections, which sought to denigrate Pashinyan and the Civil Contract party; Insikt Group assesses the network redirected to the data center after his reelection [11].
Two things to watch. Recorded Future expects CopyCop to keep targeting Western investment in Armenia, citing reuse of the same amplifier network against other Armenia-linked Western projects [12], so the practical indicator is whether the same accounts surface against the critical minerals work signed in May [9]. The second is the military-target framing: an impersonated targeting justification is a different category of output from an invented earthquake, and it lands on contractors, insurers and site staff rather than on a communications team. One caution for anyone citing the report downstream: it describes the Hrazdan site as 200,000 square miles [13], a figure that does not survive contact with a map.
Ranked by verification strength, evidence, and original report placement.
Recorded Future's Insikt Group assesses the Russian influence network CopyCop (Storm-1516) very likely targeted the joint US and Armenian-backed Firebird AI data center in Hrazdan, Armenia, and documented three separate CopyCop media impersonations targeting the facility between June 24 and July 13, 2026, ahead of its July 2026 opening. The impersonations fabricated an imminent earthquake risk, cast doubt on the facility's economic and infrastructure viability, and impersonated official Iranian military communications justifying treating the data center as a legitimate military target.
Reach expanded substantially across the three instances, growing from limited initial engagement to over 1.6 million combined views by the third.
Beginning June 24, 2026, Insikt Group observed a CopyCop amplifier account on a major Western social media platform sharing a video impersonating TechCrunch, titled "Armenia AI Hub at Risk, Authorities Warn of Major Quake," which claimed a magnitude 7.4 earthquake could imminently strike Kotayk Province and threaten the Firebird facility.
Firebird, a US and Armenia-based AI cloud and infrastructure company, is constructing the Caucasus region's first large-scale AI data center in Hrazdan, Kotayk Province, as a public-private collaborative effort with the US and Armenian governments and NVIDIA.
Phase One, scheduled for launch in July 2026, amounts to an approximately $500 million investment; once operational the facility will host more than 6,000 NVIDIA Blackwell GPUs delivering up to 110.6 exaflops of AI compute at 18 megawatts of power capacity.
Phase Two raises investment to approximately $4 billion, adding more than 41,000 additional GPUs and placing Armenia among the top five countries globally for AI computing infrastructure.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed single-vendor forensics, one external corroboration
The technical core is unusually specific for an influence-operations report: named impersonated outlets and a named journalist, domain registration dates and registrar, hosting ASNs, CSS stylesheet hash linkage to previously confirmed CopyCop domains, named amplifier accounts, and one independent corroboration (Gnida Project). It is nonetheless one publisher assessing its own research, attribution is hedged rather than proven, the third and most escalatory instance is asserted without forensic detail in the supplied text, and one background figure is internally implausible.
Campaign active and scaling; effect unmeasured
Adoption of the tactic is documented rather than hypothetical: three executed impersonations in 20 days, reuse of the same amplifier accounts across instances, and reported reach growing from negligible to over 1.6 million combined views against a real project moving toward a July 2026 Phase One launch. It is capped by the absence of any evidence of downstream uptake -- no mainstream pickup, no platform enforcement data, no investor, contractor, or official reaction.
Slightly overstated impact framing
The report's attribution language is calibrated and its forensics substantive, so the gap is small. It tilts mildly positive because impact is argued from view counts alone -- 'growing audience viewership' is presented as campaign progress with no evidence of behavioral effect on the project, its backers, or local sentiment -- and because a background figure that is orders of magnitude off goes uncorrected alongside a forward-looking 'will likely continue' judgment that nothing in the cluster tests.
Commercial threat-intel vendor publishing its own detections
The sole source is a self-published blog from a commercial threat-intelligence company reporting research by its in-house analytic unit; demonstrating early detection and attribution of a state-linked network against a headline AI megaproject directly showcases the product being sold. The report mitigates this by disclosing method detail that can be checked and by citing an outside researcher's corroboration, but no target-side or platform-side account balances the framing, and the choice of a high-attention AI-investment target is itself flagged by the report as attention-driven.
Moderate: strong method, single voice
Confidence is limited by structure rather than by sloppiness. The forensic chain is specific and partly externally corroborated, but everything in the cluster comes from one interested publisher, the central attribution is hedged, the most escalatory incident lacks supporting detail here, one background figure is clearly wrong, and no party named in the story has responded on the record.
invest
Nvidia is brokering the Nordic build-out, not just supplying it2 distinct publishers
invest
Nvidia's newest product is credit: $3bn into SB Energy, $250bn behind OpenAI's rent1 distinct publisher
build
Fifty hops, one budget: why more GPU capacity won't fix agent latency1 distinct publisher
build
QUASAR says the 2-bit QAT loss floor is a weighting bug, not a law of physics1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 17, 2026