PoliticalMANIPULATIVE

Hack-and-Leak

What it is

Stealing genuine private material and releasing it through deniable channels, timed and selected for political effect, so that true documents do the work of an influence operation while the sponsor stays hidden.

How it works

Hack-and-leak is hard to counter because its core content is real. Fact-checking does not neutralize an authentic email. The manipulation lies in everything around the documents: who was targeted and who was not, which files were released and which withheld, when they appeared, how they were framed, and who the public was told had leaked them. Selective truth delivered at a chosen moment shapes perception as effectively as falsehood, and genuine material can carry a few forged items along with it. The attribution problem is built in. Release passes through a persona, a leak site, or a willing publisher, and each layer lets the sponsor deny and lets partisans on either side argue about the source instead of the conduct. Journalists are the intended delivery mechanism, since newsworthy documents get covered. Professional guidance since 2016 asks newsrooms to authenticate before publishing, to report provenance as part of the story, and to weigh whether the news value justifies serving the leaker's timing.

Real-world examples

  • In 2016 officers of Russia's GRU stole emails from the Democratic National Committee and Clinton campaign chairman John Podesta and released them through DCLeaks, Guccifer 2.0, and WikiLeaks, according to the Mueller report and a July 2018 indictment.
  • Two days before the May 2017 French presidential runoff, thousands of Macron campaign files appeared online, with forgeries mixed in. The head of France's cybersecurity agency ANSSI said the following month that it had found no trace of a known Russian group, an example of official restraint in attribution; U.S. prosecutors later charged GRU officers in connection with it.
  • In August 2024 the Trump campaign said internal documents had been stolen; U.S. agencies attributed the intrusion to Iran, and several news organizations that received the material declined to publish it.
  • The November 2014 Sony Pictures breach released executives' emails and unreleased films; the FBI attributed it to North Korea, an attribution some private security researchers publicly disputed at the time.

Ethical guidelines

  • Authentic does not mean complete or representative. Treat a leak as a selection made by someone with a purpose.
  • Newsrooms should authenticate independently, report what is known about provenance, and resist the leaker's timetable.
  • Targets should confirm or deny authenticity honestly instead of only denouncing the source.
  • Do not circulate private personal information that has no public-interest value simply because it is in the dump.

How to defend against it

  • Ask three separate questions: is it authentic, who selected and released it, and why now?
  • Look for what is absent: a leak that exposes only one side of a contest tells you about the leaker's targeting as well as about the target.
  • Wait for authentication before sharing. Forgeries are most often inserted among real files, where they borrow credibility.
  • Read coverage that reports provenance alongside content, and be wary of coverage that offers only one of the two.
  • Notice timing relative to events such as debates, conventions, or votes; release at the moment of least possible scrutiny is a tell of operational intent.

References

  1. Mueller, R. S. (U.S. Department of Justice) (2019). Report On The Investigation Into Russian Interference In The 2016 Presidential Election, Volume I. U.S. Department of Justice · link
    The GRU intrusion and staged release of Democratic emails in 2016 (Section III).
  2. Rid, T. (2020). Active Measures: The Secret History of Disinformation and Political Warfare. Farrar, Straus and Giroux
    The historical continuity between Cold War leak operations that mixed genuine and forged documents and present-day hack-and-leak.
  3. Hulcoop, A., Scott-Railton, J., Tanchak, P., Brooks, M., & Deibert, R. (2017). Tainted Leaks: Disinformation and Phishing With a Russian Nexus. The Citizen Lab, University of Toronto, May 25, 2017
    Documented insertion of falsified material into otherwise genuine stolen documents.
Last reviewed
Suggest a correction

Detect Hack-and-Leak in any text

Paste any message, email, or article into our free Manipulation Detector to see if Hack-and-Leak or other techniques are being used on you.