PoliticalMANIPULATIVE
Hack-and-Leak
What it is
Stealing genuine private material and releasing it through deniable channels, timed and selected for political effect, so that true documents do the work of an influence operation while the sponsor stays hidden.
How it works
Real-world examples
- •In 2016 officers of Russia's GRU stole emails from the Democratic National Committee and Clinton campaign chairman John Podesta and released them through DCLeaks, Guccifer 2.0, and WikiLeaks, according to the Mueller report and a July 2018 indictment.
- •Two days before the May 2017 French presidential runoff, thousands of Macron campaign files appeared online, with forgeries mixed in. The head of France's cybersecurity agency ANSSI said the following month that it had found no trace of a known Russian group, an example of official restraint in attribution; U.S. prosecutors later charged GRU officers in connection with it.
- •In August 2024 the Trump campaign said internal documents had been stolen; U.S. agencies attributed the intrusion to Iran, and several news organizations that received the material declined to publish it.
- •The November 2014 Sony Pictures breach released executives' emails and unreleased films; the FBI attributed it to North Korea, an attribution some private security researchers publicly disputed at the time.
Ethical guidelines
- ●Authentic does not mean complete or representative. Treat a leak as a selection made by someone with a purpose.
- ●Newsrooms should authenticate independently, report what is known about provenance, and resist the leaker's timetable.
- ●Targets should confirm or deny authenticity honestly instead of only denouncing the source.
- ●Do not circulate private personal information that has no public-interest value simply because it is in the dump.
How to defend against it
- ►Ask three separate questions: is it authentic, who selected and released it, and why now?
- ►Look for what is absent: a leak that exposes only one side of a contest tells you about the leaker's targeting as well as about the target.
- ►Wait for authentication before sharing. Forgeries are most often inserted among real files, where they borrow credibility.
- ►Read coverage that reports provenance alongside content, and be wary of coverage that offers only one of the two.
- ►Notice timing relative to events such as debates, conventions, or votes; release at the moment of least possible scrutiny is a tell of operational intent.
References
- Mueller, R. S. (U.S. Department of Justice) (2019). Report On The Investigation Into Russian Interference In The 2016 Presidential Election, Volume I. U.S. Department of Justice · linkThe GRU intrusion and staged release of Democratic emails in 2016 (Section III).
- Rid, T. (2020). Active Measures: The Secret History of Disinformation and Political Warfare. Farrar, Straus and GirouxThe historical continuity between Cold War leak operations that mixed genuine and forged documents and present-day hack-and-leak.
- Hulcoop, A., Scott-Railton, J., Tanchak, P., Brooks, M., & Deibert, R. (2017). Tainted Leaks: Disinformation and Phishing With a Russian Nexus. The Citizen Lab, University of Toronto, May 25, 2017Documented insertion of falsified material into otherwise genuine stolen documents.
Last reviewed
Suggest a correction