Citizen Lab report details how emails phished from journalist critical of Russia were falsified, then leaked for disinformation campaign; 200+ others targeted
Phishing to Propaganda Gabriela Vatu / Softpedia News : Fancy Bear Hackers Tainted Dumped Emails with False Data Andy Greenberg / Wired : Security News This Week: Bug Bounties Pay But Piracy Doesn't Tweets: Kevin Riggle / @kevinriggle : Phishing using Google's AMP redirector to appear as a legitimate Google password reset email. Of course. http://twitter.com/... See also Mediagazer
Context & Ripple Effects
This report completes a picture that earlier coverage sketched in parts: Secureworks had already shown Fancy Bear hitting 4.7K Gmail users worldwide with 19K malicious links timed to Moscow office hours, and an AP investigation traced targeting of 200+ journalists, publishers, and bloggers back to mid-2014. What Citizen Lab adds is the missing middle of the operation — the phished emails weren't just stolen, they were falsified and then leaked as disinformation.
First-order effects
- The targeted journalist and the 200+ others in the AP investigation face a second harm beyond account compromise: fabricated material circulating under their names, forcing them and their outlets to publicly dispute authenticity.
- Google's own infrastructure was turned against its users — the phishing used Google's AMP redirector to make fake password-reset emails look like legitimate Google messages, defeating sender-trust cues inside Gmail itself.
Second-order effects
- Newsrooms receiving 'leaked' email dumps tied to Russia coverage now have to verify provenance before publishing, raising the cost and slowing the pace of reporting on Russian affairs.
- Google faces pressure to police abuse of its link and redirector infrastructure, not just filter inboxes — a responsibility consistent with its later disclosure of Fancy Bear phishing campaigns against Ukrainians ahead of the invasion.
Third-order effects
- If the pattern holds, credential phishing becomes stage one of influence operations rather than an end in itself — espionage output feeding propaganda — which blurs attribution and leaves defenders without a clean post-breach recovery point.
- Research shops like Citizen Lab harden into part of the response system, with their reports serving as the public record that platforms, newsrooms, and governments act on — a role their later work with Access Now on Russian agencies using deep target knowledge extends.
The trend: State-linked hacking is shifting from intelligence collection toward hack-and-leak disinformation, with phishing as the entry point and falsified document dumps as the payload.