/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Citizen Lab report details how emails phished from journalist critical of Russia were falsified, then leaked for disinformation campaign; 200+ others targeted

Phishing to Propaganda Gabriela Vatu / Softpedia News : Fancy Bear Hackers Tainted Dumped Emails with False Data Andy Greenberg / Wired : Security News This Week: Bug Bounties Pay But Piracy Doesn't Tweets: Kevin Riggle / @kevinriggle : Phishing using Google's AMP redirector to appear as a legitimate Google password reset email. Of course. http://twitter.com/... See also Mediagazer

Ars Technica Dan Goodin

Context & Ripple Effects

This report completes a picture that earlier coverage sketched in parts: Secureworks had already shown Fancy Bear hitting 4.7K Gmail users worldwide with 19K malicious links timed to Moscow office hours, and an AP investigation traced targeting of 200+ journalists, publishers, and bloggers back to mid-2014. What Citizen Lab adds is the missing middle of the operation — the phished emails weren't just stolen, they were falsified and then leaked as disinformation.

First-order effects

  • The targeted journalist and the 200+ others in the AP investigation face a second harm beyond account compromise: fabricated material circulating under their names, forcing them and their outlets to publicly dispute authenticity.
  • Google's own infrastructure was turned against its users — the phishing used Google's AMP redirector to make fake password-reset emails look like legitimate Google messages, defeating sender-trust cues inside Gmail itself.

Second-order effects

  • Newsrooms receiving 'leaked' email dumps tied to Russia coverage now have to verify provenance before publishing, raising the cost and slowing the pace of reporting on Russian affairs.
  • Google faces pressure to police abuse of its link and redirector infrastructure, not just filter inboxes — a responsibility consistent with its later disclosure of Fancy Bear phishing campaigns against Ukrainians ahead of the invasion.

Third-order effects

  • If the pattern holds, credential phishing becomes stage one of influence operations rather than an end in itself — espionage output feeding propaganda — which blurs attribution and leaves defenders without a clean post-breach recovery point.
  • Research shops like Citizen Lab harden into part of the response system, with their reports serving as the public record that platforms, newsrooms, and governments act on — a role their later work with Access Now on Russian agencies using deep target knowledge extends.

The trend: State-linked hacking is shifting from intelligence collection toward hack-and-leak disinformation, with phishing as the entry point and falsified document dumps as the payload.