How three ProPublica reporters were attacked with Twitter bots and “email bombs” that forced the closure of reporters' email accounts
and inexpensive — it is for haters to disrupt our work.” https://www.propublica.org/... Micah Lee / @micahflee : After journalists contacted extremist websites to fact-check an article, hate groups emailed bombed them and brought down ProPublica's email server. They were attacked again the next day after reporting on Russia bots promoting neo-Nazis in Charlotteville https://www.propublica.org/... Julia Angwin / @juliaangwin : In August my email account was attacked. So I wrote a reconstruction of what happened and why: https://www.propublica.org/...
Context & Ripple Effects
The attack on Julia Angwin, Micah Lee, and their colleagues did not come out of nowhere: it followed ProPublica's reporting on Russia-linked Twitter bots promoting neo-Nazi content around Charlottesville, and the retaliation arrived within a day of publication. The pattern was already visible two months earlier, when the DFR Lab documented a botnet assault on ProPublica and then faced its own wave of bots and impersonators for doing so.
The email-bombing that forced the closure of reporters' accounts is also part of a broader escalation against journalists who cover Russia-linked networks — Citizen Lab had already documented how phished emails from a Kremlin critic were falsified and weaponized in a disinformation campaign targeting 200+ people. What makes this story notable is how cheap the disruption was: no breach required, just volume.
First-order effects
- ProPublica's newsgathering is directly impaired — its email server goes down and three reporters lose working email accounts, cutting off source communication mid-investigation.
- Angwin, Lee, and colleagues must shift to costlier defensive work: rebuilding contact channels and documenting the attack itself rather than pursuing the original Russia-bot story.
Second-order effects
- The DFR Lab episode shows documentation invites retaliation, so every outlet or lab that reports on bot activity now has to budget for becoming the next target — a chilling tax on exactly this beat.
- Fact-checking organizations partnering with platforms face the same playbook, as Poynter's survey of fact-checkers handling harassment and death threats confirms, pushing newsrooms toward shared security practices rather than ad hoc responses.
Third-order effects
- If cheap volumetric attacks keep forcing account closures, operational security stops being an optional specialty for investigative journalists and becomes baseline newsroom infrastructure, alongside legal review.
- The escalation path — bots, email bombs, phished-and-falsified emails, and eventually commercial intrusion tools like the hacker-for-hire operations hitting thousands of journalists and politicians — points toward harassment being treated as a disinformation tactic regulators and platforms can no longer classify as mere trolling.
The trend: Coordinated online harassment is maturing into a low-cost, off-the-shelf instrument for disrupting investigative journalism, with each documented attack normalizing the next one.