What happened
A federal grand jury indictment announced on 13 July 2018 charged twelve Russian GRU officers with hacking offences related to the 2016 US election. According to the Department of Justice, officers in Unit 26165 began spearphishing volunteers and employees of the Clinton presidential campaign, including the campaign's chairman, and used the same methods against the DCCC and DNC to obtain usernames and passwords, steal emails and documents, monitor employee activity and implant malicious code.
How the deception worked
The unit sent targeted emails to campaign staff and party employees that harvested account usernames and passwords. Compromised mailboxes yielded further contact lists and internal context that made subsequent lures more credible, letting the operation spread laterally from volunteers to senior staff. Stolen credentials were then used to access other computers on the committees' networks, where the officers monitored employee activity and installed malware for persistent collection. The exfiltrated correspondence was subsequently staged and released publicly to maximise political effect during the campaign.
AI involvement · No AI reported
No AI involvement reported in the indictment.
The control that would have caught it· our reading, not a claim from the sources
Hardware security keys for all campaign and party staff, which several campaigns adopted afterwards, defeat credential-harvesting pages regardless of how convincing the lure is.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.