The 13 July 2018 indictment of twelve GRU officers sets out the operation in technical detail, and it is the clearest public account of a hack-and-leak.
Unit 26165 conducted spearphishing against Democratic Party staff from March 2016, obtaining credentials including those of the campaign chairman. They installed malware called X-Agent on DNC and DCCC networks, logged keystrokes, took screenshots, and exfiltrated tens of thousands of documents and emails.
Unit 74455 handled the release.
The releases went out through three channels. DCLeaks, a website launched in June 2016 presenting itself as an American transparency project. Guccifer 2.0, a persona claiming to be a lone Romanian hacker, who communicated with journalists and published documents directly. And WikiLeaks, which published the DNC emails on 22 July 2016, three days before the Democratic convention.
The technique has three components and each does distinct work.
The material is authentic. That is the crucial fact and the reason hack-and-leak outperforms fabrication. There is nothing to debunk. Every document is real, and any forensic examination confirms it, which means the ordinary defense against disinformation is unavailable.
The source is fabricated. Guccifer 2.0's function was to place a non-state origin on the material for the period in which it mattered. Attribution to Russian military intelligence was suspected quickly and established over the following two years, and by then the contents had been reported, absorbed and integrated — which is the sleeper effect and the continued influence effect of chapter 191 operating in combination.
And the sample is selected. This is the least discussed component and the most important. An organization's internal email over a period contains, inevitably, unguarded remarks, disputes, contempt for colleagues and errors of judgment. Releasing a subset creates an impression of an institution, and the audience infers the whole from the sample without knowing the sampling rule — because the sampling rule is the one thing the leak does not disclose.
That inference is a straightforward selection-bias failure, and it is unavoidable for a reader. You cannot correct for a selection you cannot see.
The authenticity premium — chapter 211's effort-justification effect — supplies the last piece. Documents obtained covertly feel like unmediated truth in a way that official statements do not, precisely because someone had to steal them.
Aftermath & Cross-Reference: Leak Evaluation Protocol