
Hack and Leak
In a hack-and-leak operation, attackers break into other people's computer systems, steal confidential documents there, and publish them in a targeted way. The goal is not money, but damage to the reputation of a person, company, or party — usually at a politically opportune moment.
Hack and Leak describes an attack in two steps. First, unknown parties gain unauthorized access to other people’s computers, email accounts, or servers. There, they copy confidential files, such as internal emails, contracts, or chat logs. In the second step, they release this material to the public — via anonymous websites, social networks, or directly to journalists. The difference from ordinary data theft lies in the purpose: the perpetrators do not want ransom, but public impact. The English expression literally means “to break in and let it leak out”.
Stolen emails as a political weapon
Such operations almost always target victims whose reputation is sensitive. Parties in election campaigns, government agencies, large corporations, or well-known individuals. Internal communication, taken out of context, often sounds embarrassing or conspiratorial, even if it contains nothing forbidden. The attackers count on exactly that.
The timing is especially delicate. If material is published just days before an election or a shareholders' meeting, there is no time for careful review. The headlines appear immediately, the correction comes weeks later. This is called an October surprise effect, named after the month before U.S. elections.
There is a second problem as well. Anyone publishing genuine stolen documents can mix in forged files. Since everything appears to come from the same source, even the forgery seems credible. Those affected then face the thankless task of denying individual points — and thereby indirectly confirming the rest.
From phishing email to headline
The break-in rarely begins with technical wizardry. Usually, a deceptively genuine email asking for a password is enough. This approach is called phishing, derived from the English word for fishing. A single employee clicking the link often opens access to an entire mailbox system.
Afterward, the attackers copy as much material as possible, often unnoticed over weeks. The package is then sorted and prepared. Some operations build their own websites with a search function for this purpose, so journalists can easily find interesting items. Others invent a cover persona, such as an alleged lone activist supposedly passing on the files for reasons of conscience.
The final step is distribution. Once reputable media report on the content, the story takes on a life of its own. The attackers then no longer need to do anything at all. This is exactly where the dilemma for newsrooms lies: they cannot ignore genuine, often relevant material, but in doing so become a tool of someone else’s agenda. Many outlets therefore have rules about when they report on such data and how they identify its origin.
Known cases and the connection to AI
The best-known example is the attack on the US Democrats during the 2016 election campaign. Stolen emails from the party headquarters were published in installments over several weeks. Something similar hit Emmanuel Macron’s campaign team in France in 2017, shortly before the runoff election. The German Bundestag was also the target of a major data leak in 2015.
The term also appears in business news. If a company’s internal documents are published, its stock price can plummet within hours. For companies, this is a distinct risk that insurers and security departments plan for.
New is the role of artificial intelligence. Language models can search through huge volumes of stolen emails in minutes and summarize the most explosive passages. They can also generate convincing phishing messages and forged documents. This significantly lowers the effort required for such operations. Experts therefore expect hack and leak to occur more frequently — and that distinguishing between genuine and forged material will become more difficult.