DCLeaks

The GRU began planning the releases at least as early as April 19, 2016, when Unit 26165 registered the domain dcleaks.com through a service that an onymized the registrnnt.137 Netyksho Indictment ,r 35. Approximately a week before the registration of dcleaks.com, the same actors attem ted to re ister the website electionleaks.com using the same domain registration se1vice. Unit 26165 paid for the registration using a pool ofbitcoin that it had mined.138 See SM-2589105, se1ial 181; Netyksho Indictment ,r 2l(a). The dcleaks.com landing page pointed to different ti·anches of stolen documents, ~m anged by victim or subject matter. Other dcleaks.com pages contained indexes of th e stolen emails that were being released (bearing the sender, recipient, an d date of the email) . To control access and the timing ofreleases, pages were sometimes password-protected for a period of time and later made unresti·icted to the public.

Staiiing in June 2016, the GRU posted stolen documents onto th e website dcleak s.com, including documents stolen from a number of individuals associated with the Clinton Campaign. These documents appeared to have originated from personal email accounts (in pa1ticular, Google and Microsoft accounts), rather than the DNC an d DCCC computer networks. DCLeaks victims included an advisor to the Clinton Campaign, a fo1m er DNC employee and Clinton Campaign employee, and four other campaign volunteers.139 The GRU released through dcleaks.com th ousands of documents, including personal identifying and financial info1mation, internal con espondence related to the Clinton Campaign and prior political jobs, an d fundraising files and infoimation.140

42

GRU officers operated a Facebook page under the DCLeaks moniker, which they primarily used to promote releases of materials.141 Netyksho Indictment ¶ 38. The Facebook page was administered through a small number of preexisting GRU-controlled Facebook accounts.142 See, e.g., Facebook Account 100008825623541 (Alice Donovan).

GRU officers also used the DCLeaks Facebook account, the Twitter account @dcleaks_, and the email account dcleaksproject@gmail.com to communicate privately with reporters and other U.S. persons. GRU officers using the DCLeaks persona gave certain reporters early access to archives of leaked files by sending them links and passwords to pages on the dcleaks.com website that had not yet become public. For example, on July 14, 2016, GRU officers operating under the DCLeaks persona sent a link and password for a non-public DCLeaks webpage to a U.S. reporter via the Facebook account.143 7/14/16 Facebook Message, ID 793058100795341 (DC Leaks) to ID [Redacted: (b) (6), (b) (7)(C)] Similarly, on September 14, 2016, GRU officers sent reporters Twitter direct messages from @dcleaks_, with a password to another non-public part of the dcleaks.com website.144 See, e.g., 9/14/16 Twitter DM, @dcleaks_ to [Redacted: (b) (6), (b) (7)(C)] 9/14/16 Twitter DM, @dcleaks_ to [Redacted: (b) (6)], [Redacted: (b) (7)(C)] The messages read: "Hi https://t.co/QTvKUjQcOx pass: KvFsg%*14@gPgu& enjoy ;)."

The DCLeaks.com website remained operational and public until March 2017.