Guccifer 2.0
¶On June 14, 2016, the DNC and its cyber-response team announced the breach of the DNC network and suspected theft of DNC documents. In the statements, the cyber-response team alleged that Russian state-sponsored actors (which they referred to as "Fancy Bear") were responsible for the breach.145 Dmitri Alperovitch, Bears in the Midst: Intrusion into the Democratic National Committee, CrowdStrike Blog (June 14, 2016). CrowdStrike updated its post after the June 15, 2016 post by Guccifer 2.0 claiming responsibility for the intrusion. Apparently in response to that announcement, on June 15, 2016, GRU officers using the persona Guccifer 2.0 created a WordPress blog. In the hours leading up to the launch of that WordPress blog, GRU officers logged into a Moscow-based server used and managed by Unit 74455 and searched for a number of specific words and phrases in English, including "some hundred sheets," "illuminati," and "worldwide known." Approximately two hours after the last of those searches, Guccifer 2.0 published its first post, attributing the DNC server hack to a lone Romanian hacker and using several of the unique English words and phrases that the GRU officers had searched for that day.146 Netyksho Indictment ¶¶ 41-42.
43¶That same day, June 15, 2016, the GRU also used the Guccifer 2.0 WordPress blog to begin releasing to the public documents stolen from the DNC and DCCC computer networks. The Guccifer 2.0 persona ultimately released thousan ds of documents stolen from the DNC an d DCCC in a series of blog posts between June 15, 2016 an d October 18, 2016.147 Released documents included opposition research perfo1med by the DNC (including a memorandum analyzing potential criticisms of candidate Tnnnp), internal policy documents (such as recommendations on how to address politically sensitive issues), analyses of specific congressional races, and fundraising documents. Releases were organized around thematic issues, such as specific states (e.g. , Florida an d Pennsylvania) that were perceived as competitive in the 2016 U.S . presidential election.
¶Beginning in late June 2016, the GRU also used the Guccifer 2.0 persona to release documents directly to reporters an d other interested individuals. Specifically, on June 27, 2016, Guccifer 2.0 sent an email to the news outlet The Smoking Gun offering to provide "exclusive access to some leaked emails linked [to] Hillaiy Clinton 's staff." 148 The GRU later sent the repo1ier a password and link to a locked po1iion of the dcleaks.com website that contained an ai·chive of emails stolen by Unit 26165 from a Clinton Campaign volunteer in March 2016. 149 That the Guccifer 2.0 persona provided repo1ters access to a restricted po1iion of the DCLeaks website tends to indicate that both personas were operated by the same or a closely-related group of people.150 Before sending the repo1t er the link and password to the closed DCLeaks website, and in an apparent effo1t to deflect attention from the fact that DCLeaks and Guccifer 2.0 were operated by the same organization, the Guccifer 2.0 persona sent the repo1ter an email stating that DCLeaks was a "Wikileaks sub project" and that Guccifer 2.0 had asked DCLeaks to release the leaked emails with "closed access" to give repo1t ers a preview of them.
¶The GRU continued its release efforts through Guccifer 2.0 into August 2016. For example, on August 15, 2016, the Guccifer 2.0 persona sent a can didate for the U.S . Congress documents related to the candidate 's opponent.151 Netyksho Indictment ,i 43(a). On August 22, 2016, the Guccifer 2.0 persona transfen ed approximately 2.5 gigabytes of Florida-related data stolen from the DCCC to a U.S. blogger covering Florida politics.152 Netyksho Indictment ,i 43(b). On August 22, 2016, the Guccifer 2.0 persona sent a U.S. repo1ier documents stolen from the DCCC pertaining to the Black Lives Matter movement. 153
44¶The GRU was also in contact through the Guccifer 2.0 persona with Roger Stone, a former Trump Campaign member whose interest in material stolen from the Clinton Campaign is further discussed in Volume I, Section III.D.1, infra. After the GRU had published stolen DNC documents through Guccifer 2.0, Stone told members of the Campaign that he was in contact with Guccifer 2.0.154 Gates 4/10/18 302, at 3. In early August 2016, Stone publicly protested Twitter's suspension of the Guccifer 2.0 Twitter account. After it was reinstated, GRU officers posing as Guccifer 2.0 wrote to Stone via private message, "thank u for writing back . . . do u find anyt[h]ing interesting in the docs i posted?" On August 17, 2016, the GRU added, "please tell me if i can help u anyhow . . . it would be a great pleasure to me." On September 9, 2016, the GRU—again posing as Guccifer 2.0—referred to a stolen DCCC document posted online and asked Stone, "what do u think of the info on the turnout model for the democrats entire presidential campaign." Stone responded, "pretty standard."155 8/15/16 – 9/9/16 Twitter DMs, @Guccifer_2 & @RogerJStoneJr. The investigation did not identify evidence of other communications between Stone and Guccifer 2.0.