Guccifer 2.0

{{Short description|Pseudonymous Russian hacker/hacker group who conducted the 2015-16 DNC data breaches}}

{{distinguish|Guccifer}}

{{Use mdy dates|date=September 2021}}

{{Trump–Russia relations}}

"Guccifer 2.0" is a persona which claimed to be the hacker(s) who gained unauthorized access to the Democratic National Committee (DNC) computer network and then leaked its documents to the media,{{Cite web |last=Uchill |first=Joe |date=July 13, 2016 |title=Guccifer 2.0 releases new DNC docs |url=https://thehill.com/policy/cybersecurity/287558-guccifer-20-drops-new-dnc-docs/ |access-date=July 27, 2016 |website=The Hill |archive-date=July 29, 2016 |archive-url=https://web.archive.org/web/20160729012045/http://thehill.com/policy/cybersecurity/287558-guccifer-20-drops-new-dnc-docs |url-status=live }}{{Cite web |first=Joe |last=Uchill |date=July 18, 2016 |title=New Guccifer 2.0 dump highlights 'wobbly Dems' on Iran deal |url=https://thehill.com/policy/cybersecurity/288119-new-guccifer-20-dump-highlights-wobbly-dems-on-iran-deal/ |access-date=July 27, 2016 |website=The Hill |archive-date=July 29, 2016 |archive-url=https://web.archive.org/web/20160729012053/http://thehill.com/policy/cybersecurity/288119-new-guccifer-20-dump-highlights-wobbly-dems-on-iran-deal |url-status=live }} the website WikiLeaks,{{Cite news |last=Savage |first=Charlie |date=July 26, 2016 |title=Assange, Avowed Foe of Clinton, Timed Email Release for Democratic Convention |work=NYT |url=https://www.nytimes.com/2016/07/27/us/politics/assange-timed-wikileaks-release-of-democratic-emails-to-harm-hillary-clinton.html |access-date=August 4, 2016 |archive-date=March 8, 2018 |archive-url=https://web.archive.org/web/20180308182211/https://www.nytimes.com/2016/07/27/us/politics/assange-timed-wikileaks-release-of-democratic-emails-to-harm-hillary-clinton.html |url-status=live }}{{Cite web |date=June 16, 2016 |title='Lone Hacker' Claims Responsibility for Cyber Attack on Democrats |url=http://www.nbcnews.com/tech/tech-news/lone-hacker-claims-responsibility-cyber-attack-democrats-n593491 |access-date=July 27, 2016 |publisher=NBC News |archive-date=July 28, 2016 |archive-url=https://web.archive.org/web/20160728092152/http://www.nbcnews.com/tech/tech-news/lone-hacker-claims-responsibility-cyber-attack-democrats-n593491 |url-status=live }}{{Cite web |last=Cox |first=Joseph |date=July 22, 2016 |title=Guccifer 2.0 Claims Responsibility for WikiLeaks DNC Email Dump |url=https://www.vice.com/en/article/guccifer-2-claims-responsibility-for-dnc-email-dump/ |access-date=July 27, 2016 |website=Motherboard |language=en-us |archive-date=July 26, 2016 |archive-url=https://web.archive.org/web/20160726183522/https://motherboard.vice.com/read/guccifer-2-claims-responsibility-for-dnc-email-dump |url-status=live }} and a conference event. Some of the documents "Guccifer 2.0" released to the media appear to be forgeries cobbled together from public information and previous hacks, which had been mixed with disinformation.{{Cite web |date=2016-10-04 |title=The Clinton Foundation hack is likely fake |url=https://www.dailydot.com/debug/guccifer-2-clinton-foundation-hack-leak/ |access-date=2022-07-27 |website=The Daily Dot |language=en-US |archive-date=August 12, 2022 |archive-url=https://web.archive.org/web/20220812131710/https://www.dailydot.com/debug/guccifer-2-clinton-foundation-hack-leak/ |url-status=live }}{{Cite news |last=Williams |first=Katie Bo |date=October 4, 2016 |title=Alleged Guccifer 2.0 hack of Clinton Foundation raises suspicions |work=The Hill |url=https://thehill.com/policy/cybersecurity/299236-alleged-guccifer-20-hack-of-clinton-foundation-raises-suspicions/ |access-date=October 8, 2016 |archive-date=October 8, 2016 |archive-url=https://web.archive.org/web/20161008110910/http://www.thehill.com/policy/cybersecurity/299236-alleged-guccifer-20-hack-of-clinton-foundation-raises-suspicions |url-status=live }} According to indictments in February 2018, the persona is operated by Russian military intelligence agency GRU.{{Cite web |date=July 13, 2018 |title=12 Russians indicted in Mueller investigation |url=https://www.cnn.com/2018/07/13/politics/russia-investigation-indictments/index.html |website=CNN.com |access-date=July 14, 2018 |archive-date=July 14, 2018 |archive-url=https://web.archive.org/web/20180714215525/https://www.cnn.com/2018/07/13/politics/russia-investigation-indictments/index.html |url-status=live }} On July 13, 2018, Special Counsel Robert Mueller indicted 12 GRU agents for allegedly perpetrating the cyberattacks.

The U.S. Intelligence Community assessed with high confidence that some of the genuine leaks from "Guccifer 2.0" were part of a series of cyberattacks on the DNC committed by two Russian military intelligence groups,{{Cite news |title=Spy Agency Consensus Grows That Russia Hacked D.N.C. |work=New York Times |url=https://www.nytimes.com/2016/07/27/us/politics/spy-agency-consensus-grows-that-russia-hacked-dnc.html |access-date=July 26, 2016 |archive-date=May 2, 2019 |archive-url=https://web.archive.org/web/20190502041948/https://www.nytimes.com/2016/07/27/us/politics/spy-agency-consensus-grows-that-russia-hacked-dnc.html |url-status=live }}{{Cite web |last1=Shieber |first1=Jonathan |last2=Conger |first2=Kate |title=Did Russian government hackers leak the DNC emails? |url=https://techcrunch.com/2016/07/26/russia-dnc-hack/ |access-date=July 26, 2016 |website=TechCrunch |date=July 26, 2016 |archive-date=November 10, 2021 |archive-url=https://web.archive.org/web/20211110063309/https://techcrunch.com/2016/07/26/russia-dnc-hack/ |url-status=live }}{{Cite web |last=Rid |first=Thomas |date=July 25, 2016 |title=All Signs Point to Russia Being Behind the DNC Hack |url=https://www.vice.com/en/article/all-signs-point-to-russia-being-behind-the-dnc-hack/ |access-date=July 25, 2016 |website=Motherboard |archive-date=December 20, 2016 |archive-url=https://web.archive.org/web/20161220065919/http://motherboard.vice.com/en_uk/read/all-signs-point-to-russia-being-behind-the-dnc-hack |url-status=live }}{{Cite news |date=July 26, 2016 |title=DNC email leak: Russian hackers Cozy Bear and Fancy Bear behind breach |work=The Guardian |url=https://www.theguardian.com/technology/2016/jul/26/dnc-email-leak-russian-hack-guccifer-2 |access-date=August 7, 2016 |archive-date=August 5, 2016 |archive-url=https://web.archive.org/web/20160805161507/https://www.theguardian.com/technology/2016/jul/26/dnc-email-leak-russian-hack-guccifer-2 |url-status=live }} and that "Guccifer 2.0" is actually a persona created by Russian intelligence services to cover for their interference in the 2016 U.S. presidential election. This conclusion is based on intelligence analysis and analyses conducted by multiple private sector cybersecurity individuals and firms, including CrowdStrike,Dmitri Alperovitch, [https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/ Bears in the Midst: Intrusion into the Democratic National Committee] {{Webarchive|url=https://web.archive.org/web/20190524090240/https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/ |date=May 24, 2019 }}, Crowdstrike (June 15, 2016).Ellen Nakashima, [https://www.washingtonpost.com/world/national-security/cyber-researchers-confirm-russian-government-hack-of-democratic-national-committee/2016/06/20/e7375bc0-3719-11e6-9ccd-d6005beac8b3_story.html Cyber researchers confirm Russian government hack of Democratic National Committee] {{Webarchive|url=https://web.archive.org/web/20160803042631/https://www.washingtonpost.com/world/national-security/cyber-researchers-confirm-russian-government-hack-of-democratic-national-committee/2016/06/20/e7375bc0-3719-11e6-9ccd-d6005beac8b3_story.html |date=August 3, 2016 }}, Washington Post (June 20, 2016). Fidelis Cybersecurity,Michael Kan, [http://www.computerworld.com/article/3086314/security/russian-hackers-were-behind-dnc-breach-says-fidelis-cybersecurity.html Russian hackers were behind DNC breach, says Fidelis Cybersecurity] {{Webarchive|url=https://web.archive.org/web/20190216143738/https://www.computerworld.com/article/3086314/security/russian-hackers-were-behind-dnc-breach-says-fidelis-cybersecurity.html |date=February 16, 2019 }}, IDG News Service (June 20, 2016). FireEye's Mandiant, SecureWorks,SecureWorks Counter Threat Unit Threat Intelligence, [https://www.secureworks.com/research/threat-group-4127-targets-hillary-clinton-presidential-campaign Threat Group-4127 Targets Hillary Clinton Presidential Campaign] {{Webarchive|url=https://web.archive.org/web/20160720175418/https://www.secureworks.com/research/threat-group-4127-targets-hillary-clinton-presidential-campaign |date=July 20, 2016 }}, SecureWorks (June 16, 2016). ThreatConnect,Threatconnect Research Team, [https://www.threatconnect.com/blog/guccifer-2-0-dnc-breach/ Shiny Object? Guccifer 2.0 and the DNC Breach] {{Webarchive|url=https://web.archive.org/web/20220812234448/https://threatconnect.com/blog/guccifer-2-0-dnc-breach/ |date=August 12, 2022 }}, Threatconnect (June 29, 2016). Trend Micro,{{Cite report |url=https://documents.trendmicro.com/assets/wp/wp-two-years-of-pawn-storm.pdf |title=Two Years of Pawn Storm—Examining an Increasingly Relevant Threat |first=Feike |last=Hacquebord |date=2017 |publisher=Trend Micro |quote=This makes it very likely that Guccifer 2.0 is a creation of the Pawn Storm actor group. |access-date=April 27, 2017 |archive-date=July 5, 2017 |archive-url=https://web.archive.org/web/20170705114126/https://documents.trendmicro.com/assets/wp/wp-two-years-of-pawn-storm.pdf |url-status=live }} and the security editor for Ars Technica.Dan Goodin, [https://arstechnica.com/security/2016/06/guccifer-leak-of-dnc-trump-research-has-a-russians-fingerprints-on-it/ "Guccifer" leak of DNC Trump research has a Russian's fingerprints on it: Evidence left behind shows leaker spoke Russian and had affinity for Soviet era] {{Webarchive|url=https://web.archive.org/web/20160725202746/http://arstechnica.com/security/2016/06/guccifer-leak-of-dnc-trump-research-has-a-russians-fingerprints-on-it/ |date=July 25, 2016 }}, Ars Technica (June 16, 2016). The Russian government denies involvement in the theft,[https://www.reuters.com/article/us-usa-election-hack-russia-idUSKCN0Z02EK Moscow denies Russian involvement in U.S. DNC hacking] {{Webarchive|url=https://web.archive.org/web/20201018072542/https://www.reuters.com/article/us-usa-election-hack-russia-idUSKCN0Z02EK |date=October 18, 2020 }}, Reuters (June 14, 2016). and "Guccifer 2.0" denied links to Russia.{{Cite web |last=Franceschi-Bicchierai |first=Lorenzo |date=June 21, 2016 |title=We Spoke to DNC Hacker 'Guccifer 2.0' |url=https://www.vice.com/en/article/dnc-hacker-guccifer-20-interview/ |access-date=July 29, 2016 |website=Motherboard |publisher=Vice News |archive-date=July 29, 2016 |archive-url=https://web.archive.org/web/20160729030259/http://motherboard.vice.com/read/dnc-hacker-guccifer-20-interview |url-status=live }}{{Cite news |last=Franceschi-Bicchierai |first=Lorenzo |date=January 12, 2017 |title=Alleged Russian Hacker 'Guccifer 2.0' Is Back After Months of Silence |language=en-us |work=Motherboard |publisher=VICE News |url=https://www.vice.com/en/article/alleged-russian-hacker-guccifer-20-is-back-after-months-of-silence/ |access-date=January 13, 2017 |archive-date=January 22, 2017 |archive-url=https://web.archive.org/web/20170122215921/http://motherboard.vice.com/read/alleged-russian-hacker-guccifer-20-is-back-after-months-of-silence |url-status=live }}

In March 2018, Special Counsel Robert Mueller took over investigation of Guccifer 2.0 from the FBI while it was reported that forensic determination had found the Guccifer 2.0 persona to be a "particular military intelligence directorate (GRU) officer working out of the agency's headquarters on Grizodubovoy Street in Moscow".

Identity

On June 21, 2016, in an interview with Vice, "Guccifer 2.0" said he is Romanian,{{Cite web |last=Franceschi-Bicchierai |first=Lorenzo |date=June 21, 2016 |title=Here's the Full Transcript of Our Interview With DNC Hacker 'Guccifer 2.0' |url=https://www.vice.com/en/article/dnc-hacker-guccifer-20-full-interview-transcript/ |access-date=August 3, 2016 |website=Motherboard |publisher=Vice News |language=en-us |archive-date=August 3, 2016 |archive-url=https://web.archive.org/web/20160803102915/http://motherboard.vice.com/read/dnc-hacker-guccifer-20-full-interview-transcript |url-status=live }} which is the nationality of Marcel Lazar Lehel, the Romanian hacker who originally used the "Guccifer" pseudonym. On June 30, 2016, and January 12, 2017, "Guccifer 2.0" stated that he is not Russian.{{Cite web |last=Guccifer 2.0 |date=June 30, 2016 |title=FAQ from Guccifer 2.0 |url=https://guccifer2.wordpress.com/2016/06/30/faq/ |access-date=July 24, 2016 |website=Guccifer 2.0 |archive-date=July 25, 2016 |archive-url=https://web.archive.org/web/20160725143738/https://guccifer2.wordpress.com/2016/06/30/faq/ |url-status=live }}{{Cite web |last=McBride |first=Jessica |date=July 25, 2016 |title=Guccifer 2.0: 5 Fast Facts You Need to Know |url=http://heavy.com/news/2016/07/guccifer-2-0-2-two-wikileaks-dnc-emails-hack-breach-scandal-schultz-democratic-hillary-trump-putin-russia-bernie-sanders-mook-lazar-snowden-cnn-convention/ |access-date=July 27, 2016 |website=Heavy |language=en-US |archive-date=July 26, 2016 |archive-url=https://web.archive.org/web/20160726135651/http://heavy.com/news/2016/07/guccifer-2-0-2-two-wikileaks-dnc-emails-hack-breach-scandal-schultz-democratic-hillary-trump-putin-russia-bernie-sanders-mook-lazar-snowden-cnn-convention/ |url-status=live }}{{Cite web |last=Guccifer 2.0 |date=January 12, 2017 |title=Here I am Again, My Friends! |url=https://guccifer2.wordpress.com/2017/01/12/fake-evidence/ |access-date=February 25, 2017 |website=GUCCIFER 2.0 |archive-date=March 12, 2017 |archive-url=https://web.archive.org/web/20170312215726/https://guccifer2.wordpress.com/2017/01/12/fake-evidence/ |url-status=live }} However, despite stating that he was unable to read or understand Russian, metadata of emails sent from Guccifer 2.0 to The Hill showed that a predominantly-Russian-language VPN was used.Joe Uchill, [https://thehill.com/business-a-lobbying/289296-guccifer-20-used-russian-language-vpns-to-leak-documents/ Evidence mounts linking DNC email hacker to Russia], The Hill (July 26, 2016). When pressed to use the Romanian language in an interview with Motherboard via online chat, "he used such clunky grammar and terminology that experts believed he was using an online translator." Linguistic analysis by Shlomo Engelson Argamon showed that Guccifer 2.0 is most likely "a Russian pretending to be a Romanian".{{Cite news |last1=Savage |first1=Charlie |last2=Perlroth |first2=Nicole |date=July 27, 2016 |title=Is D.N.C. Email Hacker a Person or a Russian Front? Experts Aren't Sure |work=The New York Times |url=https://www.nytimes.com/2016/07/28/us/politics/is-dnc-email-hacker-a-person-or-a-russian-front-experts-arent-sure.html |access-date=October 3, 2018 |archive-date=August 19, 2022 |archive-url=https://web.archive.org/web/20220819051150/https://www.nytimes.com/2016/07/28/us/politics/is-dnc-email-hacker-a-person-or-a-russian-front-experts-arent-sure.html |url-status=live }}{{Cite web |date=July 27, 2016 |title=Multa Verba: Guccifer 2.0: Russian, not Romanian |url=https://multaverba.blogspot.com/2016/07/guccifer-20-russian-not-romanian.html |access-date=October 3, 2018 |archive-date=August 19, 2022 |archive-url=https://web.archive.org/web/20220819045531/https://multaverba.blogspot.com/2016/07/guccifer-20-russian-not-romanian.html |url-status=live }} When asked about Guccifer 2.0's leaks, WikiLeaks founder Julian Assange said "These look very much like they’re from the Russians. But in some ways, they look very amateur, and almost look too much like the Russians."{{Cite web |last=Uchill |first=Joe |date=2016-12-15 |title=Assange: Some leaks may have been Russian |url=https://thehill.com/policy/cybersecurity/310654-assange-some-leaks-may-have-been-russian/ |access-date=2022-07-27 |website=The Hill |language=en-US |archive-date=July 27, 2022 |archive-url=https://web.archive.org/web/20220727210151/https://thehill.com/policy/cybersecurity/310654-assange-some-leaks-may-have-been-russian/ |url-status=live }}{{Cite magazine |publisher=Condé Nast |date=2018-07-24 |title=What the Latest Mueller Indictment Reveals About WikiLeaks' Ties to Russia—and What It Doesn't |url=https://www.newyorker.com/news/news-desk/what-the-latest-mueller-indictment-reveals-about-wikileaks-ties-to-russia-and-what-it-doesnt |access-date=2022-07-27 |magazine=The New Yorker |language=en-US |archive-date=April 22, 2019 |archive-url=https://web.archive.org/web/20190422201800/https://www.newyorker.com/news/news-desk/what-the-latest-mueller-indictment-reveals-about-wikileaks-ties-to-russia-and-what-it-doesnt |url-status=live }}

Some cybersecurity experts have concluded that "Guccifer 2.0" is likely a creation of the Russian state-sponsored hacking groups thought to have executed the attack, invented to cover up Russian responsibility.Rob Price, [http://www.businessinsider.com/security-researchers-russian-spies-hacked-dnc-guccifer-2-possible-disinformation-campaign-2016-6 Yes, Russia really did hack the Democratic National Committee] {{Webarchive|url=https://web.archive.org/web/20220819051152/https://www.businessinsider.com/security-researchers-russian-spies-hacked-dnc-guccifer-2-possible-disinformation-campaign-2016-6 |date=August 19, 2022 }}, Business Insider (June 21, 2016).Lorenzo Franceschi-Bicchierai, [https://www.vice.com/en/article/guccifer-20-is-likely-a-russian-government-attempt-to-cover-up-their-own-hack/ 'Guccifer 2.0' Is Likely a Russian Government Attempt To Cover Up Their Own Hack] , VICE News (June 16, 2016). The cybersecurity firm CrowdStrike, which was hired by the DNC to analyze the data breach,{{Cite news |title=Russian government hackers penetrated DNC, stole opposition research on Trump |url=https://www.washingtonpost.com/world/national-security/russian-government-hackers-penetrated-dnc-stole-opposition-research-on-trump/2016/06/14/cf006cb4-316e-11e6-8ff7-7b6c1998b7a0_story.html |access-date=December 14, 2016 |newspaper=Washington Post |archive-date=May 22, 2019 |archive-url=https://web.archive.org/web/20190522235639/https://www.washingtonpost.com/world/national-security/russian-government-hackers-penetrated-dnc-stole-opposition-research-on-trump/2016/06/14/cf006cb4-316e-11e6-8ff7-7b6c1998b7a0_story.html |url-status=live }} "posits that Guccifer 2.0 could be 'part of a Russian Intelligence disinformation campaign'", i.e. a creation to deflect blame for the theft. Russia has made use of the invention of "a lone hacker or an hacktivist to deflect blame" in the past, deploying this strategy in previous cyberattacks on the German government and the French network TV5Monde. Thomas Rid of King's College London, a cybersecurity expert, says it is "'more likely than not' that the whole operation, including the Guccifer 2.0 part, was orchestrated by Russian spies." The hackers responsible for the DNC email leak (a group called Fancy Bear by CrowdStrike) seem to have not been working on the DNC's servers on April 15 which in Russia is a holiday in honor of the Russian military's electronic warfare services.{{Cite news |date=September 24, 2016 |title=Bear on bear |work=Economist |url=https://www.economist.com/news/united-states/21707574-whats-worse-being-attacked-russian-hacker-being-attacked-two-bear-bear |access-date=October 25, 2016 |archive-date=May 20, 2017 |archive-url=https://web.archive.org/web/20170520234836/http://www.economist.com/news/united-states/21707574-whats-worse-being-attacked-russian-hacker-being-attacked-two-bear-bear |url-status=live }}

On July 18, 2016, Russian government spokesman Dmitry Peskov denied Russian government involvement in the DNC theft.{{Cite web |date=July 18, 2016 |title=Hacker Guccifer 2.0 claims new DNC data leak {{!}} Fox News |url=http://www.foxnews.com/tech/2016/07/18/hacker-guccifer-2-0-claims-new-dnc-data-leak.html |access-date=July 25, 2016 |publisher=Fox News |language=en-US |archive-date=June 30, 2018 |archive-url=https://web.archive.org/web/20180630104926/http://www.foxnews.com/tech/2016/07/18/hacker-guccifer-2-0-claims-new-dnc-data-leak.html |url-status=live }}

In an October 2016 joint statement, the United States Department of Homeland Security and the Office of the Director of National Intelligence stated:

{{blockquote|The U.S. Intelligence Community (USIC) is confident that the Russian Government directed the recent compromises of e-mails from U.S. persons and institutions, including from U.S. political organizations. The recent disclosures of alleged hacked e-mails on sites like DCLeaks.com and WikiLeaks and by the Guccifer 2.0 online persona are consistent with the methods and motivations of Russian-directed efforts. These thefts and disclosures are intended to interfere with the U.S. election process. Such activity is not new to Moscow—the Russians have used similar tactics and techniques across Europe and Eurasia, for example, to influence public opinion there. We believe, based on the scope and sensitivity of these efforts, that only Russia's senior-most officials could have authorized these activities.[https://www.dhs.gov/news/2016/10/07/joint-statement-department-homeland-security-and-office-director-national Joint Statement from the Department of Homeland Security and Office of the Director of National Intelligence on Election Security] {{Webarchive|url=https://web.archive.org/web/20161210004335/https://www.dhs.gov/news/2016/10/07/joint-statement-department-homeland-security-and-office-director-national |date=December 10, 2016 }}, U.S. Department of Homeland Security (October 7, 2016).}}

In March 2018, The Daily Beast, citing U.S. government sources, reported that Guccifer 2.0 is in fact a Russian GRU officer, explaining that Guccifer once forgot to use a VPN, leaving IP logs on "an American social media company" server. The IP address was used by U.S. investigators to identify Guccifer 2.0 as "a particular GRU officer working out of the agency's headquarters on {{ill|Grizodubovoy Street|ru|Улица Гризодубовой (Москва)}} in Moscow."{{Cite news |last1=Ackerman |first1=Spencer |last2=Poulsen |first2=Kevin |date=March 22, 2018 |title=EXCLUSIVE: 'Lone DNC Hacker' Guccifer 2.0 Slipped Up and Revealed He Was a Russian Intelligence Officer |work=The Daily Beast |url=https://www.thedailybeast.com/exclusive-lone-dnc-hacker-guccifer-20-slipped-up-and-revealed-he-was-a-russian-intelligence-officer |access-date=March 23, 2018 |quote=But on one occasion (...) Guccifer failed to activate the VPN client before logging on. As a result, he left a real, Moscow-based Internet Protocol address in the server logs of an American social media company. (...) Working off the IP address, U.S. investigators identified Guccifer 2.0 as a particular GRU officer working out of the agency's headquarters on Grizodubovoy Street in Moscow. |archive-date=March 23, 2018 |archive-url=https://web.archive.org/web/20180323000034/https://www.thedailybeast.com/exclusive-lone-dnc-hacker-guccifer-20-slipped-up-and-revealed-he-was-a-russian-intelligence-officer |url-status=live }}

In April 2018, BuzzFeed reported that messages showed WikiLeaks' interest in Guccifer 2.0's emails and files.{{Cite web |title=These Messages Show Julian Assange Talked About Seeking Hacked Files From Guccifer 2.0 |website=BuzzFeed |date=April 5, 2018 |url=https://www.buzzfeed.com/kevincollier/assange-seth-rich-lies-guccifer-wikileaks-hannity |quote=Less than an hour after WikiLeaks's last message{{nbsp}}... Guccifer 2.0 tweeted that it had handed those documents over. |access-date=April 13, 2018 |archive-date=April 7, 2018 |archive-url=https://web.archive.org/web/20180407183359/https://www.buzzfeed.com/kevincollier/assange-seth-rich-lies-guccifer-wikileaks-hannity |url-status=live }}

On July 13, 2018, the United States Department of Justice (DOJ) indicted 12 Russian Intelligence Officers and revealed that Guccifer 2.0 was a persona used by GRU.{{Cite news |last1=Ewing |first1=Philip |last2=Johnson |first2=Carrie |date=July 13, 2018 |title=Justice Department Charges Russian Cyberspies With Attack On 2016 Election |work=National Public Radio |url=https://www.npr.org/2018/07/13/628773789/deputy-attorney-general-rod-rosenstein-unveils-new-hacking-charges-in-dnc-case |access-date=July 13, 2018 |archive-date=July 13, 2018 |archive-url=https://web.archive.org/web/20180713170840/https://www.npr.org/2018/07/13/628773789/deputy-attorney-general-rod-rosenstein-unveils-new-hacking-charges-in-dnc-case |url-status=live }}

Twitter suspended the persona's account on July 14, 2018, for "being connected to a network of accounts previously suspended for operating in violation of our rules." The account had been dormant for at least a year and a half.{{Cite web |last=Sommerfeldt |first=Chris |date=July 14, 2018 |title=Twitter finally suspends Guccifer 2.0 and DCLeaks in light of Mueller indicting 12 Russian agents who used the accounts |url=http://www.sandiegouniontribune.com/ny-news-guccifer-mueller-russian-agents-twitter-20180714-story.html |access-date=July 15, 2018 |website=San Diego Tribune |archive-date=July 15, 2018 |archive-url=https://web.archive.org/web/20180715011542/http://www.sandiegouniontribune.com/ny-news-guccifer-mueller-russian-agents-twitter-20180714-story.html |url-status=dead }}

Computer hacking claims

{{Main|2016 Democratic National Committee email leak}}

On June 14, 2016, according to The Washington Post, the DNC acknowledged a hack{{Cite news |last=Nakashima |first=Ellen |date=June 15, 2016 |title='Guccifer 2.0' claims credit for DNC hack |url=https://www.washingtonpost.com/world/national-security/guccifer-20-claims-credit-for-dnc-hack/2016/06/15/abdcdf48-3366-11e6-8ff7-7b6c1998b7a0_story.html |access-date=July 25, 2016 |newspaper=Washington Post |archive-date=April 17, 2018 |archive-url=https://web.archive.org/web/20180417013555/https://www.washingtonpost.com/world/national-security/guccifer-20-claims-credit-for-dnc-hack/2016/06/15/abdcdf48-3366-11e6-8ff7-7b6c1998b7a0_story.html |url-status=live }} which was claimed by Guccifer 2.0.{{Cite web |last=Mackey |first=Robert |date=July 26, 2016 |title=If Russian Intelligence Did Hack the DNC, the NSA Would Know, Snowden Says |url=https://theintercept.com/2016/07/26/russian-intelligence-hack-dnc-nsa-know-snowden-says/ |access-date=July 27, 2016 |website=The Intercept |archive-date=November 21, 2021 |archive-url=https://web.archive.org/web/20211121203432/https://theintercept.com/2016/07/26/russian-intelligence-hack-dnc-nsa-know-snowden-says/ |url-status=live }}

On July 18, 2016, Guccifer 2.0 provided exclusively to The Hill numerous documents and files covering political strategies, including correlating the banks that received bailout funds with Republican Party and Democratic Party donations.

On July 22, 2016, Guccifer 2.0 stated he hacked, then leaked, the DNC emails to WikiLeaks.{{Cite web |last=Uchill |first=Joe |date=July 22, 2016 |title=WikiLeaks posts 20,000 DNC emails |url=https://thehill.com/policy/cybersecurity/288883-wikileaks-posts-20000-dnc-emails/ |access-date=July 24, 2016 |website=The Hill |language=en-US |archive-date=July 25, 2016 |archive-url=https://web.archive.org/web/20160725134552/http://thehill.com/policy/cybersecurity/288883-wikileaks-posts-20000-dnc-emails |url-status=live }}{{Cite web |last=Biddle |first=Sam |date=July 22, 2016 |title=New Leak: Top DNC Official Wanted to Use Bernie Sanders's Religious Beliefs Against Him |url=https://theintercept.com/2016/07/22/new-leak-top-dnc-official-wanted-to-use-bernie-sanderss-religious-beliefs-against-him/ |access-date=July 24, 2016 |website=The Intercept |archive-date=October 6, 2021 |archive-url=https://web.archive.org/web/20211006181933/https://theintercept.com/2016/07/22/new-leak-top-dnc-official-wanted-to-use-bernie-sanderss-religious-beliefs-against-him/ |url-status=live }} "Wikileaks published #DNCHack docs I'd given them!!!", tweeted Guccifer 2.0.

On September 13, 2016, during a conference, an unknown and remote representative of Guccifer 2.0 released almost 700 megabytes (MB) worth of documents from the DNC.{{Cite web |last=Winter |first=Tom |date=September 13, 2016 |title='Guccifer 2.0' releases more DNC docs, including Tim Kaine's cell number |url=https://www.nbcnews.com/news/us-news/hacker-guccifer-2-0-releases-more-dnc-docs-including-tim-n647921 |access-date=September 23, 2016 |publisher=NBCNews.com |archive-date=September 22, 2016 |archive-url=https://web.archive.org/web/20160922223026/http://www.nbcnews.com/news/us-news/hacker-guccifer-2-0-releases-more-dnc-docs-including-tim-n647921 |url-status=live }} Forbes also obtained a copy of those.{{Cite web |last=Fox-Brewster |first=Thomas |date=September 13, 2016 |title=Democrat Hacker Guccifer 2.0 'Appears' At London Show—Here's What Was Said |url=https://www.forbes.com/sites/thomasbrewster/2016/09/13/hacker-guccifer-2-0-dnc-hacker-london-slags-tech-companies/#1cfb9f9c35e0 |access-date=September 23, 2016 |website=Forbes |archive-date=September 23, 2016 |archive-url=https://web.archive.org/web/20160923200815/http://www.forbes.com/sites/thomasbrewster/2016/09/13/hacker-guccifer-2-0-dnc-hacker-london-slags-tech-companies/#1cfb9f9c35e0 |url-status=live }} On September 12, 2016, ahead of that conference, Guccifer posted a public Twitter message in which he confirmed that his representative was legitimate. The Russian government denied any involvement. The DNC, the DCCC, U.S. intelligence officials, and other experts speculated about Russia involvement. NGP VAN, who state they are the "leading technology provider" for the Democratic campaigns, declined to comment on Guccifer 2.0's recent statements.

On October 4, 2016, Guccifer 2.0 released documents and claimed that they were taken from the Clinton Foundation and showed "corruption and malfeasance" there.Lily Hay Newman, [https://www.wired.com/2016/10/even-fake-clinton-foundation-hack-can-serious-damage/ Even a Fake Clinton Foundation Hack and Can Do Serious Damage] {{Webarchive|url=https://web.archive.org/web/20220819045452/https://www.wired.com/2016/10/even-fake-clinton-foundation-hack-can-serious-damage/ |date=August 19, 2022 }}, Wired (October 7, 2016). Security experts quickly determined that the release was a hoax; the release did not contain Clinton Foundation documents, but rather consisted of documents previously released from the DNC and DCCC thefts, data aggregated from public records, and documents that were fabricated altogether as propaganda.{{Cite web |last=Gallagher |first=Sean |title=Guccifer 2.0 posts DCCC docs, says they're from Clinton Foundation |date=October 4, 2016 |url=https://arstechnica.com/security/2016/10/guccifer-2-0-posts-dccc-docs-says-theyre-from-clinton-foundation/ |access-date=October 21, 2016 |publisher=Ars Technica |archive-date=October 20, 2016 |archive-url=https://web.archive.org/web/20161020234151/http://arstechnica.com/security/2016/10/guccifer-2-0-posts-dccc-docs-says-theyre-from-clinton-foundation/ |url-status=live }} Singled out as particularly unrealistic was the idea that Clinton's team would have actually named a file "Pay for Play" on their own server, as Guccifer 2.0's screenshots of the alleged "hack" show.{{Cite news |last=Vankin |first=Jonathan |date=October 4, 2016 |title=READ: Guccifer 2.0 Clinton Foundation Hacked Documents |language=en-US |publisher=Heavy.com |url=http://heavy.com/news/2016/10/clinton-foundation-hacked-guccifer-2-0-russia-hacking-vladimir-putin/ |access-date=October 8, 2016 |archive-date=October 7, 2016 |archive-url=https://web.archive.org/web/20161007163555/http://heavy.com/news/2016/10/clinton-foundation-hacked-guccifer-2-0-russia-hacking-vladimir-putin/ |url-status=live }}

Former Trump confidant Roger Stone was in contact with Guccifer 2.0 during the campaign.{{Cite web |last1=Borger |first1=Gloria |last2=Korade |first2=Matt |title=Trump associate plays down Twitter contact with Guccifer 2.0 |url=http://www.cnn.com/2017/03/12/politics/stone-guccifer-2-0-messages/index.html |website=CNN |date=March 12, 2017 |access-date=December 29, 2017 |archive-date=May 8, 2019 |archive-url=https://web.archive.org/web/20190508152629/https://www.cnn.com/2017/03/12/politics/stone-guccifer-2-0-messages/index.html |url-status=live }}

Communications with WikiLeaks

A week after Guccifer 2.0 appeared online, WikiLeaks sent the persona a message saying to "send any new material here for us to review and it will have a much higher impact than what you are doing."{{Cite web |date=July 18, 2018 |first=Micah |last=Lee |title=What Mueller's Latest Indictment Reveals About Russian and U.S. Spycraft |url=https://theintercept.com/2018/07/18/mueller-indictment-russian-hackers/ |access-date=2022-07-27 |website=The Intercept |language=en |archive-date=August 16, 2022 |archive-url=https://web.archive.org/web/20220816173205/https://theintercept.com/2018/07/18/mueller-indictment-russian-hackers/ |url-status=live }} After not receiving a reply, on July 6, 2016 WikiLeaks sent another message that said "if you have anything hillary related we want it in the next tweo [sic] days prefable [sic] because the DNC is approaching and she will solidify bernie supporters behind her after." Guccifer 2.0 responded "ok ... i see," and WikiLeaks added "we think trump has only a 25% chance of winning against hillary ... so conflict between bernie and hillary is interesting."{{Cite web |last=Nilsen |first=Ella |date=2018-07-13 |title=The Mueller indictments reveal the timing of the DNC leak was intentional |url=https://www.vox.com/2018/7/13/17569030/mueller-indictments-russia-hackers-bernie-sanders-hillary-clinton-democratic-national-convention |access-date=2022-07-27 |website=Vox |language=en |archive-date=September 1, 2022 |archive-url=https://web.archive.org/web/20220901060927/https://www.vox.com/2018/7/13/17569030/mueller-indictments-russia-hackers-bernie-sanders-hillary-clinton-democratic-national-convention |url-status=live }} On July 14, 2016 Guccifer 2.0 sent WikiLeaks an email with an encrypted attachment labeled "wk dnc link1.txt.gpg." According to the indictment, the email explained that "the encrypted file contained instructions on how to access an online archive of stolen DNC documents."

Four days later, WikiLeaks responded that it had received "the 1Gb or so archive" and would release the files that week. The DNC emails were released several days later.

Post-election activities

The Guccifer 2.0 persona went dark just before the U.S. presidential election, and resurfaced on January 12, 2017, following the public release of the Steele dossier that asserted the Trump campaign was cooperating with the Russians in their interference in the 2016 presidential election. The dossier also asserted that "Romanian hackers" had performed the hacks.

The Guccifer 2.0 persona made a blog post denying that they had any relation to the Russian government, and calling the technical evidence suggesting links to the Russian government "a crude fake." In the blog post, Guccifer 2.0 indicated they had gained access to the DNC servers through a vulnerability in their NGP VAN software.{{Cite web |date=January 12, 2017 |title=Here I am Again, My Friends! |url=https://guccifer2.wordpress.com/2017/01/12/fake-evidence/ |publisher=WordPress |access-date=January 13, 2017 |archive-date=March 12, 2017 |archive-url=https://web.archive.org/web/20170312215726/https://guccifer2.wordpress.com/2017/01/12/fake-evidence/ |url-status=live }}

Timeline of Guccifer 2.0

;2016

  • June: Around this time, the conspirators charged in the July 2018 indictment stage and release tens of thousands of stolen emails and documents using fictitious online personas, including "DCLeaks" and "Guccifer 2.0".{{Cite web |first=Steven |last=Rich |title=Netyksho Et Al Indictment |url=https://www.documentcloud.org/documents/4598929-Netyksho-Et-Al-Indictment.html |website=www.documentcloud.org |access-date=August 12, 2019 |archive-date=July 13, 2018 |archive-url=https://web.archive.org/web/20180713200542/https://www.documentcloud.org/documents/4598929-Netyksho-Et-Al-Indictment.html |url-status=live }}
  • June 15: "Guccifer 2.0" (GRU) claims credit for the DNC hacking and posts some of the stolen material to a website. CrowdStrike stands by its "findings identifying two separate Russian intelligence-affiliated adversaries present in the DNC network in May 2016."{{Cite news |last=Nakashima |first=Ellen |date=June 15, 2016 |title='Guccifer 2.0' claims credit for DNC hack |newspaper=The Washington Post |url=https://www.washingtonpost.com/world/national-security/guccifer-20-claims-credit-for-dnc-hack/2016/06/15/abdcdf48-3366-11e6-8ff7-7b6c1998b7a0_story.html |access-date=March 14, 2018 |archive-date=April 17, 2018 |archive-url=https://web.archive.org/web/20180417013555/https://www.washingtonpost.com/world/national-security/guccifer-20-claims-credit-for-dnc-hack/2016/06/15/abdcdf48-3366-11e6-8ff7-7b6c1998b7a0_story.html |url-status=live }} Gawker publishes an opposition research document on Trump that was stolen from the DNC. "Guccifer 2.0" sent the file to Gawker.{{Cite news |last=Bump |first=Philip |date=July 13, 2018 |title=Timeline: How Russian agents allegedly hacked the DNC and Clinton's campaign |url=https://www.washingtonpost.com/news/politics/wp/2018/07/13/timeline-how-russian-agents-allegedly-hacked-the-dnc-and-clintons-campaign |access-date=July 15, 2018 |newspaper=The Washington Post |archive-date=February 16, 2021 |archive-url=https://web.archive.org/web/20210216023021/https://www.washingtonpost.com/news/politics/wp/2018/07/13/timeline-how-russian-agents-allegedly-hacked-the-dnc-and-clintons-campaign/ |url-status=live }}{{Cite web |last1=Biddle |first1=Sam |author-link=Sam Biddle |last2=Bluestone |first2=Gabrielle |date=June 15, 2016 |title=This Looks Like the DNC's Hacked Trump Oppo File |url=http://gawker.com/this-looks-like-the-dncs-hacked-trump-oppo-file-1782040426 |access-date=July 15, 2018 |website=Gawker |archive-date=July 24, 2018 |archive-url=https://web.archive.org/web/20180724221405/http://gawker.com/this-looks-like-the-dncs-hacked-trump-oppo-file-1782040426 |url-status=live }}
  • June 22: WikiLeaks reaches out to "Guccifer 2.0" via Twitter. They ask "Guccifer 2.0" to send them material because it will have a bigger impact if they publish it. They also specifically ask for material on Clinton they can publish before the convention.
  • July 6: "Guccifer 2.0" releases another cache of DNC documents and sends copies to The Hill.{{Cite web |title=Trumpocalypse and other DNC plans for July |url=https://guccifer2.wordpress.com/2016/07/06/trumpocalypse |archive-url=https://web.archive.org/web/20160706232502/https://guccifer2.wordpress.com/2016/07/06/trumpocalypse |archive-date=July 6, 2016 |access-date=March 14, 2016 |publisher=WordPress |via=Internet Archive}}{{Cite news |last=Uchill |first=Joe |date=July 13, 2016 |title=Guccifer 2.0 releases new DNC docs |work=The Hill |url=https://thehill.com/policy/cybersecurity/287558-guccifer-20-drops-new-dnc-docs/ |access-date=March 14, 2018 |archive-date=July 29, 2016 |archive-url=https://web.archive.org/web/20160729012045/http://thehill.com/policy/cybersecurity/287558-guccifer-20-drops-new-dnc-docs |url-status=live }}
  • July 13: "Guccifer 2.0" releases over 10,000 names from the DNC in two spreadsheets and a list of objectionable quotes from Sarah Palin.
  • July 14: Four days after the murder of Seth Rich, "Guccifer 2.0" sends Assange an encrypted one-gigabyte file containing stolen DNC emails, and Assange confirms that he received it. WikiLeaks publishes the file's contents on July 22. The Mueller report asserts that Assange was "working to shift blame onto [Seth Rich] to obscure the source of the materials he was releasing".{{Cite news |last=Poulsen |first=Kevin |date=April 18, 2019 |title=Mueller Report: Assange Smeared Seth Rich to Cover for Russians |url=https://www.thedailybeast.com/mueller-report-julian-assange-smeared-seth-rich-to-cover-for-russians |access-date=April 22, 2019 |website=The Daily Beast |quote=Julian Assange not only knew that a murdered Democratic National Committee staffer wasn't his source for thousands of hacked party emails, he was in active contact with his real sources in Russia's GRU months after Seth Rich's death. At the same time he was publicly working to shift blame onto the slain staffer "to obscure the source of the materials he was releasing," Special Counsel Robert Mueller asserts in his final report on Russia's role in the 2016 presidential election. |archive-date=April 19, 2019 |archive-url=https://web.archive.org/web/20190419141652/https://www.thedailybeast.com/mueller-report-julian-assange-smeared-seth-rich-to-cover-for-russians |url-status=live }} The Senate Intelligence Committee reported that "WikiLeaks actively sought, and played, a key role in the Russian intelligence campaign and very likely knew it was assisting a Russian intelligence influence effort."{{cite web |publisher=Senate Intelligence Committee |date= |title=Counterintelligence Threats and Vulnerabilities |website=senate.gov |url=https://www.intelligence.senate.gov/sites/default/files/documents/report_volume5.pdf |access-date=December 12, 2021 |quote=WikiLeaks actively sought, and played, a key role in the Russian intelligence campaign and very likely knew it was assisting a Russian intelligence influence effort. |archive-date=January 22, 2021 |archive-url=https://web.archive.org/web/20210122003727/https://www.intelligence.senate.gov/sites/default/files/documents/report_volume5.pdf |url-status=live }}
  • July 18: "Guccifer 2.0" dumps a new batch of documents from the DNC servers, including personal information of 20,000 Democratic donors and opposition research on Trump.{{Cite news |last=Uchill |first=Joe |date=July 18, 2016 |title=New Guccifer 2.0 dump highlights 'wobbly Dems' on Iran deal |work=The Hill |url=https://thehill.com/policy/cybersecurity/288119-new-guccifer-20-dump-highlights-wobbly-dems-on-iran-deal/ |access-date=July 27, 2016 |archive-date=July 29, 2016 |archive-url=https://web.archive.org/web/20160729012053/http://thehill.com/policy/cybersecurity/288119-new-guccifer-20-dump-highlights-wobbly-dems-on-iran-deal |url-status=live }}
  • August 5: Stone writes an article for Breitbart News in which he insists "Guccifer 2.0" hacked the DNC, using statements by "Guccifer 2.0" on Twitter and to The Hill as evidence for his claim. He tries to spin the DNC's Russia claim as a coverup for their supposed embarrassment over being penetrated by a single hacker.{{Cite news |last=Goodman |first=Ryan |date=September 28, 2017 |title=How Roger Stone Interacted with Russia's Guccifer and WikiLeaks |work=Newsweek |url=http://www.newsweek.com/how-stone-interacted-russias-guccifer-and-wikileaks-673268 |access-date=March 15, 2018 |archive-date=February 16, 2021 |archive-url=https://web.archive.org/web/20210216023006/https://www.newsweek.com/how-stone-interacted-russias-guccifer-and-wikileaks-673268 |url-status=live }} The article leads to "Guccifer 2.0" reaching out to and conversing with Stone via Twitter.{{Cite news |last=Blake |first=Andrew |date=March 10, 2017 |title=Roger Stone, Trump confidant, acknowledges 'innocuous' Twitter conversation with DNC hackers |work=The Washington Times |url=https://www.washingtontimes.com/news/2017/mar/10/roger-stone-trump-confidant-acknowledges-innocuous/ |access-date=March 15, 2018 |archive-date=February 16, 2021 |archive-url=https://web.archive.org/web/20210216023006/https://www.washingtontimes.com/news/2017/mar/10/roger-stone-trump-confidant-acknowledges-innocuous/ |url-status=live }}
  • August 12:
  • "Guccifer 2.0" releases a cache of documents stolen from the Democratic Congressional Campaign Committee.
  • Journalist Emma Best has two simultaneous conversations by Twitter direct message with "Guccifer 2.0" and WikiLeaks. Best tries to negotiate the hosting of stolen DNC emails and documents on archive.org. WikiLeaks wants Best to act as an intermediary to funnel the material from "Guccifer 2.0" to them. The conversation ends with "Guccifer 2.0" saying he will send the material directly to WikiLeaks.{{Cite news |last=Collier |first=Kevin |date=April 5, 2018 |title=These Messages Show Julian Assange Talked About Seeking Hacked Files From Guccifer 2.0 |work=Buzzfeed News |url=https://www.buzzfeed.com/kevincollier/assange-seth-rich-lies-guccifer-wikileaks-hannity |access-date=April 6, 2018 |archive-date=April 7, 2018 |archive-url=https://web.archive.org/web/20180407183359/https://www.buzzfeed.com/kevincollier/assange-seth-rich-lies-guccifer-wikileaks-hannity |url-status=live }}
  • August 13:
  • Twitter and WordPress temporarily suspend Guccifer 2.0's accounts.{{Cite web |last=Loffredo |first=Nicholas |date=August 13, 2016 |title='Guccifer 2.0' Suspended From Twitter After Latest Hack of Democrats |url=https://www.newsweek.com/guccifer-20-twitter-suspended-dccc-hack-490165 |access-date=July 15, 2018 |website=Newsweek |archive-date=February 16, 2021 |archive-url=https://web.archive.org/web/20210216023010/https://www.newsweek.com/guccifer-20-twitter-suspended-dccc-hack-490165 |url-status=live }} Stone calls "Guccifer 2.0" a hero.
  • August 15:
  • A candidate for Congress allegedly contacts Guccifer 2.0 to request information on the candidate's opponent. Guccifer 2.0 responds with the requested stolen information.
  • Guccifer 2.0 begins posting information about Florida and Pennsylvania races stolen from the DCCC.
  • The GRU stops its five-attempts-per-second attack on the Illinois State Board of Elections servers.{{Cite web |last=Sweet |first=Lynn |author-link=Lynn Sweet |date=June 7, 2017 |title=Illinois' chapter in the Russian hacking saga |url=https://chicago.suntimes.com/politics/illinois-chapter-in-the-russian-hacking-saga/ |access-date=April 23, 2019 |website=Chicago Sun Times |archive-date=April 23, 2019 |archive-url=https://web.archive.org/web/20190423194003/https://chicago.suntimes.com/politics/illinois-chapter-in-the-russian-hacking-saga/ |url-status=live }}{{Cite news |last=Sweet |first=Lynn |author-link=Lynn Sweet |date=April 18, 2019 |title=Mueller report confirms Russians 'compromised' Illinois State Board of Elections |url=https://chicago.suntimes.com/news/mueller-report-special-counsel-russia-hacking-illinois-state-board-elections/ |access-date=April 23, 2019 |website=Chicago Sun Times |archive-date=April 19, 2019 |archive-url=https://web.archive.org/web/20190419144047/https://chicago.suntimes.com/news/mueller-report-special-counsel-russia-hacking-illinois-state-board-elections/ |url-status=live }}
  • August 16: Stone sends "Guccifer 2.0" an article{{Cite web |last=Stone |first=Roger |author-link=Roger Stone |date=August 16, 2016 |title=Can the 2016 election be rigged? You bet |url=https://thehill.com/blogs/pundits-blog/presidential-campaign/291534-can-the-2016-election-be-rigged-you-bet/ |access-date=July 13, 2018 |website=The Hill |archive-date=February 16, 2021 |archive-url=https://web.archive.org/web/20210216023016/https://thehill.com/blogs/pundits-blog/presidential-campaign/291534-can-the-2016-election-be-rigged-you-bet |url-status=live }} he wrote for The Hill on manipulating the vote count in voting machines.{{Cite news |last1=Helderman |first1=Rosalind S. |last2=Roig-Franzia |first2=Manuel |date=July 13, 2018 |title=Charges against Russian intelligence officers intensify spotlight on Trump adviser Roger Stone |url=https://www.washingtonpost.com/politics/charges-against-russian-intelligence-officers-intensify-spotlight-on-trump-adviser-roger-stone/2018/07/13/ba0d0caa-86bb-11e8-8553-a3ce89036c78_story.html |access-date=July 13, 2018 |newspaper=The Washington Post |archive-date=July 13, 2018 |archive-url=https://web.archive.org/web/20180713220145/https://www.washingtonpost.com/politics/charges-against-russian-intelligence-officers-intensify-spotlight-on-trump-adviser-roger-stone/2018/07/13/ba0d0caa-86bb-11e8-8553-a3ce89036c78_story.html |url-status=live }} "Guccifer 2.0" responds the next day, "@RogerJStoneJr paying u back".
  • August 22:
  • "Guccifer 2.0" allegedly sends DCCC material on Black Lives Matter to a reporter, and they discuss how to use it in a story. "Guccifer 2.0" also gives the reporter the password for accessing emails stolen from Clinton's staff that were posted to "Guccifer 2.0's" website but had not yet been made public. On August 31, The Washington Examiner publishes a story based on the material the same day the material is released publicly on Guccifer 2.0's website.{{Cite web |last=Glaser |first=April |date=July 13, 2018 |title=What the Latest Mueller Indictment Reveals About Guccifer 2.0 |url=https://slate.com/technology/2018/07/the-mueller-indictment-and-guccifer-2-0-what-we-now-know.html |access-date=April 22, 2019 |website=Slate |archive-date=April 23, 2019 |archive-url=https://web.archive.org/web/20190423023053/https://slate.com/technology/2018/07/the-mueller-indictment-and-guccifer-2-0-what-we-now-know.html |url-status=live }}
  • Florida GOP campaign advisor Aaron Nevins contacts Guccifer 2.0 and asks for material. Nevins sets up a Dropbox account and "Guccifer 2.0" transfers 2.5 gigabytes of data into it. Nevins analyzes the data, posts the results on his blog, HelloFLA.com, and sends "Guccifer 2.0" a link. "Guccifer 2.0" forwards the link to Stone.{{Cite web |last=Gallagher |first=Sean |date=May 25, 2017 |title=Florida GOP consultant admits he worked with "Guccifer 2.0", analyzing hacked data |url=https://arstechnica.com/tech-policy/2017/05/florida-gop-consultant-admits-he-worked-with-guccifer-2-0-analyzing-hacked-data/ |access-date=July 15, 2018 |website=Ars Technica |archive-date=July 13, 2018 |archive-url=https://web.archive.org/web/20180713234840/https://arstechnica.com/tech-policy/2017/05/florida-gop-consultant-admits-he-worked-with-guccifer-2-0-analyzing-hacked-data/ |url-status=live }}
  • August 23: The Smoking Gun reaches out to "Guccifer 2.0" for comment on its contacts with Stone. "Guccifer 2.0" accuses The Smoking Gun of working with the FBI.{{Cite web |last=Bastone |first=William |date=March 8, 2017 |title=Roger Stone's Russian Hacking "Hero" |url=http://thesmokinggun.com/documents/investigation/roger-stone-and-guccifer-913684 |access-date=July 14, 2018 |website=The Smoking Gun |archive-date=July 15, 2018 |archive-url=https://web.archive.org/web/20180715094452/http://thesmokinggun.com/documents/investigation/roger-stone-and-guccifer-913684 |url-status=live }}
  • August 31: "Guccifer 2.0" leaks campaign documents stolen from House Minority Leader Nancy Pelosi's hacked personal computer.{{Cite news |last=Uchill |first=Joe |date=August 31, 2016 |title=Guccifer 2.0 leaks docs from 'Pelosi's PC' |work=The Hill |url=https://thehill.com/business-a-lobbying/293958-guccifer-20-leaks-docs-from-pelosis-pc/ |access-date=March 15, 2018 |archive-date=March 16, 2018 |archive-url=https://web.archive.org/web/20180316151821/http://thehill.com/business-a-lobbying/293958-guccifer-20-leaks-docs-from-pelosis-pc |url-status=live }}{{Cite news |date=August 31, 2016 |title=DCCC Docs from Pelosi's PC |newspaper=Guccifer 2.0 |url=https://guccifer2.wordpress.com/2016/08/31/pelosi/ |archive-url=https://web.archive.org/web/20160831231344/https://guccifer2.wordpress.com/2016/08/31/pelosi |archive-date=August 31, 2016 |access-date=March 15, 2018 |via=Internet Archive}}
  • September 3–5: Wealthy Republican donor Peter W. Smith gathers a team to try to acquire the 30,000 deleted Clinton emails from hackers. He believes Clinton's private email server was hacked and copies of the emails were stolen. Among the people recruited are former GCHQ information-security specialist Matt Tait,{{Cite news |last=Bertrand |first=Natasha |date=October 16, 2017 |title=Mueller has interviewed the cybersecurity expert who said he was 'recruited to collude with the Russians' |work=Business Insider |url=https://www.businessinsider.com/mueller-trump-russia-matt-tait-michael-flynn-investigation-2017-10?r=US&IR=T |access-date=August 12, 2019 |archive-date=October 18, 2017 |archive-url=https://web.archive.org/web/20171018013628/http://uk.businessinsider.com/mueller-trump-russia-matt-tait-michael-flynn-investigation-2017-10?r=US&IR=T |url-status=live }} alt-right activist Charles C. Johnson, former Business Insider CTO and alt-right activist Pax Dickinson, "dark web expert" Royal O'Brien, and Jonathan Safron.{{Cite web |last=Schreckinger |first=Ben |date=July 11, 2017 |title=GOP Researcher Who Sought Clinton Emails Had Alt-Right Help |url=https://www.politico.com/magazine/story/2017/07/11/gop-researcher-who-sought-clinton-emails-had-alt-right-help-215359 |access-date=August 13, 2018 |website=Politico |archive-date=November 20, 2017 |archive-url=https://web.archive.org/web/20171120135724/https://www.politico.com/magazine/story/2017/07/11/gop-researcher-who-sought-clinton-emails-had-alt-right-help-215359 |url-status=live }} Tait quickly abandons the team after learning the true purpose of the endeavor. Hackers contacted in the search include "Guccifer 2.0" and Andrew Auernheimer (a.k.a. "weev"). The team finds five groups of hackers claiming to have the emails. Two of the groups are Russian. Flynn is in email contact with the team. Smith commits suicide on May 14, 2017, about ten days after telling the story to The Wall Street Journal but before the story is published in June.{{Cite news |last1=Skiba |first1=Katherine |last2=Heinzmann |first2=David |last3=Lighty |first3=Todd |date=July 13, 2017 |title=Peter W. Smith, GOP operative who sought Clinton's emails from Russian hackers, committed suicide, records show |url=http://www.chicagotribune.com/news/local/politics/ct-peter-smith-death-met-0713-20170713-story.html |access-date=March 15, 2018 |website=Chicago Tribune |archive-date=July 14, 2017 |archive-url=https://web.archive.org/web/20170714000457/http://www.chicagotribune.com/news/local/politics/ct-peter-smith-death-met-0713-20170713-story.html |url-status=live }}
  • September 15: "Guccifer 2.0" sends a Twitter direct message to DCLeaks informing them that WikiLeaks is trying to contact them to set up communications using encrypted emails.
  • October 5: Trump Jr. retweets a WikiLeaks tweet announcing an "860Mb [sic]" archive of various Clinton campaign documents from "Guccifer 2.0".{{Cite web |last=The Minority Members of the House Permanent Select Committee on Intelligence |author-link=United States House Permanent Select Committee on Intelligence |date=March 26, 2018 |title=Minority Views |url=https://upload.wikimedia.org/wikipedia/commons/a/a9/HRPT-115-2_Minority_Views.pdf |access-date=April 24, 2019 |archive-date=March 22, 2019 |archive-url=https://web.archive.org/web/20190322102730/https://upload.wikimedia.org/wikipedia/commons/a/a9/HRPT-115-2_Minority_Views.pdf |url-status=live }}
  • October 7: At 12:40 PM EDT,{{Cite web |last=Mayer |first=Jane |author-link=Jane Mayer |date=October 1, 2018 |title=How Russia Helped Swing the Election for Trump |url=https://www.newyorker.com/magazine/2018/10/01/how-russia-helped-to-swing-the-election-for-trump |access-date=September 24, 2018 |website=NewYorker.com |archive-date=July 18, 2019 |archive-url=https://web.archive.org/web/20190718145515/https://www.newyorker.com/magazine/2018/10/01/how-russia-helped-to-swing-the-election-for-trump |url-status=live }} The DHS and the ODNI issue a joint statement{{Cite web |date=October 7, 2016 |title=Joint Statement from the Department Of Homeland Security and Office of the Director of National Intelligence on Election Security |url=https://www.dhs.gov/news/2016/10/07/joint-statement-department-homeland-security-and-office-director-national |access-date=April 10, 2017 |publisher=Department of Homeland Security |archive-date=December 10, 2016 |archive-url=https://web.archive.org/web/20161210004335/https://www.dhs.gov/news/2016/10/07/joint-statement-department-homeland-security-and-office-director-national |url-status=live }} accusing the Russian government of breaking into the computer systems of several political organizations and releasing the obtained material via DCLeaks, WikiLeaks, and "Guccifer 2.0", with the intent "to interfere with the U.S. election process."{{Cite news |last=Nakashima |first=Ellen |title=U.S. government officially accuses Russia of hacking campaign to interfere with elections |newspaper=The Washington Post |url=https://www.washingtonpost.com/world/national-security/us-government-officially-accuses-russia-of-hacking-campaign-to-influence-elections/2016/10/07/4e0b9654-8cbf-11e6-875e-2c1bfe943b66_story.html |access-date=October 7, 2016 |archive-date=January 25, 2017 |archive-url=https://web.archive.org/web/20170125032340/https://www.washingtonpost.com/world/national-security/us-government-officially-accuses-russia-of-hacking-campaign-to-influence-elections/2016/10/07/4e0b9654-8cbf-11e6-875e-2c1bfe943b66_story.html |url-status=live }}

;2017

  • January 12: "Guccifer 2.0" denies having any relation to the Russian government.{{Cite web |date=January 12, 2017 |title=Here I am Again, My Friends! |url=https://guccifer2.wordpress.com/2017/01/12/fake-evidence/ |access-date=July 15, 2018 |website=Guccifer 2.0 |archive-date=March 12, 2017 |archive-url=https://web.archive.org/web/20170312215726/https://guccifer2.wordpress.com/2017/01/12/fake-evidence/ |url-status=live }}
  • March 10: Roger Stone admits to communicating with Guccifer 2.0.
  • March 13: Senate Intelligence Committee Chairman Richard Burr says Roger Stone's communications with Guccifer 2.0 are part of the Committee's ongoing investigation.{{Cite web |last1=Raju |first1=Manu |last2=Schleifer |first2=Theodore |last3=Killough |first3=Ashley |date=March 14, 2017 |title=Justice department asks for more time to collect evidence on Trump wiretap claims |url=https://www.cnn.com/2017/03/13/politics/intelligence-deadline-wiretaps/ |access-date=March 19, 2018 |publisher=CNN |archive-date=March 20, 2018 |archive-url=https://web.archive.org/web/20180320105831/https://www.cnn.com/2017/03/13/politics/intelligence-deadline-wiretaps/ |url-status=live }}

;2018

  • March 22: The Daily Beast reports that Guccifer 2.0, the "lone hacker" who took credit for providing WikiLeaks with stolen emails from the Democratic National Committee, was in fact an officer of Russia's military intelligence directorate (GRU) and that Mueller has taken over the investigation into his criminal activities and his direct contact with Stone.{{Cite news |last1=Poulsen |first1=Kevin |last2=Ackerman |first2=Spencer |date=March 22, 2018 |title=EXCLUSIVE: 'Lone DNC Hacker' Guccifer 2.0 Slipped Up and Revealed He Was a Russian Intelligence Officer |language=en |work=The Daily Beast |url=https://www.thedailybeast.com/exclusive-lone-dnc-hacker-guccifer-20-slipped-up-and-revealed-he-was-a-russian-intelligence-officer |access-date=March 23, 2018 |archive-date=March 23, 2018 |archive-url=https://web.archive.org/web/20180323000034/https://www.thedailybeast.com/exclusive-lone-dnc-hacker-guccifer-20-slipped-up-and-revealed-he-was-a-russian-intelligence-officer |url-status=live }}
  • June 18: Lawyers for Andrew Miller, a former associate of Roger Stone, challenge in court a subpoena he received for information about Stone, WikiLeaks, "Guccifer 2.0", "DCLeaks", and Julian Assange. Miller's lawyer Alicia Dearn asserts at the hearing that Miller had asked for immunity regarding political action committee transactions involving himself and Stone.{{Cite news |last1=Hsu |first1=Spencer S. |last2=Barrett |first2=Devlin |date=August 10, 2018 |title=Judge holds Roger Stone associate in contempt for refusing to testify in Russia investigation |url=https://www.washingtonpost.com/world/national-security/witness-in-mueller-probe-refuses-to-appear-before-grand-jury/2018/08/10/73e27130-9ca4-11e8-843b-36e177f3081c_story.html |access-date=August 10, 2018 |newspaper=The Washington Post |archive-date=August 10, 2018 |archive-url=https://web.archive.org/web/20180810163126/https://www.washingtonpost.com/world/national-security/witness-in-mueller-probe-refuses-to-appear-before-grand-jury/2018/08/10/73e27130-9ca4-11e8-843b-36e177f3081c_story.html |url-status=live }}

See also

References

{{reflist|30em}}