Russian GRU officers spoofed Google security-alert emails to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails.
Social Engineering Examples·6 sources
Beginning in at least March 2016, GRU officers ran a spear-phishing campaign against more than 300 people affiliated with the Clinton campaign, DNC, and DCCC. The lures were emails crafted to look like Google security notifications ("Someone just used your password to try to sign in to your Google Account... You should change your password immediately"), with the malicious link hidden behind a Bitly URL-shortener.
On March 19, 2016, GRU officer Aleksey Lukashev (using the Bitly account "john356gh") sent such an email to campaign chairman John Podesta. Podesta's team forwarded it to IT aide Charles Delavan, who meant to warn that it was illegitimate but wrote "This is a legitimate email" (he later told the New York Times he intended to type "not a legitimate email" and omitted the word).
The link was clicked and credentials were entered; on March 21, 2016 the GRU stole the contents of Podesta's account, over 50,000 emails. The same technique compromised numerous other staffers, including a later wave on March 25, 2016 sent from a spoofed Russia-based Yandex account. Attribution is confirmed: Secureworks documented the Bitly infrastructure in 2016, the U.S. intelligence community attributed the operation to Russia, and the July 13, 2018 Mueller indictment (US v. Netyksho et al.) charged twelve named GRU officers with the intrusions and staged leaks.
The emails impersonated a trusted brand (Google) and used a fabricated security-alert pretext: a supposed unauthorized sign-in attempt, sometimes citing an IP address and a foreign location, demanding an immediate password change. The malicious destination, a GRU-controlled page that spoofed the real Google login screen, was hidden behind Bitly short links so recipients could not see the true URL.
Per Secureworks, the phishing URL carried a Base64-encoded copy of the victim's own email address so the fake login page arrived pre-filled with their address, increasing believability. Because the Clinton campaign and DNC used Google/Gmail for mail, staff were conditioned to expect exactly this kind of Google login prompt. Entering credentials on the decoy page handed the attackers a live session and full mailbox access.
The campaign was reconnaissance-driven and personalized; per the Mueller indictment, GRU officer Ivan Yermakov researched targets' names and Clinton-campaign affiliations on social media, placing it at the hyper-targeted end of spear phishing.
Lure: a fake Google "Someone has your password / suspicious sign-in" alert urging an urgent password reset via an embedded (Bitly-shortened) link. Tells: the sender address was spoofed rather than a genuine Google domain (one wave sent from a Russia-based Yandex account); the action link was a shortened URL masking a non-Google destination; and the fastest safe check, appending a "+" to a Bitly link or navigating to Google account settings directly instead of clicking, would have exposed the decoy login domain.
Podesta's 50,000+ emails and large volumes of DNC and DCCC material were exfiltrated and staged for release through the DCLeaks site, the Guccifer 2.0 persona, and WikiLeaks across summer and fall 2016, becoming a dominant story of the U.S. election. Twelve GRU officers were indicted by name in July 2018; none have been arrested, and they remain in Russia.
Secureworks' analysis of Bitly-link datasets, roughly 8,900 links analyzed in its original 2016 report and a separate 19,000-link dataset it later shared that underpinned a 2017 Associated Press reconstruction, provided much of the forensic backbone for public attribution.
This is the canonical case that credential-harvesting spear phishing, not malware, is enough to compromise the highest-value targets: a single spoofed security alert and one clicked link opened a presidential campaign to a nation-state. It also shows how a human escalation step meant to protect the target (asking IT) can backfire, how brand-mimicking "reset your password" pretexts exploit good security hygiene messaging, and how URL shorteners defeat casual link inspection.
It set the template studied in nearly every modern phishing-awareness program.
Enforce phishing-resistant MFA (hardware security keys / FIDO2) so stolen passwords alone cannot grant access. Treat any "change your password" link in an inbound email as suspect; navigate to account security settings directly rather than clicking. Expand short links before trusting them (append "+" to a Bitly URL to preview the destination) and verify the true login domain before entering credentials.
Deploy DMARC/SPF/DKIM and anti-spoofing controls, external-sender banners, and link rewriting/sandboxing. Give high-risk staff (executives, comms, finance, IT) targeted training and a fast, unambiguous IT escalation path, and enroll them in enhanced account protection programs.
Social Engineering Examples. “GRU 'Someone has your password' phishing of the DNC and Clinton campaign (2016)”. Accessed 16 September 2026. https://socialengineeringexamples.com/dnc-clinton-podesta-google-alert-phishing-2016
per the Mueller indictment (paragraph 23), GRU Unit 26165 personnel researched DNC and DCCC network configurations through technical and open-source queries in mid-March 2016, while separately (paragraph 21c) officer Ivan Yermakov researched named victims' identities and their Clinton-campaign affiliations on social media, building a target list that ultimately covered over 300 individuals.
employee and network OSINT exposure (staff names and roles on social media, technical details visible via public DNS/network queries) is very difficult to eliminate at organizational scale; the realistic control is minimizing what technical footprint is exposed where possible and assuming a motivated attacker can still build a target list, then hardening the later stages that list gets used against.
the GRU registered and operated a Bitly URL-shortener account ("john356gh") and stood up look-alike, GRU-controlled Google login pages, including a deceptive domain documented by Secureworks, engineered with a Base64-encoded parameter that pre-filled each victim's own email address on the decoy page to increase its believability.
domain and brand-monitoring services plus rapid takedown requests against look-alike domains and abusive URL-shortener accounts impersonating a trusted brand can disrupt attacker infrastructure, though defenders are often racing an attacker who only needs the infrastructure live for a single mailing.
starting March 19, 2016, GRU officer Aleksey Lukashev sent emails spoofed to appear as legitimate Google security alerts warning of an unauthorized sign-in attempt and demanding an immediate password change, with the malicious link masked behind the Bitly shortener; a later wave on March 25, 2016 was sent from a spoofed Russia-based Yandex account, reaching over 300 Clinton campaign, DNC, and DCCC-affiliated recipients in total.
DMARC, SPF, and DKIM enforcement plus anti-spoofing mail-gateway controls make it harder to forge a convincing "from Google" sender identity, and external-sender banners with link-rewriting or sandboxing can flag or defuse inbound credential-reset lures before a user ever sees a clean-looking link.
on March 19, 2016, campaign chairman John Podesta's staff forwarded the suspicious email to IT aide Charles Delavan for a legitimacy check; Delavan has stated he intended to flag it as fraudulent but instead replied "This is a legitimate email," removing the one review step positioned to catch the lure before the link was clicked.
give IT and helpdesk staff a clear, standardized escalation and verification procedure for forwarded suspicious emails, one that always instructs the requester not to click and to navigate to account settings directly, rather than relying on a single free-text reply channel where one dropped word can invert the guidance.
Podesta's link was clicked and his Google credentials entered into the GRU-controlled decoy login page, per the indictment, handing the attackers a live, authenticated session rather than merely a static password.
phishing-resistant MFA (hardware security keys or FIDO2) prevents a harvested password alone from producing a usable session, and training staff to navigate directly to official account-security settings rather than clicking emailed "change password" links removes the credential-harvesting page from the equation entirely.
on March 21, 2016, Lukashev, Yermakov, and co-conspirators used the harvested access to download the full contents of Podesta's mailbox, over 50,000 emails, while parallel spear-phishing and network-intrusion efforts compromised DCCC and DNC staff and systems; the stolen material was later staged for public release through DCLeaks, Guccifer 2.0, and WikiLeaks to complete the operation's espionage-and-influence objective.
continuous anomalous-access monitoring (new-device or new-session alerts, unusual mailbox export or download volume flags) and a fast incident-response process can limit how much data is taken once compromise is suspected, though once bulk email exfiltration has already occurred the realistic control shifts from prevention to containment, breach notification, and damage limitation.
Browse by what this case has in common with others in the library.
A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer.
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…
An interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC.
A revived Lampion banking-trojan campaign spoofed Portugal's tax authority site to trick victims into pasting a PowerShell command into the…
A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into…
The FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters…
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
During an internal OpenAI benchmark run with safety refusals deliberately lowered.
Dow Chemical and Sasol paid PR firms who subcontracted a private intelligence firm to run over 120 dumpster-diving raids on…
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
An interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC.
A Houston- and California-based ring spoofed business emails to trick five companies and a New Jersey township into wiring over…
An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…
A single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that stole data…
North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials.
A single spear-phishing email titled "2011 Recruitment Plan," with a booby-trapped Excel attachment.
Lazarus operators spear-phished a senior Sky Mavis engineer through a fake LinkedIn recruiting process and a spyware-laced job-offer PDF.
In the same January 12, 2010 blog post disclosing Operation Aurora, Google revealed that dozens of Gmail accounts belonging to…
Operation Buckshot Yankee: a malware-laden USB drive plugged into a U.S. military laptop in 2008 spread the agent.btz worm onto…