Russian GRU officers spoofed Google security-alert emails to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails.
Social Engineering Examples·6 sources
Beginning in at least March 2016, GRU officers ran a spear-phishing campaign against more than 300 people affiliated with the Clinton campaign, DNC, and DCCC. The lures were emails crafted to look like Google security notifications ("Someone just used your password to try to sign in to your Google Account... You should change your password immediately"), with the malicious link hidden behind a Bitly URL-shortener.
On March 19, 2016, GRU officer Aleksey Lukashev (using the Bitly account "john356gh") sent such an email to campaign chairman John Podesta. Podesta's team forwarded it to IT aide Charles Delavan, who meant to warn that it was illegitimate but wrote "This is a legitimate email" (he later told the New York Times he intended to type "not a legitimate email" and omitted the word).
The link was clicked and credentials were entered; on March 21, 2016 the GRU stole the contents of Podesta's account, over 50,000 emails. The same technique compromised numerous other staffers, including a later wave on March 25, 2016 sent from a spoofed Russia-based Yandex account. Attribution is confirmed: Secureworks documented the Bitly infrastructure in 2016, the U.S. intelligence community attributed the operation to Russia, and the July 13, 2018 Mueller indictment (US v. Netyksho et al.) charged twelve named GRU officers with the intrusions and staged leaks.
The emails impersonated a trusted brand (Google) and used a fabricated security-alert pretext: a supposed unauthorized sign-in attempt, sometimes citing an IP address and a foreign location, demanding an immediate password change. The malicious destination, a GRU-controlled page that spoofed the real Google login screen, was hidden behind Bitly short links so recipients could not see the true URL.
Per Secureworks, the phishing URL carried a Base64-encoded copy of the victim's own email address so the fake login page arrived pre-filled with their address, increasing believability. Because the Clinton campaign and DNC used Google/Gmail for mail, staff were conditioned to expect exactly this kind of Google login prompt. Entering credentials on the decoy page handed the attackers a live session and full mailbox access.
The campaign was reconnaissance-driven and personalized; per the Mueller indictment, GRU officer Ivan Yermakov researched targets' names and Clinton-campaign affiliations on social media, placing it at the hyper-targeted end of spear phishing.
Lure: a fake Google "Someone has your password / suspicious sign-in" alert urging an urgent password reset via an embedded (Bitly-shortened) link. Tells: the sender address was spoofed rather than a genuine Google domain (one wave sent from a Russia-based Yandex account); the action link was a shortened URL masking a non-Google destination; and the fastest safe check, appending a "+" to a Bitly link or navigating to Google account settings directly instead of clicking, would have exposed the decoy login domain.
Podesta's 50,000+ emails and large volumes of DNC and DCCC material were exfiltrated and staged for release through the DCLeaks site, the Guccifer 2.0 persona, and WikiLeaks across summer and fall 2016, becoming a dominant story of the U.S. election. Twelve GRU officers were indicted by name in July 2018; none have been arrested, and they remain in Russia.
Secureworks' analysis of Bitly-link datasets, roughly 8,900 links analyzed in its original 2016 report and a separate 19,000-link dataset it later shared that underpinned a 2017 Associated Press reconstruction, provided much of the forensic backbone for public attribution.
This is the canonical case that credential-harvesting spear phishing, not malware, is enough to compromise the highest-value targets: a single spoofed security alert and one clicked link opened a presidential campaign to a nation-state. It also shows how a human escalation step meant to protect the target (asking IT) can backfire, how brand-mimicking "reset your password" pretexts exploit good security hygiene messaging, and how URL shorteners defeat casual link inspection.
It set the template studied in nearly every modern phishing-awareness program.
Enforce phishing-resistant MFA (hardware security keys / FIDO2) so stolen passwords alone cannot grant access. Treat any "change your password" link in an inbound email as suspect; navigate to account security settings directly rather than clicking. Expand short links before trusting them (append "+" to a Bitly URL to preview the destination) and verify the true login domain before entering credentials.
Deploy DMARC/SPF/DKIM and anti-spoofing controls, external-sender banners, and link rewriting/sandboxing. Give high-risk staff (executives, comms, finance, IT) targeted training and a fast, unambiguous IT escalation path, and enroll them in enhanced account protection programs.
Social Engineering Examples. “GRU 'Someone has your password' phishing of the DNC and Clinton campaign (2016)”. Accessed 19 September 2026. https://socialengineeringexamples.com/dnc-clinton-podesta-google-alert-phishing-2016
per the Mueller indictment (paragraph 23), GRU Unit 26165 personnel researched DNC and DCCC network configurations through technical and open-source queries in mid-March 2016, while separately (paragraph 21c) officer Ivan Yermakov researched named victims' identities and their Clinton-campaign affiliations on social media, building a target list that ultimately covered over 300 individuals.
employee and network OSINT exposure (staff names and roles on social media, technical details visible via public DNS/network queries) is very difficult to eliminate at organizational scale; the realistic control is minimizing what technical footprint is exposed where possible and assuming a motivated attacker can still build a target list, then hardening the later stages that list gets used against.
the GRU registered and operated a Bitly URL-shortener account ("john356gh") and stood up look-alike, GRU-controlled Google login pages, including a deceptive domain documented by Secureworks, engineered with a Base64-encoded parameter that pre-filled each victim's own email address on the decoy page to increase its believability.
domain and brand-monitoring services plus rapid takedown requests against look-alike domains and abusive URL-shortener accounts impersonating a trusted brand can disrupt attacker infrastructure, though defenders are often racing an attacker who only needs the infrastructure live for a single mailing.
starting March 19, 2016, GRU officer Aleksey Lukashev sent emails spoofed to appear as legitimate Google security alerts warning of an unauthorized sign-in attempt and demanding an immediate password change, with the malicious link masked behind the Bitly shortener; a later wave on March 25, 2016 was sent from a spoofed Russia-based Yandex account, reaching over 300 Clinton campaign, DNC, and DCCC-affiliated recipients in total.
DMARC, SPF, and DKIM enforcement plus anti-spoofing mail-gateway controls make it harder to forge a convincing "from Google" sender identity, and external-sender banners with link-rewriting or sandboxing can flag or defuse inbound credential-reset lures before a user ever sees a clean-looking link.
on March 19, 2016, campaign chairman John Podesta's staff forwarded the suspicious email to IT aide Charles Delavan for a legitimacy check; Delavan has stated he intended to flag it as fraudulent but instead replied "This is a legitimate email," removing the one review step positioned to catch the lure before the link was clicked.
give IT and helpdesk staff a clear, standardized escalation and verification procedure for forwarded suspicious emails, one that always instructs the requester not to click and to navigate to account settings directly, rather than relying on a single free-text reply channel where one dropped word can invert the guidance.
Podesta's link was clicked and his Google credentials entered into the GRU-controlled decoy login page, per the indictment, handing the attackers a live, authenticated session rather than merely a static password.
phishing-resistant MFA (hardware security keys or FIDO2) prevents a harvested password alone from producing a usable session, and training staff to navigate directly to official account-security settings rather than clicking emailed "change password" links removes the credential-harvesting page from the equation entirely.
on March 21, 2016, Lukashev, Yermakov, and co-conspirators used the harvested access to download the full contents of Podesta's mailbox, over 50,000 emails, while parallel spear-phishing and network-intrusion efforts compromised DCCC and DNC staff and systems; the stolen material was later staged for public release through DCLeaks, Guccifer 2.0, and WikiLeaks to complete the operation's espionage-and-influence objective.
continuous anomalous-access monitoring (new-device or new-session alerts, unusual mailbox export or download volume flags) and a fast incident-response process can limit how much data is taken once compromise is suspected, though once bulk email exfiltration has already occurred the realistic control shifts from prevention to containment, breach notification, and damage limitation.
Browse by what this case has in common with others in the library.
A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer.
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
A trusted, decades-respected Kansas community bank CEO was groomed over WhatsApp into a crypto "pig butchering" scam.
Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar.
Criminals impersonated a trusted vendor over email and redirected two building-fund payments totaling $4.92M from a North Dakota school district.
A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…
A long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened…
FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages.
CVS pharmacies nationwide tossed pill bottles, prescriptions, and employee SSNs into unsecured public dumpsters.
North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials.
Attackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread.
Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American…
Air Canada admitted in a sworn Ontario Superior Court affidavit that it hired private investigators who twice took trash from…
KnowBe4 unknowingly hired a North Korean operative for a software engineering role after he passed four video interviews using an…
North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials.
Lazarus-linked operators built polished fake job-interview sites impersonating Coinbase, Kraken, Circle and other crypto firms.
A compromised Constant Contact account let Russia-linked Nobelium send USAID-spoofed phishing emails to 150-350 government and NGO organizations.
Operation Buckshot Yankee: a malware-laden USB drive plugged into a U.S. military laptop in 2008 spread the agent.btz worm onto…
Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar.