DC Leaks
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
DC Leaks is the alias used by a hacking entity that has been linked to a series of disclosures involving U.S. political figures. The group first came to public attention in September 2016 when it released an image purporting to be a scanned copy of Michelle Obama’s passport alongside personal emails from a low‑level White House staffer named Ian Mellul. The staffer’s Gmail account contained mostly routine campaign logistics related to Hillary Clinton’s presidential run. DC Leaks describes itself as operating in the name of anti‑secrecy.
The material released by DC Leaks consistently targets individuals and organizations within the United States political sphere. In addition to the Obama passport and staffer emails, the group previously published personal correspondence from former Secretary of State Colin Powell that revealed his views on the 2016 presidential candidates. Cybersecurity experts and U.S. intelligence officials have noted that the group’s activities are part of a broader pattern aimed at American political figures, Democratic Party organizations, and state election systems. The apparent goal of these disclosures appears to be the collection and dissemination of sensitive political information, indicating an espionage‑oriented objective.
Attribution publicly discussed by U.S. officials points to a connection with the Russian government. Intelligence assessments have characterized DC Leaks as a front for a wider Russian‑linked hacking operation that has also breached Democratic Party entities and at least two state election systems. While the group’s exact organizational structure remains unspecified in the sources, the consensus among analysts is that it serves as a proxy for state‑sponsored activity. No public evidence links DC Leaks to a criminal consortium or financially motivated motive.
Representative operations attributed to DC Leaks include the September 2016 disclosures, the earlier release of Colin Powell’s personal emails, and the broader intrusions into Democratic Party networks and state election systems cited by investigators. These actions have been described as part of a sustained effort to expose or influence U.S. political processes. The group’s leaks have prompted investigations by the White House, the Department of Justice, and the U.S. Secret Service, which expressed concern over the unauthorized disclosure of information pertaining to protected individuals. Collectively, these campaigns illustrate the actor’s focus on political espionage and information warfare.
Incidents
Attributed incidents are available to members.
2 incidents