On December 24, 2011, the private intelligence firm Strategic Forecasting (Stratfor) discovered it had been compromised. Over the following days, Anonymous released Stratfor's internal database: 860,000 subscriber email addresses and password hashes, and 60,000 credit card numbers that had been stored in plaintext without PCI compliance. The credit cards were used to make approximately $700,000 in fraudulent donations to the Red Cross, CARE, and other charities. The Associated Press called it "one of the largest hacktivist breaches in history."
Three months later, in February 2012, WikiLeaks began publishing the Stratfor emails as "The Global Intelligence Files" - five million internal communications spanning years of analysis, client relationships, and internal discussions about the firm's work. The archive revealed Stratfor's network of paid informants, its surveillance of social movement organizations, and a corporate culture that fused genuine geopolitical analysis with surveillance-for-hire that its clients included major corporations, governments, and law enforcement agencies.
The person who had conducted the hack, Jeremy Hammond, was arrested on March 6, 2012. He was 27 years old, had been hacking for activism since his teens, and had already served a 2-year federal sentence for a previous hack of a conservative website. What he did not know until later - and what became the central legal controversy of his case - was that the FBI informant who had directed him to attack Stratfor was providing the target to the FBI in real time.
Hammond and the LulzSec Legacy
Jeremy Hammond came from Chicago's anarchist political community and had been involved in hacktivist operations for years. He operated under the handle "Anarchaos" and was affiliated with the loose network of operators that coalesced around LulzSec and Anonymous in 2011. His politics were explicitly radical: he believed corporate surveillance, private intelligence firms, and the surveillance state were targets that deserved to be attacked, and he acted on those beliefs.
Hammond had connected with Hector Monsegur ("Sabu") through the Anonymous IRC network in 2011. Monsegur was at that time the most prominent public face of LulzSec - the person who gave interviews, posted communiques, and coordinated operations. He was also, from June 2011 onward, an FBI informant. He had been identified, arrested, and flipped within 24 hours by the FBI. His cooperation agreement required him to remain in character as "Sabu" and to provide the FBI with intelligence on his former associates' activities.
From the government's perspective, Monsegur was providing valuable intelligence about ongoing attacks and identifying participants for prosecution. From Hammond's defense attorneys' perspective, Monsegur was actively directing attacks at the FBI's behest - not merely reporting on crimes that would have happened anyway, but instructing specific targets and providing operational support for attacks that might not have occurred without FBI direction.
The FBI's Role: Direction or Observation?
The legal controversy centered on the entrapment doctrine and a related concept called "outrageous government conduct." Entrapment, under US law, requires that the government induce a defendant to commit a crime they were not predisposed to commit. Hammond had a prior conviction for hacking and was clearly predisposed to hacktivist attacks; standard entrapment doctrine did not apply.
The "outrageous government conduct" argument was different: it did not require showing lack of predisposition but argued that the government's active participation in and direction of criminal activity was so fundamentally unfair that prosecution should be barred regardless. Hammond's attorneys argued that the FBI, through Monsegur, had provided the target (Stratfor), the infrastructure (servers for storing exfiltrated data), and operational direction for the attack - that without FBI involvement, the specific attack on Stratfor would not have occurred.
The evidence for FBI direction was substantial. Chat logs subpoenaed during the case showed Monsegur suggesting Stratfor as a target and providing logistical support. The data from the breach was stored on servers the FBI was monitoring in real time - the exfiltration was visible to the FBI as it happened. Court filings revealed that Monsegur had directed attacks on government systems in other countries, including Turkey and Brazil, at the FBI's direction - raising questions about whether the FBI had been running offensive hacking operations through a criminal proxy.
The Stratfor Emails: What They Revealed
The five million Stratfor emails published by WikiLeaks contained several categories of significant disclosures. The most attention-grabbing involved the firm's "Shadow Squad" - a network of paid human intelligence sources including informants inside government agencies, corporations, and activist organizations. Emails described sources within the US military, government contractors, and foreign governments providing information on specific topics.
One notable category involved Stratfor's monitoring of protest movements and civil society organizations. Emails described surveillance of activists related to the Occupy movement, Latin American social movements, and groups advocating for Bradley Manning (Chelsea Manning). Corporate clients had purchased targeted intelligence gathering on organizations they considered adversaries - a private sector surveillance capability that paralleled government intelligence programs.
The emails also revealed Stratfor's financial and operational practices in unflattering detail. Internal discussions showed analysts' private assessments of geopolitical situations that contradicted the firm's public analysis, casual use of racially charged language, and frank discussions of the firm's commercial interests in conflict zones. The gap between private and public analysis was significant enough that several of the firm's clients and subscribers found it material to their relationship with Stratfor.
Prosecution and Sentence
Hammond was charged with violating the Computer Fraud and Abuse Act, specifically with computer intrusion causing over $5,000 in damages. The Stratfor breach, combined with related hacks on other targets, produced an aggregate damage figure the government calculated at over $2.5 million.
Judge Loretta Preska, who was assigned Hammond's case, had a conflict of interest that Hammond's attorneys identified and contested: Preska's husband had been a Stratfor subscriber whose email and personal information had been exposed in the breach. The defense requested recusal; Preska denied it, ruling that her husband's minor exposure to the breach (he received a breach notification email) did not constitute a sufficient connection to require disqualification.
Hammond pleaded guilty in May 2013, explicitly to avoid trial and a potentially longer sentence. In his sentencing statement, he argued that the true criminals were the corporations and surveillance firms like Stratfor, that he had acted in accordance with his conscience, and that he expected to be imprisoned for his beliefs. Judge Preska sentenced him to the statutory maximum of 10 years in federal prison. He was released in November 2020 after serving the full sentence minus good-time credit.
Legacy: Corporate Intelligence and Hack-to-Expose Operations
The Stratfor hack contributed to a broader conversation about the private intelligence industry that had accelerated following the HBGary Federal breach in early 2011. The two incidents together revealed a substantial market for corporate surveillance capabilities: firms like Stratfor and HBGary Federal provided services to governments, corporations, and law enforcement that operated in legal gray areas or, in some cases, clearly beyond legal authority.
The hacktivist "hack-to-expose" methodology - breach a target, publish the internal communications, and let the content speak for itself - had mixed results across multiple operations. The HBGary emails had revealed genuinely significant surveillance proposals. The Stratfor emails revealed a surveillance-for-hire industry but produced less dramatic accountability than the HBGary disclosures. In both cases, the legal consequences fell on the people who conducted the hacks rather than on the organizations whose activities were exposed.
This asymmetry - where the breach is a crime but the surveillance it exposes may not be - remains an unresolved tension in discussions about whistleblowing, journalism, and the limits of lawful intelligence gathering by private actors. Hammond's view, expressed in his sentencing statement, was that the law protected the wrong people. The government's view, expressed through his prosecution, was that the law applied regardless of who the target was.