How Leakers Get Caught: The OPSEC Chain of Failure

TL;DR

  • Leakers rarely get caught by one thing: It's usually a chain of operational security failures, any one of which might be survivable but together form an identification pattern.
  • Common failures: Contacting journalists from traceable accounts, printing on monitored systems, sharing with groups that include unvetted members, leaving behavioral patterns.
  • Technology matters but isn't everything: Printer dots identified Reality Winner, but so did her email contact with the news outlet and the fact she was one of six who printed the document.
  • The human element: Most exposures involve someone talking, behavioral changes, or basic mistakes that sophisticated forensics then confirm.
  • Lessons: Security isn't one tool, it's an entire operational practice. One broken link breaks the chain.

In March 2025, the Atlantic published precise US military plans for a strike, because the Secretary of Defense had added a journalist to a Signal group chat containing top officials. No hacking. No sophisticated forensics. Someone just added the wrong contact. [1]

This wasn't an anomaly. It's how most leaks get traced: not through brilliant forensic analysis, but through operational security failures so basic they're almost embarrassing after the fact.

Understanding how leakers actually get caught matters for two reasons:

  1. For security: Organizations need to know what actually works (access controls, behavior monitoring) vs. what's theater
  2. For privacy: Anyone handling sensitive information, journalist sources, whistleblowers, activists, needs to understand the full threat model, not just the technical parts

The Anatomy of an Exposure

Most leaker identifications follow a predictable pattern:

  1. The leak becomes known (publication, discovery, reports)
  2. Access is narrowed (who had access to this document/information?)
  3. Behavioral indicators emerge (who was acting strangely? who searched for this topic?)
  4. Technical forensics confirm (document fingerprints, metadata, access logs)
  5. Questioning produces confession (most leakers confess when confronted with evidence)

Let's examine how this played out in real cases.

Case Study: Reality Winner (2017)

Reality Winner, an NSA contractor, printed a classified document about Russian election interference and mailed it to The Intercept. She was identified within days and sentenced to five years.

What Caught Her

1. Access Narrowing

NSA audit logs showed that only six people had printed the document. Winner was one of them.

2. Communication Trail

Of those six, only Winner had email contact with the news outlet that received the document.

3. Printer Tracking Dots

Yellow microdots on the printed document encoded the printer's serial number and the date/time of printing, confirming the specific printer and time.

4. Search History

Winner had searched the classified system for the specific report on the day she printed it.

The Critical Mistakes

  • Printing on a work system: All printing was logged
  • Emailing from a traceable account: She contacted the news outlet from an account linked to her identity
  • Limited pool: Only six people printed the document, making investigation easy
  • Physical document: Yellow dots provided confirmation

The printer dots are famous, but they weren't necessary for identification, the access logs and email contact were sufficient. The dots just provided additional confirmation. [2]

Case Study: Jack Teixeira, Discord Leaker (2023)

Jack Teixeira, an Air National Guard member, photographed classified documents and shared them in a Discord gaming server. He was identified and arrested after months of leaking.

What Caught Him

  • Social network tracing: The documents spread from his Discord server to larger servers to 4chan to Twitter, but investigators traced the chain back
  • Server member identification: Discord server members were identified and interviewed
  • Visual clues in photos: Some photos showed furniture and surfaces from his home environment
  • Account linking: His Discord account was connected to his real identity through other platform usage
  • Access records: Military records showed he had access to the specific classified systems

The Critical Mistakes

  • Sharing with a group: Every person added is a potential vector for exposure
  • Photographing physical documents: Photos contained background details
  • Using a traceable account: His Discord account was linkable to his identity
  • Ongoing relationship: He wasn't an anonymous source, he was a community member who people knew
  • Retention: People saved and re-shared the documents, creating permanent evidence

Teixeira's operational security was essentially nonexistent. He apparently believed a small Discord server was private. It wasn't. [3]

Case Study: The Signal Chat Leak (2025)

In March 2025, The Atlantic published US military strike plans because a journalist was inadvertently added to a Signal group chat that included the Secretary of Defense, Director of National Intelligence, CIA Director, and other officials. [1]

What Happened

  • Wrong contact added: Someone added a journalist to the group chat, apparently accidentally
  • Sensitive discussion: Officials discussed precise military operational plans
  • Journalist received classified information: Without seeking it or hacking anything
  • Publication: The Atlantic reported on the chat contents

The Failures

  • Contact verification: Nobody verified who was in the chat before discussing classified information
  • Unapproved platform: Signal on personal devices is not approved for classified communications
  • Assumption of privacy: Group chats are only as secure as every member
  • No compartmentalization: Multiple senior officials in one chat created concentration of exposure

This wasn't a leak in the traditional sense, it was an operational security failure so basic that it requires almost no investigation. Someone just added the wrong person. [1]

The Common Failure Patterns

1. The Narrowed Pool

The most effective investigation technique isn't forensic, it's elimination. Who had access to this specific information?

  • Classified documents: Access logs show who viewed/printed them
  • Corporate data: DLP systems log who accessed sensitive files
  • Physical documents: Distribution lists show recipients

If only 10 people had access and one of them leaks, you're already 90% eliminated. If only 3 people had access, you're essentially identified.

2. The Communication Trail

Contacting journalists or outlets creates traceable connections:

  • Email: Even "anonymous" email can be traced through headers, timing, IP addresses
  • Phone: Metadata shows who called whom and when
  • Physical mail: Postmarks, fingerprints, DNA, purchase records
  • Encrypted apps: Secure content, but the fact of communication may be visible

Reality Winner emailed The Intercept. That alone was enough to identify her among the six who printed the document.

3. The Behavioral Pattern

Before or after leaking, behavior often changes:

  • Unusual searches: Accessing documents outside normal work patterns
  • Timing changes: Working unusual hours, accessing systems at odd times
  • Statements: Expressing frustration or disagreement with policies
  • Resource use: Using printers, making copies, downloading files

Insider threat programs specifically monitor for these behavioral indicators.

4. The Technical Fingerprint

Once suspects are narrowed, technical forensics provide confirmation:

  • Printer tracking dots: Identify specific printer and timestamp
  • Document metadata: Author, editing history, file paths
  • Digital watermarks: Invisible marks identifying recipient copy
  • Camera sensor fingerprints: Photos can be matched to specific devices
  • Screen capture artifacts: Resolution, aspect ratio, UI elements

These confirm suspicions but rarely provide the initial identification.

5. The Confession

Most identified leakers confess when confronted. They're shown evidence, offered deals, or simply break under pressure.

Reality Winner confessed during her first FBI interview. Many leakers do.

What Actually Works (From the Investigator's Perspective)

Access Controls and Logging

The single most effective tool: knowing who accessed what information.

  • Print logging: Every print job recorded with user ID and timestamp
  • Access audits: Who viewed classified or sensitive documents
  • Download tracking: Who copied files to external media
  • Search logging: What queries were run on classified systems

If you access a document, there's probably a record.

Network Analysis

When a leak is discovered externally:

  • Which outlet published it?
  • Who contacted that outlet?
  • What's the chain of sharing?
  • Who had access AND had motive AND had contact?

The intersection of access, motive, and opportunity usually produces very short suspect lists.

Behavioral Analytics

Modern insider threat programs use software to flag anomalies:

  • Accessing files outside normal work scope
  • Large downloads or print jobs
  • Working during unusual hours
  • Negative sentiment in communications

This creates a watchlist before any leak occurs.

What Doesn't Work (Security Theater)

Relying Solely on Technical Measures

Printer dots, watermarks, and metadata are confirmation tools, not identification tools. By the time you're analyzing the document's technical fingerprints, you usually already have a suspect list from access logs.

Assuming Encryption = Anonymity

End-to-end encryption protects content, not metadata. Who you contacted, when, for how long, and from where may still be visible.

Using Signal doesn't matter if you're one of three people with access to the document you're leaking.

Trusting "Private" Groups

Any group with more than one person is potentially compromised:

  • Someone may talk
  • Someone may be an informant
  • Someone may share with others who share with others
  • The platform itself may be compromised or compelled

Jack Teixeira apparently trusted his Discord gaming friends. They didn't betray him intentionally, the documents just spread beyond the group.

For Whistleblowers: What This Means

This Is Not Legal Advice

This section describes security concepts for educational purposes. Leaking classified information is a serious federal crime. If you're considering whistleblowing, consult with lawyers experienced in national security law first.

The Threat Model Reality

If you're considering disclosing information:

  1. You're probably already on a suspect list: Access logs exist. If the pool is small, you're already narrowed
  2. Any contact is a connection: Reaching out to journalists creates evidence
  3. One mistake is enough: Security fails at the weakest link
  4. Investigation resources are enormous: The government will spend millions to find you

The Safer Channels

Legal protections exist for some disclosures:

  • Inspector General offices: Internal channels with (weak) legal protections
  • Congressional intelligence committees: Can receive classified information
  • GAO: For waste/fraud/abuse reporting
  • SEC whistleblower program: For securities violations (with financial rewards)

These channels offer legal protection that direct media disclosure does not.

If You Insist on External Disclosure

Security experts recommend (we do not endorse illegal activity):

  • Use SecureDrop or equivalent anonymous submission systems
  • Never contact from devices or networks linked to your identity
  • Understand the access log, if you're one of few people, you're essentially identified
  • Consider that document fingerprints exist
  • Consider that even successful anonymity may not survive forever

For Organizations: Actual Security vs. Theater

What Works

  • Principle of least privilege: Minimize who has access to what
  • Logging and auditing: Know who accessed sensitive information
  • Behavioral monitoring: Detect anomalies before they become leaks
  • Compartmentalization: Limit how much any one person can access

What Doesn't Work

  • Relying on forensics post-leak: Prevention beats investigation
  • Ignoring insider threats: Most leaks come from insiders
  • Over-classifying: When everything is sensitive, nothing is treated as sensitive
  • Security through obscurity: Assuming people don't know about tracking measures

The Bottom Line

Security Is a Chain

Leakers get caught not by one forensic technique but by a chain of failures:

  • Access logs narrow the pool
  • Behavioral patterns flag suspects
  • Communication traces provide connection
  • Technical forensics confirm suspicion
  • Interrogation produces confession

Printer tracking dots are famous because they're visible. But Reality Winner would have been identified without them. The email contact and access logs were sufficient.

The signal chat leak required no forensics at all. Someone just added the wrong person to a group.

If you're handling sensitive information, as a source, a journalist, an activist, understand that security isn't about one tool. It's about every link in the chain. One broken link is enough.

And if you're on the investigator side, understand that your most powerful tools aren't forensic software, they're access controls, logging, and the simple math of a narrowed suspect pool.

References

  1. Dark Reading - Signal Chat Leak Reveals Severe OPSEC Failure (March 2025)
  2. The Guardian - Reality Winner: How NSA Document's Printer Dots Helped Identify Her (June 2017)
  3. Washington Post - How Investigators Identified the Pentagon Leaker (April 2023)
  4. EFF - Printer Tracking Dots Documentation
  5. Wired - The Discord Leaks and the Limits of OPSEC