There are two competing explanations for how the DNC emails reached WikiLeaks in 2016.
The “official account” holds that Russian military intelligence hacked the DNC, stole thousands of emails, and transferred them to WikiLeaks to influence the presidential election. That claim became the central pillar of Russiagate.
The “conspiracy theory”—examined in Parts 1 and 2—is that the emails were not remotely hacked at all, but leaked by an insider, possibly Seth Rich.
Any serious attempt to distinguish between those accounts must confront the strange figure who appeared immediately after the DNC announced its breach: “Guccifer 2.0.”
Who is Guccifer 1.0?
“Guccifer” — a portmanteau of “Gucci” and “Lucifer” — is the handle of an infamous Romanian hacker and taxi driver, Marcel Lehel Lazăr, who has pulled off several high-level hacks in the U.S. and Romania.
The actual Guccifer 1.0 was in jail in Virginia from 2016-2021 for several counts of unauthorized access and identity fraud.
One of Guccifer 1.0’s claims to fame is hacking Clinton’s private emails in 2013.
The new hacker’s moniker, Guccifer 2.0, is therefore an homage to Guccifer 1.0, because the new Guccifer is purporting to carry on Guccifer’s legacy of hacking Hillary Clinton. But Guccifer 1.0 and Guccifer 2.0 are completely different people.
Guccifer 2.0 Takes The Credit
On June 14, 2016, the Washington Post reported that the DNC had been hacked.
The next day, June 15th, a hacker calling himself ‘‘Guccifer 2.0’’ claims responsibility for the hack and announces he’ll be giving the documents to Wikileaks, releasing many online himself.
The following day, much of the mainstream media ran with this ‘‘lone hacker’’ narrative:

6 days later, in a Vice interview, Guccifer 2.0 claims to be a lone wolf “hacker, manager, philosopher, women lover … I also like Gucci! I bring the light to people. I’m a freedom fighter! So u can choose what u like!”
Trump surrogate Roger Stone — who I consider one of the least trustworthy sources of news in the world — claimed he exchanged private messages with Guccifer 2.0: “Guccifer 2.0 is the real deal … Guccifer 2.0 made a fateful and wise decision. He went to Wikileaks with the DNC files and the rest is history. Now the world would see for themselves how the Democrats had rigged the game.”
For the next couple of years, many mainstream outlets frequently referred to Guccifer 2.0 simply as “the hacker”:
This narrative would soon prove to be fake. With the benefit of hindsight, we can now categorically say that Guccifer 2.0 was a misinformation operation.
Deliberately Planted Russian Fingerprints?
If this was a Russian intelligence operation, it was the sloppiest in history. Guccifer 2.0 conspicuously left behind a trail of amateurish breadcrumbs pointing directly to Russia. Rather than masking its origins, the operation appeared almost engineered to advertise “Made In Russia” labels on the data.
Fox News immediately claimed that “fingers point to Russia” because the leaked documents from Guccifer 2.0 were edited on a computer using the name “Felix Dzerzhinsky.” Dzerzhinsky, founder of the Cheka and a symbol of Soviet intelligence, has been dead for over 90 years— the GRU even have a statue of him outside its headquarters. But if you’re a Russian spy running a covert op, why would you label your files with the name of the most infamous figures in your country’s intelligence history? If I found a document last modified by a user named “James Bond,” I wouldn’t assume it came from British intelligence. Yet that’s exactly what much of the U.S. media did: they took this satirical clue at face value and cited it as proof of Russian hacking.
The documents that Guccifer 2.0 created had metadata in Russian, Russian stylesheet entries, and Russian error messages… all of which were inserted for seemingly no reason. Guccifer 2.0 wrote in Cyrillic and used Russian )))))) smileys.
Guccifer 2.0’s accounts on Twitter and WordPress revealed their IP address as Russian intelligence headquarters building.
These clues were glaring and discovered immediately, making this appear less like a genuine slip-up and more like a clumsy attempt to frame Russia. This metadata is examined in detail in the excellent forensic investigation, Guccifer 2.0 - Game Over.
Contradicting these clues that Russia did it, there were also many clues that someone in an American timezone did it:
The operation left US breadcrumbs behind in the form of timezone indicators (reported on: here, here, here, here, here, here and here). There are, in fact, more types of timezone indicator pointing at the persona’s activities being in American timezones than Russian. However, they were generally more obscure and took a lot longer to find that the Russian breadcrumbs.
There are also locale indicators in some pieces of evidence that conflict with accompanying Russian indicators and that would be correct for a computer configured for US locale (decimal separator conflicting with Russian language and date format conflicting with Russian timezone offset).
Deliberately Planted DNC Fingerprints?
When Guccifer 2.0 released his first documents, reporters immediately noticed that the metadata identified the author of the first three files as Warren Flood. Flood was a Democratic data strategist who had worked for the DNC and Barack Obama’s presidential campaigns.
Thousands of people online took this as proof that Guccifer 2.0 was Warren Flood.
This was misdirection.
The substantive contents of Guccifer 2.0’s first document came from a December 2015 opposition-research file titled “12192015 Trump Report — for dist.docx.”
But Guccifer 2.0 did not simply publish that file. Someone appears to have copied its contents into a second, much older document: a 2008 Obama-transition file titled “Slate — Domestic — USDA — 2008-12-20.doc.” That document had originally been created under the author name “Warren Flood” on a copy of Microsoft Word registered to “GSA.” It was also attached to an entirely separate email in Podesta’s inbox. That email and the 2008 attachment can be viewed here.
The Forensicator blog reconstructed the process by comparing the documents’ metadata, formatting and internal revision identifiers. Their analysis found that the 2008 USDA document supplied the “Warren Flood” author field, the “GSA” company field, the footer and the underlying “CONFIDENTIAL DRAFT” watermark. Whoever constructed Guccifer 2.0’s document apparently emptied that older file, removed “DRAFT” from the watermark, altered the footer and pasted in the contents of the 2015 Trump report. The resulting template was then reused to produce Guccifer 2.0’s second and third documents.
Only afterward were the files saved under the Russian-language username “Феликс Эдмундович”—Felix Edmundovich Dzerzhinsky—and processed using Russian language settings. Guccifer 2.0’s first three files therefore contain two different layers of metadata: an inherited American author name from a 2008 document followed by conspicuous Russian identifiers introduced during their later construction.
This means that Warren Flood’s name is not evidence that Flood personally created the Guccifer 2.0 documents, nor does it prove that his computer was used... Flood’s name survived because someone used his old file as a template.
The Documents Don’t Add Up
The Forensicator reviewed 175 documents Guccifer 2.0 uploaded between June 15 and October 4, 2016. This chart shows the cumulative documents published:
The more revealing chart traces those documents to other collections that later became public. Much of the material was recycled from earlier breaches. Some appear to have originated in the Podesta emails or an earlier Clinton Foundation breach, while others—such as documents concerning misuse of TARP funds—had already been reported by OpenSecrets in 2009. Guccifer 2.0 nevertheless presented them to journalists as newly stolen from the DNC. Nearly half of the documents can be traced to the DCCC rather than the DNC.
Another unresolved discrepancy is that Guccifer 2.0 described his archive as roughly 1 GB, while the complete WikiLeaks DNC collection (44,053 emails and 17,761 attachments) was approximately 2 GB when compressed.
The Method of Hacking Doesn’t Add Up
Guccifer 2.0 claimed he hacked the DNC using a “0-day exploit of NGP-Van”.
“I used 0-day exploit of NGP VAN soft then I installed shell-code into the DNC server. it allowed me to intrude into DNC network. They have Windows-based domain architecture. then I installed my Trojans on several PCs. I had to go from one PC to another every week so CrowdStrike couldn’t catch me for a long time. I know that they have cool intrusion detection system. But my heuristic algorithms are better.”
— Guccifer 2.0 in an interview to Vice News
On the surface, this sounds impressively technical. Under scrutiny, however, it reads more like a collection of hacking buzzwords strung together.
NGP VAN was not software running locally on the DNC’s Windows servers. It was a web-based platform hosted by an outside company and used by Democratic campaigns to manage voter information. Exploiting a vulnerability in NGP VAN might conceivably have exposed information stored inside that platform, but it would not automatically provide shell access to the DNC’s internal network, much less allow an attacker to install Trojans across multiple DNC computers.
Hacking NGP VAN and hacking the DNC’s Windows domain would have been two separate operations requiring separate access. It would be like exploiting a vulnerability in Salesforce and claiming that this automatically allowed you to install malware on every computer belonging to one of Salesforce’s customers.
The only publicly documented NGP VAN vulnerability resembling what Guccifer 2.0 described was the permissions bug involved in the December 2015 Bernie Sanders campaign controversy. That bug temporarily allowed authorized campaign users to view certain information belonging to another campaign. It did not permit remote code execution, provide access to the underlying operating system or allow anyone to install malware on DNC computers.
Guccifer 2.0 told Vice that he first entered the DNC “last summer,” meaning the summer of 2015. But the NGP VAN permissions bug was introduced through a software update on December 16, 2015—months after his purported intrusion began. Cybersecurity firm ThreatConnect examined these contradictions and concluded that Guccifer 2.0’s NGP VAN story “[didn’t] make any sense.”
Guccifer Claims His Source Was Seth Rich
The Guccifer 2.0 hacker ran a (now suspended) “Guccifer_2 Twitter account, where in August 2016 he repeatedly flirted with the actress Robbin Young,
In this private conversation, Guccifer 2.0 claimed that Seth Rich was his source — despite publicly claiming he obtained his material by hacking the DNC.
This claim never made much sense and provides little evidentiary value.
An infamous hacker was casually disclosing sensitive details about his dead whistleblower to some random actress chick to impress her? My interpretation is that this is misdirection, trolling, or narrative-seeding to sow chaos and poison the well… not a credible admission.
In the same conversation Guccifer 2.0 mused that Julian Assange “may be connected with Russians”:
The exchange further damages Guccifer 2.0’s credibility. In different contexts, the persona advanced mutually incompatible stories:
Publicly, Guccifer claimed to have personally hacked the DNC.
Privately, he allegedly called Seth Rich “my whistleblower.”
Here, he casts suspicion on Assange as possibly connected to Russia.
Meanwhile, U.S. investigators later alleged that Guccifer 2.0 itself was operated by Russian intelligence.
If the official Russian intelligence attribution is correct, this reads like deliberate distancing: a Russian-operated persona privately accusing Assange of Russian connections to reinforce the impression that Guccifer was independent of Moscow.
The Story Doesn’t Add Up
On the day he claimed credit, June 15, 2016, Guccifer 2.0 stated that it had given material to WikiLeaks and asserted that the organization would publish that material soon. However, the earliest recorded communication between Guccifer 2.0 and WikiLeaks—as later disclosed in Special Counsel Robert Mueller’s July 2018 indictment of 12 Russian GRU officers—did not occur until June 22, 2016.
WikiLeaks says it had no prior contact with Guccifer 2.0.
This chronological gap creates a glaring paradox:
June 12, 2016: Julian Assange appears on British television (ITV) and publicly announces that WikiLeaks has incoming emails related to Hillary Clinton and the Democratic Party scheduled for publication.
June 15, 2016: Guccifer 2.0 makes his public debut, claiming he has already transferred the stolen DNC files to WikiLeaks.
June 22, 2016: WikiLeaks initiates their very first private contact with Guccifer 2.0 via Twitter direct messages.
July 14, 2016: Guccifer 2.0 finally transmits an encrypted 1 GB data file to WikiLeaks.
If WikiLeaks was already preparing to publish the material prior to June 12, Guccifer 2.0 could not have been the original source who provided it. Furthermore, Guccifer’s June 15 public claim of having already handed the documents over to WikiLeaks was demonstrably false at the time he made it.
At minimum, this chronology leaves Guccifer 2.0’s June 15 claim unexplained, and heavily points toward the conclusion that Guccifer 2.0 was not the original pipeline to WikiLeaks. The persona appeared after WikiLeaks already possessed the documents, inserting itself into the narrative after the fact to claim responsibility for a breach that had already taken place.
What the Transfer Speeds Can—and Cannot—Prove
A Good American is an excellent documentary about William Binney, the former NSA technical director and one of the most accomplished intelligence analysts of his generation. Although the film does not examine the Guccifer 2.0 case specifically, it provides essential background on Binney’s extraordinary technical abilities and career. His résumé already speaks for itself: no one rises to become technical director of the NSA without possessing exceptional technical talent.
Binney remains the most prominent intelligence insider arguing that the official Guccifer 2.0 narrative is a technical impossibility. His core thesis was first detailed in a Veteran Intelligence Professionals for Sanity (VIPS) memorandum:
Independent cyber-investigators have now completed the kind of forensic work that the intelligence assessment did not do … They found that the purported “hack” of the DNC by Guccifer 2.0 was not a hack, by Russia or anyone else. Rather it originated with a copy (onto an external storage device – a thumb drive, for example) by an insider.
The key technical evidence in that open letter is that someone “copied 1,976 MegaBytes of data in 87 seconds onto an external storage device. That speed is much faster than what is physically possible with a hack.”
This interview directly presents Binney’s argument:
This is a longer interview in which Binney elaborates at length about how the material was transferred to a thumb drive or CD-ROM and physically transported:
Binney then did an AMA on Reddit where he explained :
Remember when emails released by Wikileaks proved that the DNC rigged the primary election against Bernie Sanders? And everyone claimed that the Russians had hacked the DNC?
There’s only one problem. There was no hack.
It was an internal leak.
It boils down to these three key points:
1.) The modification times on the files point to the use of a FAT file system, which is used almost exclusively by storage devices (such as flash drives).
2.) Analysis of the files released by Guccifer 2.0 -- claimed to be the Russian hacker who got the files to Wikileaks -- reveals that they were created at a data transfer rate consistent with a flash drive, but not with an internet transfer.”
3.) The NSA would’ve known the hack was taking place, thanks to the leaks revealed by Edward Snowden, which the NSA has never denied
…
The Guccifer 2.0 data was actually too fast to be consistent with an internet hack.
Reddit moderators shut that thread down almost immediately.
I emailed Binney to ask whether any new evidence, technical analyses, or counterarguments have emerged in the past 8 years that have caused him to revise or qualify his conclusion. He replied:
All the factual evidence supports an internal download of the DNC emails posted by Wikileaks.
1. The transfer rates between 19 and 49.1 mega bytes (million characters) per second can not be supported by the WWW.
2. All 35813 DNC emails posted by Wikileaks have a last modified time ending in an even second. This is a property of FAT (File Allocation Table) format which is a function of the program reading data to a storage device like a thumb drive then physically transported before Wikileaks published. Podesta email could have been a hack but not the DNC emails.
3. Our English collaborators found 5 Guccifer 2.0 email that had Russian fingerprints - in the Wikileaks posted data, the same 5 did not have Russian fingerprints. So, Guccifer 2.0 put them there.
4. All these facts are consistent with Shawn Henry’s (CSO of Crowd Strike) testimony to HPSCI (Jan 2017) where he said: they observed the data was prepared for exfiltration but they did not see it exfiltrated. Here I assume he is referring to the last modified times.
5. Proof of an inside job is also consistent with statements from Sy Hersh, Craig Murry, Kim Dot Com and Julian Assange.
I would also point out that no one (including NSA, CIA, FBI) has produced any evidence (they only have opinion) to contradict these facts. They are going with the emotion TDS plus trading their integrity for money. Plus they called me a conspiracy theorist when in fact, they don’t know the difference between a theory and a theorem. They did get a lot of awards and money out of all those lies.
Bill
A subsequent investigation, The Need for Speed, again concludes that “a transfer rate of 23 MB/s is estimated for this initial file collection operation. This transfer rate can be achieved when files are copied over a LAN, but this rate is too fast to support the hypothesis that the DNC data was initially copied over the Internet (esp. to Romania).”
Other independent investigators, such as Guccifer Game Over, who are still skeptical of the official “Russia hacked the DNC” narrative, are more cautious in their analysis of the data transfer speeds:
Another skeptical voice of the thumb drive theory is Stephen McIntyre:
Conclusion
Guccifer 2.0 was not a lone wolf in Romania.
Two years after he appeared, the CIA, NSA, and FBI assessed “with high confidence” that “Russian military intelligence used the Guccifer 2.0 persona to release US victim data.” Mueller identified two people behind the Guccifer 2.0 persona, both officers of the GRU. This Russian narrative is somewhat more plausible than the lone wolf in Romania theory. The hacker left far more clues pointing toward a Russian identity than toward the Romanian persona he publicly claimed. If Guccifer 2.0 was a GRU psychological operation, lying, trolling (like claiming Seth Rich was the source to Robbin Young), and dropping sloppy clues is standard tradecraft for disinformation.
But there is a third possibility: the incident was a leak deliberately made to look like a hack, and Guccifer 2.0 was a domestic influence operation intended to discredit WikiLeaks and divert attention from the substance of the DNC emails. For the next three years, the mainstream press became obsessed with Donald Trump’s alleged collusion with the Russians, while devoting little attention to what the leaked emails revealed about the Democratic establishment’s efforts to undermine Bernie Sanders’s campaign.
None of this, by itself, establishes who controlled Guccifer 2.0.
That leaves the central question unresolved: who actually created Guccifer 2.0, and on what evidence did the press and intelligence establishment conclude that the persona was Russian? To answer that, we have to turn to CrowdStrike—the private cybersecurity firm hired by the DNC, whose analysis became the foundation for the entire hacking narrative.
My next article, Part 4 in this series, will examine what CrowdStrike actually found, what it never proved, and how its conclusions came to be treated as settled fact.


























This series have been fantastic. Great journalism!
As the plot thickens…truly it reads like something Hollywood dreamed up. If only this were the case and Seth Rich would still be alive.