Environmental activists were targeted in a coordinated cybersecurity campaign involving tailored credential-theft messages. The operation used spearphishing—deceptive messages customized for specific people—to pursue U.S.
climate advocates from 2015 through 2018. Investigators confirmed access to at least one advocacy group's email account. However, the evidence does not establish that every phishing attempt succeeded or identify the campaign's ultimate client.
Table of Contents
- What investigators documented
- How the phishing worked
- What was stolen and how it was used
- What remains alleged
- What targeted organizations should do
What investigators documented
Citizen lab called the operation Dark Basin and linked it with high confidence to people working for the Indian firm BellTroX. Researchers found nearly 28,000 credential-phishing URLs aimed at hundreds of people and organizations.
The targets included Greenpeace, 350.org, the Union of Concerned Scientists, the Rockefeller Family Fund, Oil Change International, and the Center for International environmental Law. These organizations were associated with the #ExxonKnew campaign, according to Citizen Lab's investigation.
How the phishing worked
attackers impersonated colleagues, lawyers, Google News, and Twitter. They also sent links presented as shared documents about climate issues, creating plausible reasons for recipients to enter account credentials. The operation extended beyond organizational boundaries.
Some activists' relatives were targeted, including a minor child. That detail shows why security planning for prominent advocates may need to account for family members as potential routes of pressure or access. The nearly 28,000 URLs measure campaign infrastructure, not confirmed breaches. The clearest reported compromise is Citizen Lab's conclusion that attackers accessed at least one advocacy group's email account.
What was stolen and how it was used
U.S. prosecutors said Aviram Azari managed hacking projects against climate activists, hired an India-based hacking group, and received reports identifying successful account access and stolen information.
Azari pleaded guilty to computer intrusion, wire fraud, and aggravated identity theft. He received an 80-month prison sentence. The Justice Department said stolen climate-advocacy documents were leaked to the press and influenced reporting about state investigations of ExxonMobil, as detailed in its sentencing announcement.
What remains alleged
The prosecution of Azari established his role, but it did not publicly resolve who ultimately commissioned the climate-targeting project. Citizen Lab's original investigation could not identify that client. A later indictment alleges that a lobbying firm working for an Irving, Texas oil-and-gas corporation hired Amit Forlit for the project.
Forlit has pleaded not guilty, so those allegations have not been adjudicated. Exxon and DCI Group deny involvement, and neither has been charged. That distinction matters: the evidence supports the existence of a coordinated hacking operation, but the alleged corporate chain remains unresolved, according to The Guardian's July 2026 account.
What targeted organizations should do
Organizations should prioritize phishing-resistant FIDO/WebAuthn multi-factor authentication for sensitive accounts. This login control can stop authentication on a fraudulent website even when the user follows a deceptive link, according to CISA's account-security guidance. A focused response should include these steps:.
- Verify unexpected document shares and sign-in requests through a separate, known communication channel.
- Treat messages about legal matters, climate documents, news alerts, or social platforms as possible tailored lures.
- Include publicly connected relatives in threat briefings, especially when attackers may use personal relationships.
- Preserve suspicious messages and URLs, report them promptly, and review the affected account for unauthorized access.
- Move email and other sensitive accounts to phishing-resistant FIDO/WebAuthn authentication.
