Environmental activists targeted in coordinated cybersecurity breach incident

Private investigators and hackers conspired to breach climate activists' accounts, feeding leaked documents to media outlets to undermine climate investigations targeting ExxonMobil.

Environmental activists were targeted in a coordinated cybersecurity breach orchestrated by Amit Forlit, an Israeli private investigator and former Israeli police officer, who pleaded guilty to conspiracy to commit computer hacking, wire fraud, and aggravated identity theft. The hacking campaign, which the U.S. Department of Justice began investigating in 2025, involved the systematic targeting of climate activists through phishing and other attack methods, with evidence of coordination traced to a single hacking group operating across multiple victims’ email inboxes. The breach went beyond targeting critics of specific corporations—the activists found themselves on an extensive target list designed to feed a broader disinformation campaign aimed at undermining state-level climate investigations.

The attack represents a deliberate convergence of private intelligence operations, corporate legal strategy, and coordinated hacking to silence environmental advocacy. Rather than a random or opportunistic breach, this incident followed a clear conspiracy chain: a D.C. lobbying firm identified targets and organizations to discredit, operatives like Forlit received those target lists, hired hackers to execute the intrusions, and then circulated the stolen documents back to media outlets in carefully crafted news stories. What made this campaign particularly damaging was its connection to corporate litigation—ExxonMobil’s legal team later used these leaked stories as evidence in court proceedings, weaponizing stolen information to defend against climate accountability investigations.

Table of Contents

How Environmental Activists Became Targets in a Coordinated Hacking Campaign

The targeting of environmental activists was not random or limited to a single organization criticizing one corporation. Investigators discovered that activists working on climate accountability issues faced systematic phishing attempts that, when traced through technical evidence found in email inboxes, pointed back to a single hacking group coordinating across multiple victims. This breadth of targeting revealed a campaign with organizational ambitions far larger than attacking individuals who questioned ExxonMobil’s practices—the victim list encompassed a wider range of environmental advocates and organizations that threatened corporate and political interests aligned against climate action.

The coordinated nature of the breach became evident as researchers traced the attack methods back to their source. Phishing emails, credential harvesting, and account compromise all followed patterns consistent with a single operation, suggesting professional orchestration rather than scattered opportunistic hacking. The involvement of Forlit and a co-conspirator named Azari demonstrated that this was not a spontaneous cybercriminal venture but rather a deliberate operation with clear objectives tied to specific political and legal outcomes related to climate regulation and corporate defense.

The Conspiracy Chain Behind the Coordinated Cyber Attack

The Justice Department’s investigation revealed a multi-stage conspiracy involving distinct roles and responsibilities. A D.C. lobbying firm served as the source of targeting intelligence, identifying which activists and organizations should become subjects of the hacking operation. This firm then passed target lists to operatives—Forlit and his co-conspirator—who coordinated with hired hackers to execute the actual intrusions.

After the hackers accessed activists’ accounts and obtained sensitive documents, the stolen materials circulated back to the lobbying firm, which then distributed these documents to media outlets with the apparent goal of generating damaging news stories designed to discredit climate investigations. This conspiracy structure created separation between the corporate interests benefiting from the breach and the hackers executing it, with the lobbying firm and private investigators serving as intermediaries. The fact that a co-conspirator named Azari was specifically tasked with hiring hackers demonstrates a deliberate outsourcing of the technical attack work, typical of operations designed to obscure accountability chains. Yet despite these layers of separation, the Justice Department was able to trace the entire operation back to its originators, proving that coordination between private intelligence, corporate defense strategies, and cybercriminals leaves investigative trails even when parties attempt to compartmentalize their roles.

Methods Used in the Cybersecurity Breach Against Climate Activists

The attackers relied on phishing as a primary entry vector, using emails to trick activists into compromising their credentials or revealing sensitive information. Once inside activists’ email accounts, the hackers extracted documents and communications that revealed both personal vulnerability and strategic information about climate investigations targeting ExxonMobil. The technical sophistication was adequate but not extraordinary—the breach succeeded through social engineering and access to victim accounts rather than zero-day exploits or advanced persistent threats, making it a relatively straightforward operation once target lists and financial backing were secured.

The use of phishing against individual activists rather than attacking organizational infrastructure at scale meant that success depended on identifying specific targets with compromise-able attack surfaces. Environmental advocates, often operating across multiple organizations and less likely to have extensive security infrastructure, presented ideal targets for this type of credential-based compromise. Once activists’ email accounts were breached, their stored documents—including litigation strategy, communications with attorneys, and materials related to corporate investigations—became immediately accessible to conspirators seeking to obtain intelligence on climate accountability efforts.

The Real-World Consequences for Activists and Climate Investigations

The stolen documents were weaponized in a secondary attack: instead of remaining private, they were leaked to media outlets in stories specifically designed to undermine state-level climate investigations of ExxonMobil. This transformation of stolen communications into news narratives served multiple purposes for the conspiracy—it created an appearance of scandal around the activists and their organizations, distracted public attention from the underlying climate investigations, and provided ExxonMobil’s legal team with what they could frame as independent “evidence” to use in court proceedings. The company’s lawyers then cited these media stories in litigation, completing the cycle of damage: private communications stolen via hacking, leaked to create scandals, and then introduced as ostensibly legitimate documentary evidence.

For the targeted climate activists, the breach created layered harm. Beyond the violation of privacy and the theft of strategic communications, they faced the distraction and credibility attacks that came from having their private conversations weaponized against them publicly. State-level climate investigations that might otherwise have proceeded with focus and momentum became entangled in defense against the leaked-document narratives, diminishing the investigators’ ability to hold corporations accountable and delaying climate-related legal and regulatory actions that depended on their work.

Exposure Risks for Advocacy Organizations

Advocacy organizations face heightened vulnerability in cybersecurity breaches because their work often centers on information that powerful entities actively seek to suppress or discredit. Environmental activists, in particular, operate at odds with well-resourced corporations and their legal defense infrastructure, making their communications and strategies valuable intelligence to those seeking to protect corporate interests. Unlike data breaches at financial institutions or retailers where stolen information is primarily monetized through fraud, breaches targeting activists create asymmetric exposure—the attackers gain strategic advantage in legal, regulatory, and public relations contests where the stolen information becomes a weapon.

A significant limitation in defending against campaigns like the one targeting environmental activists is that traditional security practices alone cannot prevent conspiracies involving people with authorized access to target lists and coordination authority. Even organizations with strong cybersecurity posture remain vulnerable when the attack vector originates with a trusted intermediary, like a lobbying firm maintaining target databases or law enforcement with access to activist information. This represents a fundamental challenge in the security of advocacy work: the adversary may not be a distant cybercriminal but rather an entity with legitimate reasons to know who activists are and what they are working on.

Amit Forlit’s guilty plea to conspiracy to commit computer hacking, wire fraud, and aggravated identity theft represented a significant outcome in holding perpetrators accountable for the environmental activist breach. The fact that prosecutors were able to secure a guilty plea from the operation’s orchestrator, rather than fighting an extended trial, suggested substantial evidence linking Forlit to the hacking campaign and the conspiracy’s broader objectives.

His identity as a private investigator and former Israeli police officer underscored how law enforcement backgrounds and private intelligence operations can blur together to facilitate corporate-directed attacks against civil society. The charges Forlit faced—computer hacking, wire fraud, and identity theft—captured the distinct criminal elements of the conspiracy: the unauthorized access to activists’ accounts, the fraudulent misrepresentation involved in phishing, and the use of stolen identities to maintain access and cover tracks. The inclusion of wire fraud charges reflected the interstate and electronic nature of the communications used to coordinate the conspiracy, allowing federal prosecutors to assert jurisdiction and pursue charges under statutes designed to address sophisticated, multi-party fraud schemes.

What This Incident Reveals About Attacks on Civil Society

The coordinated breach of environmental activists demonstrates how surveillance and hacking can be weaponized not only for financial gain but also to undermine political and legal processes. When corporate entities have sufficient resources to hire private investigators, who then hire hackers, who compromise activists’ communications, the resulting intelligence becomes a tool for corporate defense in litigation and regulatory proceedings. This creates a market for cybercriminal services directed specifically at suppressing advocacy and investigation into corporate conduct.

The Justice Department investigation that progressed through 2025 illustrates both the possibility of holding perpetrators accountable and the complexity involved in untangling multi-party conspiracies spanning private investigators, lobbying firms, hired hackers, and corporate clients. The targeting of climate activists reveals that environmental advocacy remains a contested space where powerful interests may employ tactics ranging from legal intimidation to coordinated hacking to prevent accountability for corporate environmental practices. The conspiracy’s structure—with the lobbying firm at the center identifying targets while private operatives handled hacking and distribution—created a business model where civil society activists could be systematically surveilled, compromised, and discredited as a service to corporate interests.


You Might Also Like