NotesNo. 18
Case FileSeptember 29, 2026 · 7 min

The cases where it didn’t work

Every earlier case file in this column was one where the play worked, which tests nothing. France 2017 is the counter-case: the same denominator attack as Slovakia, aimed at a blackout, and it lost.

By J.W. Bouckaert

Every case file in this column has been one where the play worked. Brasília, Bucharest, Nairobi, Libreville. A rubric only ever pointed at successes is not being tested by them, and a reader who has noticed is entitled to ask whether the framework does any work at all. So this week, a failure.

There is a good one. On Friday, May 5, 2017, roughly fifteen gigabytes of material stolen from Emmanuel Macron’s campaign, including 21,075 emails, were dumped online two days before the second round of the French presidential election. The hashtag #MacronLeaks appeared in close to half a million tweets in twenty-four hours. Macron won on the Sunday with 66.1 percent of the vote.

What makes it worth a file is that the attack was aimed squarely at the denominator, and the denominator held. The dump landed hours before midnight on the Friday, when French electoral silence begins: the window in which, under Article L. 49 of the Electoral Code, the candidate cannot answer and the press is restricted in what it can carry. That is the Slovakia move from week eleven. Jean-Baptiste Jeangène Vilmer’s post-mortem for the Atlantic Council and IRSEM supplies the other half of the design: the package had been padded with unrelated material to make it too large to examine in the time available. The contents were never the point, and Vilmer puts the bet in his own words:

not what was in the leak, but the fact that there was a leak.

Vilmer attributes the failure to three things: structure, luck, and response. Structure is the resilience term arriving decades early and by accident. Paid political advertising is illegal in France for the six months before a vote, broadcast airtime is rationed by the regulator, and the silence period is written into statute. None of it was designed against hack-and-leak operations.

Inside the window, the response was fast. At ten in the evening the campaign alerted the broadcast regulator, which emailed television and radio newsrooms ninety minutes later. The following morning the electoral commission issued a formal recommendation to the press, written in the middle of the blackout with the authenticity question still open:

data presented as coming from the candidate’s information systems, but part of which is probably made up of forgeries.

It asked news organizations, and their websites in particular, not to report the contents. Most traditional media complied. Whatever one thinks of a state asking that, and it is worth arguing about, as an intervention on time-to-counter it is the most direct in any case in this column.

Part of the response was the campaign’s own preparation, and it is the part I find genuinely novel. Warned in early February that they were being watched, Macron’s digital team seeded their own systems with false credentials and forged documents, assuming they would be breached anyway. Some plants were plausible. Others appear to have been jokes: one forged email about a defense purchase was addressed to characters invented by a pair of French comedians, copying in a CIA agent borrowed from a spy spoof. By the time the dump was published, an estimated fifth of it was fake, some planted by the attackers and some by the campaign, and nobody could sort one from the other at speed. Macron did not have to explain his emails; the operators had to establish that any of it was real, and they had two days.

That defense is worth naming, because it appears nowhere else in this column. Every other denominator move is an attempt to answer faster. This one raises the attacker’s own time-to-verify, which is the same variable pointed in the other direction.

Now the part that disciplines the rubric. Vilmer’s remaining reason is luck, and he does not soften it. The attackers were sloppy and overconfident. Macron became a front-runner only in early February, which left little time to get inside, and there was nothing incriminating to find. The forgeries were clumsy, the cultural read was wrong, and the campaign ran under an English hashtag pushed mainly by the American alt-right. Emilio Ferrara, working from nearly seventeen million posts, found that the accounts engaging with #MacronLeaks were largely foreigners with prior alt-right interests rather than French users. Vilmer’s summary is that France was fortunate, and that smarter attackers under the same conditions could have done considerably more damage.

Score the event and the equation gets the direction right: high numerator, high resilience, a denominator attack that ran into a defense prepared to meet it. But a large share of what happened sits in a term the equation does not contain, which is whether the operator was any good. There is no variable for competence. The framework prices the pressure applied and the resistance available, and then a campaign that had not bothered to learn what scandalizes a French electorate throws the match. I would rather write that down than let the case stand as a clean confirmation.

Two cautions before anyone reaches for France as a model. Vilmer notes that what was true of the French information environment in 2017 may not have survived the years since, and he wrote that in 2019. Resilience decays, and a case file is a photograph. The structural advantages were also inherited rather than built, which is difficult to recommend to a country that does not have them.

The lesson is narrower than the usual story, which treats France as proof that saturation can be beaten. What France showed is that the denominator is where the fight happens, that preparation bought the room the time it needed, and that the operators helped. Two of those three are reproducible.

Next week the column turns forward: C2PA and the provenance bet, which is the one defense in the book that does not depend on the operators being careless.

— J.W.B.
Note 18 of 24

Sources
  1. 01Jean-Baptiste Jeangène Vilmer, The “Macron Leaks” Operation: A Post-Mortem, Atlantic Council (Digital Forensic Research Lab, Eurasia Center, Future Europe Initiative) and IRSEM, French Ministry of the Armed Forces (2019).The primary study for this case and the reason the post exists, read in full rather than summarized. Cited for the scale and timing of the leak (roughly 15GB and 21,075 emails, released Friday 5 May 2017, two days before the second round, hours before the electoral silence); for the finding that the package was padded with unrelated material so that it could not be examined in the time available, making the bet the existence of the leak rather than its contents, in his phrase quoted in the post, “not what was in the leak, but the fact that there was a leak”; for the structural factors, including the six-month ban on paid political advertising and the statutory silence period; for the sequence of the response, the campaign alerting the broadcast regulator at 10pm and the regulator emailing newsrooms at 11:30pm; for the campaign’s cyber-blurring, the deliberate seeding of false credentials and forged documents including the fabricated defense contract naming characters invented by French comedians; for the estimate, attributed to journalist Antton Rouget, that around 80 percent of the dump was genuine; and above all for the analysis dividing the failure between structure, luck, and response, including the judgment that France was fortunate and that smarter attackers under the same conditions could have done considerably more damage. The caution that the 2017 French information environment may not have survived the years since is also his.https://www.atlanticcouncil.org/wp-content/uploads/2019/06/The_Macron_Leaks_Operation-A_Post-Mortem.pdf
  2. 02Commission nationale de contrôle de la campagne électorale en vue de l’élection présidentielle, Recommandation aux médias suite à l’attaque informatique dont a été victime l’équipe de campagne de M. Macron, Paris, 6 May 2017 (2017).The intervention itself, read in the original French from an archived copy because the commission’s site no longer serves it. Quoted here for the commission’s own description of the material as “data presented as coming from the candidate’s information systems, but part of which is probably made up of forgeries” (my translation), and cited for its request that news organizations, and their websites in particular, not report the contents, on the grounds that the free expression of the electorate and the sincerity of the ballot were at stake. Notable for being issued inside the blackout, the morning after the dump, with the authenticity question still open.https://web.archive.org/web/2017/http://www.cnccep.fr/communiques/cp14.html
  3. 03Emilio Ferrara, Disinformation and Social Bot Operations in the Run Up to the 2017 French Presidential Election, First Monday, vol. 22, no. 8 (2017).Read for the audience finding rather than the bot detection. From a dataset of nearly seventeen million Twitter posts collected between 27 April and 7 May 2017, Ferrara concludes that the accounts engaging with #MacronLeaks were mostly foreigners with a preexisting interest in alt-right topics and alternative news media rather than French users, which he offers as a reason for the campaign’s scarce success. Confirmed against the author’s own preprint rather than taken from Vilmer’s citation of it.https://arxiv.org/abs/1707.00086
Related notes