You Cannot Out-Discipline Your Own Paperwork
What the Skripal poisoning reveals about digital privacy, and why the same machine that burned three GRU officers is pointed at you.
What the Skripal poisoning reveals about digital privacy, and why the same machine that burned three GRU officers is pointed at you
There is a comforting myth about privacy that the Skripal poisoning demolishes more thoroughly than almost any case on record. The myth is that privacy is a discipline problem, the idea that if you are careful enough, quiet enough, disciplined enough in your own behavior, you can stay invisible. Skripal proves this is not true. It proves that the people most likely to burn you are not the ones watching you in the field. They are the clerks, the databases, and the bureaucracies that documented you long before you ever did anything worth hiding.
What follows is how the case actually unfolded, and why it is arguably the single most important privacy lesson available to anyone who is not a Russian military intelligence officer, which, statistically, is most of us.
THE CORE IDEA.The people most likely to expose you are not watching you in the field. They are the institutions that already wrote you down. Your behavior is one layer of your privacy. What has been recorded about you, and who can buy it, is the layer that actually decides the outcome.
The tourists who came for the spire
On 4 March 2018, Sergei Skripal and his daughter Yulia were found slumped on a bench in Salisbury, England. Skripal was a former GRU colonel who had spied for British intelligence and been resettled in the UK after a 2010 spy swap. Someone had smeared Novichok, a Soviet-designed, military-grade nerve agent, on the front door handle of his home. Both Skripals survived after weeks in critical condition. A police officer who responded was poisoned too. And months later, a woman named Dawn Sturgess found the discarded counterfeit perfume bottle the agent had been carried in, sprayed it on her wrists thinking it was perfume, and died. She had nothing to do with any of it. That detail matters, and it returns at the end.
The two men who carried out the attack flew Aeroflot from Moscow to London, spent two nights in a cheap hotel in East London, took a reconnaissance run out to Salisbury on the 3rd, went back on the 4th to do the job, and flew home that same night. They traveled as "Alexander Petrov" and "Ruslan Boshirov." A third officer, "Sergey Fedotov," flew in separately and ran the London end from a hotel near Paddington.
When British police released their photographs and the two men were eventually pressed to explain themselves, they went on Russian state television and said they were tourists. They had come all the way to Salisbury, they explained, to admire the cathedral, specifically its famous "123-metre spire," a figure they had apparently lifted straight off the cathedral's Wikipedia page. It was, and remains, one of the least convincing cover stories in the history of the trade. But the cover story did not matter. The alibi was a sideshow. By the time they were on television talking about Gothic architecture, they were already finished, and they had been finished not by anything they said or did in England, but by paperwork generated in Moscow years earlier.
How they were actually caught
Everyone remembers the CCTV. The British did excellent, patient forensic work, reconstructing the two men's movements minute by minute from cameras, travel records, and hotel swabs, right down to finding Novichok traces in the London hotel room where they had stayed. That work is real and it mattered for the criminal case. But CCTV only ever gave the British two faces and two fake names. It did not, on its own, tell anyone who these men actually were.
That part, the unmasking to true names, ranks, home addresses, and eventually an entire unit roster, was done by journalists. Bellingcat and their Russian partner The Insider did it from outside Russia, with no defector, no human source, no double agent inside the GRU. They did it with leaked and purchasable databases. And the way they did it is the whole lesson.
They started with nothing but the photos and the aliases, and the aliases went nowhere. So they got hold of the men's internal passport files, sourced from people with access to Russia's central passport and residential databases, the kind of access that, in a corrupt digitized state, is simply for sale. And the files lit up like a Christmas tree. Here is what they showed, and not one item on the list is something a careful operative could have scrubbed in the field:
- No record before 2009 or 2010.People who exist have histories. Manufactured identities begin abruptly on the day the state decides to create them.
- A "Do not provide information" stampthat a police contact said he had never once seen on an ordinary civilian file, plus a biographical page left blank and marked with the Russian initials for "top secret."
- An issuing authority of Unit 770001, a single central Moscow passport desk reserved for intelligence officers and a handful of state VIPs.
- A telephone number stamped on the file that a 2012 Moscow directory tied to a Ministry of Defense exchange at the GRU's own headquarters. The men's cover documents pointed, like a weathervane, straight at the building they worked in.
- Sequential passport numbers.The two documents differed by three digits from each other and sat only twenty-six numbers from the passport of a separately exposed GRU officer. One burned officer becomes a seed, and the batch numbering hands over all of his colleagues.
From there it was almost mechanical. Bellingcat reasoned that an officer of "Boshirov's" apparent rank would have gone through an elite military academy, found the academy, found a decorated colonel named Anatoliy Chepiga who had received Russia's highest honor and then conspicuously vanished from every photograph you would expect a decorated man to appear in, and matched his 2003 face to the 2009 cover photo. "Petrov" turned out to be a naval doctor named Alexander Mishkin, whose cover identity had lazily kept his real date of birth, and whose personal car had been registered to an address that was, once again, GRU headquarters. Villagers in Mishkin's home town recognized the photo.
And then the whole thing scaled. A few months later a linked GRU cyber team was caught red-handed in the Netherlands trying to hack the chemical-weapons watchdog that was analyzing the Salisbury samples. When they were rolled up, one of them was carrying an almost unbelievable artifact: a taxi receipt for a ride from a street next to GRU headquarters to the Moscow airport. He had kept it, presumably to expense it. A spy on a black operation held onto a taxi receipt because some accountant back home needed it for the books, and that receipt ended up in a Dutch intelligence briefing. But the real prize was one of their personal cars, found in a leaked vehicle-registration database, registered to the street address of their GRU unit. Reverse-search that one address and you get a roster of 305 people, with names, passport numbers, and in most cases mobile phone numbers. One of the largest single exposures of an intelligence service's personnel in modern history, and it came out of a car registry, because officers were registering their cars to their military units to dodge traffic tickets.
The distinction that runs the whole case
Here is the frame that matters most, because it is the one that transfers directly to ordinary life. There are two kinds of signature that can burn a person, and they are not equally within anyone's control.
FIELD ERRORS (you can fix these).Signatures generated in the moment, through your own behavior. The kept taxi receipt. A real birthday left inside a cover identity. The online dating profile one of the officers had set up. Embarrassing, avoidable, and a disciplined operator mostly does avoid them.
INHERITED SIGNATURES (you cannot).Signatures baked in by the institution that documented you. The sequential passport number. The "top secret" stamp. The Unit 770001 issuer. The headquarters phone number in the travel file. The car registry that ties 305 people to one building. Written down in Moscow, years earlier, by people the operative never met, in systems he did not control.
No amount of personal discipline in Salisbury could have scrubbed the second list, because none of it was created in Salisbury. That is the whole case in one sentence, and it is worth committing to memory.
THE ONE-LINE LESSON.You cannot out-discipline a signature that the bureaucracy building your cover has already baked into the system.
This is clarifying and a little frightening in equal measure. Once it lands, the question changes. It stops being "are you being careful enough?" and becomes "what has already been written down about you, and who can already buy it?"
The ten-euro version of you
Here is the part that should actually keep you up at night. Up to this point it reads like a story about spies, and you are not a spy, so it is fair to ask who cares.
Buried in the reporting on this case is a set of numbers worth sitting with. In Russia, a Bellingcat investigation found, you can buy a target's full personal dossier, including date of birth, passport number, license plate, vehicle history, traffic violations, and the Moscow parking spots he uses most often, from a Telegram bot, for about ten euros, delivered in two or three minutes. A BBC journalist reported that months of a person's actual phone-location data ran about a hundred and ten euros, and that when it arrived it was accurate, right down to near-exact locations over time. There was no hacking involved in any of this. It was a retail transaction. The Russian state's own leaks, corruption, and data-broker economy had turned every citizen, and fatally every officer with a manufactured identity, into a product you could order like a pizza.
The reflexive American response is "well, that's Russia, that's a corrupt failed system, it can't happen here." That response is wrong, and it is the most dangerous thing you can believe.
You do not need a corrupt cop selling records out the back door when you have a legal, retail, industrial-scale data-broker economy operating in broad daylight. In the United States, brokers most people have never heard of assemble and sell dossiers on essentially every adult in the country. The location data that gets brokered here comes not from bribing a telecom clerk but from the advertising exchanges built into the ordinary apps on your phone, the weather app, the game, the mapping tool, all quietly bidding your location out to anyone willing to buy the feed. Investigators and journalists have shown, more than once, that this commercial ad-tech "bidstream" data can reconstruct the movements of specific people, including military and government personnel, without a warrant, a hack, or a single illegal act. The Russians built their surveillance substrate out of corruption. The United States built its version out of a business model. The end product, a purchasable, queryable, historical map of where you are and who you are, is functionally identical. The American one is just better funded and has a nicer user interface.
KEY TAKEAWAY.You do not need a corrupt state to be for sale. A legal data-broker market and the ad-tech buried in ordinary apps produce the same purchasable map of your life. The mechanisms differ. The category does not.
The machine that burned three GRU officers is pointed at you, almost literally. Leaked and purchasable databases, telecom and travel metadata, vehicle and residence registration, and commercial location data are a single surveillance surface, and it does not care whether the target is a colonel in the GRU or an accountant in Fairfax. It queries everyone the same way.
Metadata is the substrate, not the exhaust
A second lesson sits layered inside the first, and it is about metadata specifically, because most people still fundamentally misunderstand what metadata is.
Metadata gets treated as harmless exhaust: who called whom, from where, when, and for how long. The content of the call is the real secret, the thinking goes, and the metadata is just the packaging you throw away. This is exactly backwards. In the Skripal case, nobody needed the content of anyone's phone calls. The coordinating officer, "Fedotov," ran good field discipline. He used an unregistered "ghost" number, and the hit team went into a communications blackout. And it did not save him, because a Russian mobile-operator insider leaked his metadata wholesale, and from that alone, just the pattern of when his phone was where, investigators reconstructed his movements across Moscow, London, and Switzerland and tied him to the operation. The content was never the point. The pattern of life was the whole game.
The irony in how that leak happened is worth pausing on. The whistleblower who leaked "Fedotov's" phone records reasoned that because "Fedotov" was a fake identity, because no such person actually existed, no real person's privacy was being violated, and therefore no law was broken. The cover identity, the thing meant to protect the officer, is precisely what stripped away the privacy protection a real human being would have had. The disguise became the vulnerability.
Most readers will never face that exact problem. The underlying truth still applies. Your carrier, your apps, your car, your building access system, and your travel bookings generate a continuous pattern-of-life record every hour of every day, and that record does not need the content of anything to be devastating.
KEY TAKEAWAY.Metadata is the substrate of modern attribution, not harmless exhaust. The shape of your life, drawn in dots, is enough, and nobody needs to read your messages to read the shape.
The other kind of failure, and why it belongs beside this one
The Skripal case is best understood beside a very different one: a U.S. prosecution of two Chinese intelligence officers, He and Wang, who were caught because the American "asset" they thought they had recruited was actually an FBI double agent, and because the bribes they paid in Bitcoin stayed traceable on the blockchain even after they ran them through a mixer designed to launder them.
The two are mirror images, and the contrast is the point:
- He and Wang, human-relationship failure.They trusted a counterparty who was compromised, and their money and their phones betrayed them through that human channel.
- Skripal and the GRU, institutional-signature failure. No asset, no double agent, no compromised human anywhere in the operation. They were undone by leaked institutional records, purchasable databases, and the signatures stamped into their cover identities.
Almost every way a person can be unmasked falls into one of those two buckets, and the reason both cases matter together is that defending against one does nothing to defend against the other. You can be perfectly disciplined about who you trust and still be sold for ten euros out of a database you never knew existed. You can lock down every database entry about yourself and still be handed over by one compromised friend. Real security means accounting for both surfaces, and most people, most organizations, and apparently at least one major intelligence service, only account for one.
What to actually do with this
A checklist is a strange way to end, because the whole point of this case is that the checklist mentality, the "be disciplined, be careful, follow the steps" reflex, is exactly what fails when the threat is structural. Still, the case should change how you think, and a few concrete things follow from it.
THE MINDSET SHIFT.Stop treating privacy as a function of your behavior alone. Start treating it as a function of what institutions have already recorded about you, and who can buy that record. Good habits are the field-discipline layer. The GRU had excellent field discipline, and it did not save them.
The layer that actually burned those officers was the inherited one, and for a civilian that inherited layer is the data-broker economy, the ad-tech location feeds, the breach corpora sitting on criminal forums, and the routine commercial and government records that quietly describe you. A few things are therefore worth more time than most people give them:
- Lock down your phone's location first. The apps that harvest and resell it are the closest civilian equivalent to what reconstructed a GRU general's movements. Audit permissions, kill background location, and treat "allow while using" as the ceiling, not the default.
- Pull yourself out of the data-broker market on purpose.Do not assume you were never in it. Everyone is in it by default. Opt out directly or use a removal service, and treat it as ongoing maintenance rather than a one-time chore.
- Assume every database about you is eventually public.Anything ever entered into a breachable system, which is every system, should be planned around as if it will leak, because on a long enough timeline it does.
- Guard metadata like a classified document.To a modern adversary, your pattern of life and a page marked secret are the same asset, and the pattern of life is the one that is quietly for sale.
Dawn Sturgess is the reason none of this can be treated as an abstract game. She was not a spy or a target or a player. She found a perfume bottle in a charity bin, and she died because a reckless operation, run by a state that authorized it at the highest level, left its weapon lying in a public place. The surveillance machinery described here is not aimed at any one person. That is the point. It is ambient, it is commercial, it is for sale, and it does not check your threat model before it hoovers you up. The officers who thought they were invisible were being described, in fine detail, in systems they never saw, and so are you.
The comforting version of privacy says: be careful and you will be fine. The Skripal case says something harder and truer. The record of you already exists, most of it was written by people you will never meet, and the real work is not staying quiet. It is understanding what has already been written down, and making the parts that matter harder to buy. You cannot out-discipline your own paperwork. But you can, at least, stop pretending it isn't there.