A decade after the #ExxonKnew movement began to peel back the layers of the fossil fuel industry’s historical climate deception, a chilling new chapter in that struggle has emerged. A high-stakes legal battle currently unfolding in U.S. federal courts is peeling back the curtain on a sophisticated, international cyber-espionage operation that allegedly targeted the very activists, lawyers, and journalists working to hold oil giants accountable.

For years, those at the forefront of climate advocacy operated under a persistent, gnawing sense of surveillance. Now, through a series of indictments, extradition proceedings, and investigative reports, that paranoia is being validated. The evidence suggests that for years, a "hack-for-hire" industry was fueled by the deep pockets of corporate interests, turning private investigators and cyber-mercenaries into digital weapons aimed at environmental dissent.

The Genesis of a Digital Siege

The story began in earnest in 2016. Kert Davies, founder of the Climate Investigations Center, was among a cohort of strategists meeting at the Rockefeller Family Fund’s offices in Upper Manhattan. Their objective was clear: utilize the findings of explosive media reports—which proved that Exxon Mobil’s own scientists had identified the dangers of fossil fuels as early as 1982—to demand corporate accountability.

They wanted to hold Exxon accountable. Then they got hacked.

Shortly after that meeting, the "weird" emails began. They arrived in the guise of social media notifications—Facebook pokes, LinkedIn connection requests, and Twitter alerts. It was a classic phishing campaign, but one with an unnervingly precise focus.

"Has anybody received weird emails?" Davies asked his colleagues on a listserv. The response was a resounding, fearful "yes."

By April 2016, the scope of the operation became terrifyingly clear. A Wall Street Journal report cited a private, detailed agenda from the very meeting Davies had attended in January. The resulting headlines alleged "secret coordination" among activists—a narrative that Exxon Mobil quickly weaponized in court filings to deflect from the mounting pressure of investigations by 17 state attorneys general. The leaked internal documents became a shield for the company, painting its critics as conspirators rather than concerned citizens.

They wanted to hold Exxon accountable. Then they got hacked.

A Chronology of Intrusion

The infiltration was not a random act of digital vandalism; it was a multi-year, multi-continental campaign of professional intelligence gathering.

  • 2015: As investigations into Exxon intensified, evidence suggests that a lobbying firm with deep ties to the oil giant began looking for ways to "go on offense."
  • 2016: The peak of the phishing campaign. Climate activists, lawyers, and financial journalists were bombarded with sophisticated, personalized lures.
  • 2017: Researchers at the University of Toronto’s Citizen Lab, led by John Scott-Railton, identified the perpetrators as "Dark Basin," an India-based hack-for-hire group. They discovered that the targets were not limited to climate activists but included hedge funds and short sellers—anyone whose work might threaten the interests of a well-funded client.
  • 2019: Following extensive evidence provided by victims and researchers to the Department of Justice, federal agents arrested Israeli private investigator Aviram Azari at JFK International Airport.
  • 2022: Azari pleaded guilty to hacking charges, admitting he had been paid over $4.8 million to manage these projects, though he maintained silence regarding his ultimate clients.
  • 2024-2025: The U.S. government issued an arrest warrant for another Israeli private investigator, Amit Forlit. His subsequent extradition to the U.S. and the unsealing of his indictment provided the "missing link" connecting the hackers to the corporate world.

The Anatomy of the Hack-for-Hire Industry

The indictment against Amit Forlit, unsealed earlier this year, describes a "sprawling cybercriminal enterprise." According to the document, a principal at a D.C.-based lobbying firm—which Forlit’s own legal team identified in U.K. court filings as the DCI Group—contacted Forlit to help address "recent attacks" on a major oil and gas corporation.

The indictment outlines a proposal for a $125,000 monthly budget to "operationalize the research on the bad guys." This research, gathered via illegal breaches of email accounts, was allegedly funneled back to the lobbying firm to be used in legal proceedings and public affairs campaigns. The sheer scale of the operation was staggering; between 2014 and 2017, Forlit’s firms allegedly raked in $7 million for these services.

They wanted to hold Exxon accountable. Then they got hacked.

For victims like Lee Wasserman of the Rockefeller Family Fund and attorney Jennifer Cunningham, the revelation is both vindication and a source of profound violation. "We’re all sitting on the edge of our seats waiting to see if we hear [the full story] at trial," Wasserman said. Many, including Cunningham, have only recently realized—based on the DOJ’s victim notifications—that their accounts were likely successfully breached, a fact that had remained hidden for nearly a decade.

Official Responses and Corporate Denials

The corporate entities involved have maintained a strict posture of denial. Exxon Mobil has consistently stated that it has not been involved in, nor is it aware of, any hacking activities. In a previous statement, the company noted: "If there was any hacking involved, we condemn it in the strongest possible terms."

DCI Group has been equally adamant. Craig Stevens, a partner at the firm, stated: "We have been told by the government that neither DCI nor any of its personnel are under investigation," adding that the firm had "no knowledge or understanding of the alleged hacking activity." He dismissed any insinuation of involvement as "completely false and unsubstantiated."

They wanted to hold Exxon accountable. Then they got hacked.

Despite these denials, the proximity of the hackers’ targets to the specific legal and political battles facing Exxon is difficult to ignore. The DOJ investigation explicitly confirms that stolen materials from the activists were integrated into Exxon’s own court filings.

Implications for Democracy and Digital Safety

The "Dark Basin" operation serves as a grim warning about the fragility of modern advocacy. The chilling effect on climate activists was immediate: they stopped using email for sensitive communications, began whispering in their own homes, and operated under the constant, demoralizing suspicion that they were being tracked by professionals.

John Scott-Railton, who continues to track digital threats, views this as a watershed moment for environmental organizations. "The #ExxonKnew hacking campaign stands out, in my mind, as one of the largest and most brazen hacking attempts I’ve ever seen," he noted.

They wanted to hold Exxon accountable. Then they got hacked.

The danger, however, is not a relic of the past. As cyber-intelligence firms develop increasingly sophisticated, "zero-click" spyware—tools that do not even require a user to click a link to initiate a breach—the barrier to entry for corporate espionage has lowered significantly. The Forlit case highlights that the "hack-for-hire" model is not just a nuisance; it is an infrastructure of intimidation that threatens the integrity of civil society and the legal system.

For Kert Davies, the emotional toll remains high. He is still living with the uncertainty of whether his most private professional communications were exposed. "It’s personal," he says. "Because I really don’t like bullies or liars or cheaters."

As the trial moves forward, the climate movement—and the public at large—waits to see if the judicial system will finally pierce the veil of corporate deniability and hold those who commissioned this digital shadow war accountable. The outcome will likely set a precedent for how corporations interact with their critics in the digital age, determining whether the cost of silence will be paid by activists or by those who choose to pay others to hack them into submission.

By Nana Wu