EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/cyberattack/sarah-palin-email-hack-2008
386/430

File EL-0045HighResolvedCyberattack / Email Account Compromise

Sarah Palin Email Hack

Also filed as Palin Yahoo! Mail Breach · 2008 Vice Presidential Candidate Hack

Anonymous hacked the personal Yahoo Mail account of Sarah Palin, the 2008 Republican vice presidential candidate. The attacker gained access by exploiting Yahoo's password recovery system, using publicly available biographical information to answer security questions. Screenshots of the inbox were posted online, exposing personal and political communications.

  • #anonymous
  • #sarah-palin
  • #email-hack
  • #2008-election
  • #yahoo-mail
  • #political-hack
Notoriety8/10
Event
16 Sept 2008
Disclosed
16 Sept 2008
Target
Sarah Palin
Actor
Anonymous
Scale
1 people
Status
Resolved

01Summary

On September 16, 2008, David Kernell, the son of a Tennessee state representative, successfully accessed Sarah Palin's personal Yahoo Mail account. Using only publicly available information such as Palin's birthdate, zip code, and high school, Kernell answered the account security questions and reset the password. He then took screenshots of the inbox contents and posted them on the imageboard 4chan and later on Wikileaks. The leaked emails revealed routine political communications and personal correspondence. The FBI quickly identified Kernell through IP logs, leading to his arrest. He was convicted of a felony and sentenced to one year in federal prison. The incident highlighted the vulnerability of webmail accounts to social engineering and poor security question practices.

02Background

The hack occurred during the final stretch of the 2008 US presidential campaign, with Palin serving as John McCain's running mate. The breach of a major political figure's personal email raised immediate national security and privacy concerns, becoming a major news story in the final weeks of the campaign.

03Key revelations

  1. 01The ease with which a personal email account could be compromised using only publicly available information.
  2. 02The vulnerability of major webmail providers' password reset systems to social engineering.
  3. 03The legal consequences of unauthorized email access, resulting in federal felony charges.

04Technical analysis

The attack did not involve sophisticated technical exploitation. Instead, it relied on social engineering and the exploitation of Yahoo Mail's password recovery system. By guessing the answers to security questions (birthdate, zip code, high school) which were publicly available through voter registration and Wikipedia, the attacker triggered a password reset and gained full access to the account.

Attack vector
Password Reset Exploitation / Social Engineering
Attack method
Account Takeover via Security Question Bypass
Initial access
Password reset via publicly available PII
Exfiltration
Screenshot capture and public posting

Vulnerabilities exploited

  • Weak Security Question Authentication (Yahoo Mail)

MITRE ATT&CK techniques

  • T1589.001

05Threat actor

Anonymous is a decentralized, global hacktivist collective. In this case, the perpetrator was an individual affiliated with Anonymous who acted independently using basic social engineering techniques rather than sophisticated technical exploits.

Aliases

  • Anonymous Collective
  • David Kernell

MITRE groups

  • T1589.001

Known members

  • David Kernell

Attribution sources

  • FBI Investigation
  • Court Records
  • Media Reports

06Victims and impact

Additional victims

  • Yahoo Mail

Countries affected

  • United States

07Data exposed

Data types

  • Emails
  • Personal Correspondence
  • Political Communications
  • Photographs

Notable documents

  • Screenshots of Palin's Yahoo Mail Inbox

08Financial damage

Primarily political and reputational damage.

09Timeline

  1. 2008-09-16David Kernell accesses Sarah Palin's Yahoo Mail account and posts screenshots on 4chan.
  2. 2008-09-17FBI identifies and arrests David Kernell.
  3. 2010-11-12Kernell convicted and sentenced.

10Key figures

  • David KernellHacker / Perpetrator · University of TennesseeAmericanConvicted and sentenced to 1 year federal prison.
  • Sarah PalinVictim · McCain-Palin CampaignAmericanPersonal emails exposed publicly.

11On the record

The ease of this hack is embarrassing. With just a little research online, anyone could have done it.

Security Analysts, Commentary following the incident.

12Reaction and fallout

Public reaction

The incident caused a political firestorm, with debates over whether the hack constituted a national security threat. It raised public awareness about the risks of security question-based authentication for public figures.

Political impact

The hack became a campaign issue, highlighting cybersecurity vulnerabilities for public officials and generating scrutiny of Yahoo's security practices.

13Legal

David Kernell was convicted of felony obstruction of justice and unauthorized computer access. Sentenced to 1 year and 1 day in federal prison plus 3 years supervised release.

Prosecutions

  • David KernellConvicted
    Charge
    Felony obstruction of justice, unauthorized computer access
    Jurisdiction
    United States (Eastern District of Tennessee)
    Sentence
    1 year and 1 day imprisonment

14Aftermath

Policy changes

  • Increased awareness of security question vulnerabilities in consumer webmail services.
  • Major tech companies began phasing out knowledge-based authentication.

Security improvements

  • Yahoo and other providers moved toward multi-factor authentication and two-step verification.
  • Deprecation of weak security question-based password resets.

15Significance and legacy

Significance

One of the most high-profile political email hacks in history, occurring during a presidential election. It demonstrated the profound vulnerability of personal online accounts to simple social engineering and set a legal precedent for prosecuting unauthorized email access as a federal crime.

Legacy

The case contributed to the broader movement toward stronger authentication methods (2FA, MFA) across all major consumer platforms and highlighted the need for public officials to maintain rigorous digital security practices.

16Disclosure and media

Authentication
FBI investigation and court proceedings

Media partners

  • CNN
  • The New York Times
  • ABC News

Publishing organisations

  • Wikileaks
  • 4chan

17Field notes

  1. 01The password reset questions were answered using Wikipedia and newspaper archives.
  2. 02Kernell was the son of a Tennessee state representative at the time of the hack.

18Resolution

Perpetrator convicted and sentenced. Yahoo subsequently improved its password recovery security.

19Sources

Wikipedia article ↗

Official documents

  • US v. Kernell court documents

References

  1. [1]FBI Investigation Records
  2. [2]Court Proceedings (US v. Kernell)
  3. [3]Media Reports (2008)
Fact sheetEL-0045

Dates

Event
16 Sept 2008
Started
16 Sept 2008
Ended
17 Sept 2008
Duration
2 days
Discovered
16 Sept 2008
Disclosed
16 Sept 2008
Resolved
17 Sept 2008
Ongoing
No

Target

Organisation
Sarah Palin (2008 Republican Vice Presidential Candidate)
Type
Individual
Sector
Politics
Country
United States

Actor

Name
Anonymous
Type
Individual Hacker
Nationality
American
Motivation
Political hacktivism and exposing alleged hypocrisy during the 2008 US presidential election.
Attribution
High
Status
Convicted
Arrested
Yes
Convicted
Yes
Sentence
1 year federal prison, 3 years supervised release

Data

People
1
Records
1
Volume
Screenshots of inbox
Sensitivity
Confidential
Published
Yes
Sold (dark web)
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.