Episode Info
- Season13
- Episode3
Hosted by Christina Ruffini and Sir Richard Dearlove
Guest
Christo Grozev
Christo Grozev is the lead Russia Investigator for open-source investigative website Bellingcat who hunted Russian trolls as a hobby and is now an internationally celebrated journalist on Russia's most wanted list for exposing GRU spies.
Episode Summary
Christo Grozev once humorously described himself as an ‘internet nerd’ who hunted Russian trolls in his spare time. Well, his hobby has now made him an internationally celebrated journalist - and earned him a place on Russia’s most wanted list. As Lead Russia Investigator for the open-source investigative website Bellingcat, Grozev is one of the best people to talk to if you want to learn more about the war of information being fought by Moscow, and how data trails from some of the GRU’s more clumsy spies are giving canny investigators and journalists the chance to expose some of Russia’s activities it would rather you not know about. Sir Richard Dearlove and Julia Macfarlane sit down with him to find out more.
Listen & Subscribe
- Watch on YouTube
- Listen on Apple Podcasts
- Listen on Spotify
Transcript
INTRODUCTION
Mcfarlane: You're listening to One Decision, the show that looks at the choices made that shape our world. I'm your host, Julia McFarlane. If you're Vladimir Putin, the list of things that cause you eternal headaches is probably very long, but somewhere near the top of that list is probably an oddly named investigative consortium known as Bellingcat. Back in 2014, British blogger Eliot Higgins, then known by most of the world as Brown Moses, his Twitter pseudonym at the time, was following the Syrian civil war in all its horror. Much of what was happening on the ground is being recorded and published almost in real time by activists, rebels, residents, and soldiers. Higgins, along with a few of his self-confessed internet nerds, began to catalog data and evidence of crimes, the use of various munitions, the areas impacted, and any identifying information that gave a picture of what was happening. As the work they carried out garnered more attention and recognition, they organized, and thus, Bellingcat was born. They expanded the scope of their data collection, harvesting publicly available information, satellite data, telephone directories, plane data. Soon, they were getting help from whistleblowers about plane manifests. And before long, Bellingcat's work was being cited as key evidence in some of the highest courts in the land. Higgins now describes his motley crew of investigators as the Kremlin's biggest nightmare. Their work got a boost with the arrival of Christo Grozev, a Bulgarian journalist who brought with him a wealth of experience in chasing corruption and criminality across Europe. Grozev has authored some of Bellingcat's landmark investigations, identifying, among others, the key suspects linked to the shooting down of the Malaysia Airlines flight MH17, the GRU officers involved in plotting a coup in Montenegro in 2016, and in 2018, the Russian suspects involved in the Salisbury poisonings that saw chemical weapons being deployed on the streets of Europe for the first time since World War Two. My co-host, Sir Richard Dearlove, I caught up with Christo recently to chat about how we are in a new age of open source intelligence gathering and what the pitfalls are in this emerging field. Christo, welcome so much to the podcast. Happy New Year to you. And you begin 2023 with the news a couple of weeks ago that the Russians have put you on their most wanted list according to the interior ministry. A rather dubious honor, no doubt. Congratulations, if that's the right word. What exactly are you wanted for according to the Russians?
INTERVIEW
Grozev: Happy New Year to you, and I have no idea. The Russians are not telling anyone what I'm wanted on. The Bulgarian government actually asked the Russian ambassador to Sofia, because I'm still a Bulgarian citizen, for an explanation. And the ambassador said, we have no idea. It will take a while to find out what he's charged with. But for now, we just wanna say to Mister Grozev, don't come to Russia. We don't want you there.
Mcfarlane: I mean, that's quite polite considering the Russians are advising you to stay away. I don't think they've given quite the same advance notice to other critics of the Putin regime. I have been a Twitter fan of yours for a really long time, even back in the days before you joined Bellingcat. Did you describe yourself as a Russian troll hunter in your spare time back in those days?
Grozev: That was true. Yeah. I think I was looking for Kremlin trolls. I think I invented the term before it was cool.
Mcfarlane: Yeah. Yeah. Happy days. I wanna start off by asking you. You spoke on a podcast recently, on the True Spies podcast, N Is for Novichok. You said Russia is a very online society, and it's a very corrupt one as well. And the two of these things together result in a lot of data being traded. A lot of the work that you do for Bellingcat is work that's sort of derived for you wade through a lot of these databases where a lot of information, a lot of personal data in Russia are freely bought on black markets. And in that podcast, you said that by 2018 when the Skripal incident happened, you had already amassed this collection of more than 500 databases containing telephone data, car ownership data, passport data, residential data. I mean, to many of our listeners, it might sound quite mad that this sort of thing is not protected by law in Russia.
Grozev: Well, I would add the third component that is particularly useful and prevalent in Russia. It is the obsession of the government traditionally with monitoring in a centralized way all of their citizens. So it's a centralized data storing of every single piece of everybody's life. That is the third ingredient. So it's corruption, it's transparency in terms of availability of this data, but also the online convenience of Russians. They prefer to do everything online, which the government is exploiting into essentially similar to the Chinese government into consolidating all of data about every aspect of people's life into a central database. So these things together result in a market that is pretty sizable in Russia. It is a large industry, a large market. And this has resulted in an industrialized state of this data market. Why? Because there are hundreds and hundreds of large companies that buy data from this gray market in order for them to control their employees, to do vetting of competitors, due diligence on applicants, job applicants, and so on and so forth. These were traditionally the large clients for this gray market of data. Add to that hundreds or maybe thousands of small-time crooks and criminals and scammers who are buying also data on their targets from this gray market. Then only recently, and I wouldn't say that Bellingcat was the first one that delved into that for more legitimate reasons, but it was not longer than the last five or six years that journalists, investigative journalists have actually delved into this market as well. So the market has existed. It's existed for decades, but before the internet, it was a market that you could find at the open flea market in the form of CD-ROMs with collected databases that were being sold by furtively looking around guys in Macintosh coats at again in Russian markets outside of Moscow and St. Petersburg. And in the last ten years, this has become all digital, all online, and that's what changed. But again, to describe the market, you would find these traders not necessarily on the dark web. You could find them on Telegram channels. Telegram is the most popular Russian messaging app. You could find them on websites that are not hosted in Russia, but are hosted in island countries and on forums. And you would find these people, anonymous people with strange names saying, I'm selling access to the phone records from this and this mobile operator for this and that price.
Mcfarlane: That's so fascinating. Richard, speaking of shady looking individuals in Macintosh coats looking furtively around in Moscow and Saint Petersburg, is any of this harkening back to your days as a spy chief? I mean, phone records and hard data like that, that's very classic sort of intelligence gathering, isn't it?
Dearlove: Yeah. But I think what you have to understand is I was a child of the Cold War really, or let's say a professional of the Cold War, I did retire a long time ago. And I think it's extraordinary what Christo is explaining because, you know, I just wonder at what point the Russian state became vulnerable to this degree of loss of data. Because certainly, pre the period of time that we're talking about, the extent of control that the Soviet state exercised, the extent of the control that Warsaw Pact governments exercised, really over every aspect of life, including data, was really extensive. And it was difficult to penetrate or get into these areas, except perhaps through classic espionage. I mean, let me give you a simple example. I served behind the Iron Curtain in Prague in the early 70s, in that decade. And, you know, when I was in Prague, it was actually very difficult to buy a street map of the city. I mean, just put it at its most banal. Because street maps were just not available. And the reason I'm giving that as an example, it shows the extent to which the state attempted to control every aspect of life that might have a security implication. So I find it quite revealing when Christo explains the way that one is now dealing with this, I wouldn't say avalanche, but there's clearly a cupboard stacked with data. And of course, in the modern world, data has a value, which is hard to estimate and describe, because it unlocks so many doors and gives us so much understanding of all sorts of problems. But I'm keen to ask Christo when he feels at what point did the system fall apart in Russia? Because really, that's what we're talking about with freelance individuals flogging this sort of stuff on the black market or whatever you like to call it, the gray market?
Grozev: I think the main question is not when objectively this secrecy collapsed, but when the government realized that it has collapsed in a way that can hurt them, it can hurt the regime. Because this only happened essentially with this Skripal investigation and around that with MH17 deeper dive that we did based on phone data. But before that, for about ten or fifteen years, the system was broken, had been broken, but nobody dared go and expose this and use it for legitimate public interest goals. And so far, as it was used only by criminals or by companies for corporate use, the government was fine with that. I mean, they were taking their cut of this large market, I'm sure. But then when journalists started delving into that, it became a problem and they started trying to fill in the holes. And they've gone through several iterations of trying to fix it. First one, they started deleting data about their spies and about operatives from the FSB and so on and so forth from public registers. But that caused major problems. First of all, it allowed us to compare old versions of the database with new versions of the database and do wholesale discovery of spies. We literally discovered about 3,000 GRU spies based on the difference between an older and a new iteration of a database. Then they figured out that there was a problem. It didn't help that the COVID era came in and a lot of FSB spies who had been deleted from databases couldn't even get on the tram because they couldn't scan their required QR code because they were not existing. They were dead souls. Right? So the government decided to bring these guys back to life, but just to change the data on them. So they started sort of poisoning the data by changing photographs, changing birth dates, and so on and so forth.
Mcfarlane: That's hilarious. It's like Laurel and Hardy do espionage.
Grozev: Yes. I was going to say Tom and Jerry, but Laurel and Hardy is probably a good enough analogy. So yeah, that is just an example of when the government realized and were fumbling trying to fix the problem. And on the other end of the spectrum, like in investigating war crimes in Ukraine at the moment, we're only using public data that can be acquired by anybody by just finding it on the internet based on postings on social media. But what we do is we preserve it in the way where chain of command, chain of custody is clearly maintained and can be validated by future courts. And that's a trick that we've kind of developed over the years. And it's not as sort of fancy and romantic as going and buying phone data, but it is evidentiary, it's completely evidentiary compliant.
Dearlove: Yeah, we used to call what you're describing providing signpost information. So you can actually, as it were, make sure that those prosecuting authorities know what they have to turn into evidence. They've got the material which has to become evidential which they can then present in court. Personally, I think this is a fascinating area and one in which clearly you are very very powerful now and you have some extraordinary achievements behind you.
Mcfarlane: Christo, people like you who are shining a light and revealing a lot of what is going on, a lot of the activities of the GRU and some of the Russians' involvement in a lot of international tragedies. One of which was the MH17 Malaysia Airlines flight, which left the Netherlands in July 2014 and then was downed by a surface-to-air missile all those years ago. And that was one of, I think, your earlier investigations for Bellingcat. I remember that day particularly very well because I was working in a major newsroom at the time, and it was perhaps a week or several weeks after that incident. A lot of photos had popped up on social media of that Buk missile on Instagram and on Twitter. And some of those photos allegedly painted this journey from Russia to occupied Eastern Ukraine. And I remember also very clearly, almost immediately, all international airlines boycotted Ukrainian airspace because of that attack, and they continued to do that for months and months afterwards. Christo, were you working with Bellingcat at that point? I mean, what do you remember of that day that the crash happened and how did the investigation that you carried out for Bellingcat begin?
Grozev: Well, that was the day that I actually changed my life because before that I was just a media investor who occasionally blogged on disinformation issues. But on that day, I was at my summer house in Bulgaria with my kids and this happened. And I decided to focus initially on whether or not the early intercepts that were published by the Ukrainian secret service, by the SBU were authentic or not because they immediately published intercepts of people, Russian mercenaries, Russian officers talking about shooting down a plane. And I, like many others thought, well, this can't be true. This is too good to be real. This must be faked. So actually I spent the next few days trying to ascertain whether these were real or fake recordings. And I even picked up the phone and called one of the numbers that had been shown on these intercepts on YouTube published by the SBU. And I was able to talk to one of the Russian mercenaries who actually confirmed that, yes, his voice had been on the tape, but he didn't mean that they shot down a plane. He came up with some alternative explanation. So I realized that these are real. In parallel, the fledgling Bellingcat team at the time I was not a part of, had started gathering the photographs of soldiers posting selfies in front of weapons that could have shot down MH17. And they started reconstructing a potential map, a potential route of the weapon all the way from the Russian base in Kursk through the border into Ukraine and back, totally based on selfies. So in fact, we worked in parallel on the same project, but taking different approaches to it. And at one point, Eliot Higgins, who was the founder of Bellingcat, he called me and said, why don't you start blogging for us instead of for yourself? We seem to be working on the same topic. So I kind of joined forces with them initially, again, focusing more on a data-driven approach and going and analyzing phone calls, doing voice analysis and doing a little bit more traditional journalism than Bellingcat was doing. And at one point I just joined the team and started working with them full time.
Mcfarlane: That's incredible. Richard, would your life as the head of an intelligence organization, would your life have been made any easier if Russian hostiles and soldiers posted selfies of what they're up to and showing their location and where they were at?
Dearlove: Well, I think it's an indication of how the technology that we now all have in our pockets has changed the world of intelligence. I mean, it's not just social media and the fact that we all carry our own powerful personal computers, it's the vulnerability of communications, it's the extent to which data is collected. I mean, the whole scenario has shifted and changed at such speed. I mean, I would be very interested to hear Christo's insights into the fundamental way that the information gathering arena has gone through a complete technological, cultural and social change.
Mcfarlane: But technological advances is one thing. But this is soldiers taking photos of their faces with military hardware in the background as things like a Buk missile is being smuggled across borders. I mean, that's not an issue of the technology changing to make those sorts of things easier. That is the soldiers themselves revealing sensitive information.
Dearlove: But it's a combination of human weakness, human behavior and the technology that they have in their pockets. In the past these sorts of things would have been quite impossible. I mean, I often say, you know, if you think back to the world in which I was a young man, in which I was brought up, in the UK, there was something called the General Post Office. I mean, the General Post Office had a complete monopoly on all communications, private and public. I mean, there was no other way to communicate with anybody. And the two worlds are almost unimaginable. And I mean, I won't get into detail, but for example, I used to professionally travel around the world as a different person. That is no longer possible. For reasons which are completely obvious now. You can't pick up a different passport and set off on a trip as a different person because it doesn't work any longer for reasons that we all understand, and Christo would understand that better than anybody.
Mcfarlane: Well, actually, that leads me on very nicely to a question I have for you, Christo, and that is about the curious case of Sergei Skripal. And that was a story that I spent a lot of time covering for ABC in Salisbury, and that was back in 2018. And it was that very issue of fake passports that really sort of set off your investigation into those two Russians who were announced as suspects by the British government. They released these two very blurry CCTV pictures of these two Russian guys who had landed in London and who had traveled to Salisbury twice on the days around March when Sergei Skripal and his daughter Yulia were initially found slumped on that park bench in the center of Salisbury. Take us through where you started that trail and how you were able to piece together the identities of these two people who later turned out to be GRU officers. Because I remember at the time when the UK government first announced that they were gonna be on the hunt for whoever poisoned Sergei Skripal, I remember being really confused because they said it's gonna take a long time to be able to comb through all the CCTV footage to find who was a suspect. I remember thinking, Salisbury is not that big, and that the area around that park is also not that big. How can it take quite such a long time to comb through CCTV and to see who was around and who was looking shady at the time? But actually, you guys managed to pick this up pretty quickly. We have two photographs and two clearly fake names. So as the British police announced the names and said, don't believe these are the real names. So Ruslan Boshirov and Alexander Petrov. And here are the photographs. And that's all we had to go on.
Grozev: But they also announced the approximate times of arrival of these gentlemen from Russia to Heathrow and back. And we had by that time, we knew that we could get the plane manifests of all the passengers on all the flights that flew on those days into London and back. So we got, I think four different flights, lists of passengers and we found matching names for these two gentlemen, Alexander Petrov and Boshirov. And then we noticed that their passport numbers on which they flew were almost consecutive. There were, I think, three or four different numbers between the two passport numbers. So we thought, well, this is odd. Either these are very close people that went to the passport office on the same day and got the passports at the same time, or we are observing a very curious blunder, operational blunder, and passports are issued consecutively to spies. Well, we have only one way to find out. Let's find out if these are real people. So we got the names and the birth dates and the passport number and acquired passport files, passport record dossiers from Russian black market for each of them. And we found that these were not usual passport files. If I get your file, if you're a Russian citizen, Julia, I would see all of the previous passports that had been issued to you in a sequence. I would see photographs from previous passports and so on and so forth. These guys had different passport files. They had only one passport issued. It was issued 2009, and they had only one photograph there of an adult 30-year-old person. So it's as if they were born when they were 30. So we knew that these are fake identities. But then we found out the clues on these passport files such as phone numbers that when we called up, we got somebody from the GRU answering and saying, yeah, who are you looking for? And so on and so forth. So it was a complete mess on the Russian side. And this took longer. This took about two months for us to find out who they really were. And we went through a very, very sort of a deductive approach of distilling who they might be and then finding the photographs of those other people and then matching them. It would be an hour's podcast to just describe that.
Mcfarlane: Christo, you're leaving out one of my favorite threads from that story, which was that that phone number that was tied to those earlier passports, which turned out to be a phone number from the Ministry of Defense. When other journalists made the same calls as you guys did in trying to ascertain who these people were, the Russian Ministry of Defense cottoned on to the fact that there was this leak and journalists were getting in on these officers' identity, they started picking up the phone and saying that, actually, hello. This is the flea market and things like that. The flea market, literally.
Grozev: Yes. Yes. I didn't believe when I read this on Novaya Gazeta, and I called and I got the flea market guy. Yeah. Probably the same guy who was selling data ten years earlier.
Mcfarlane: It's so interesting, essentially. And then of course, these guys did this bizarre thing where I think Putin also, he was starting when all the speculation that these were agents of the GRU started circulating. Putin went public to say that, no, they're not GRU. They're probably normal people who got mixed up in all of this. And then he said they should appear in public and set the record straight. And then I think the very next day, they did this interview with Russia Today and our old pal, Margarita Simonyan. They said that they were on holiday and they were so desperate to see that famous Salisbury spire having been told all about it by their friends. I mean, that was an extraordinary interview, wasn't it? I mean, what did you make of that?
Grozev: Julia, this was the interview that actually made me focus on this investigation because I watched it, I had followed the story, but I wasn't fully devoted to this investigation until I saw this interview. And I thought, okay, okay, they can't be that bad. What if we're wrong? What if the UK government is wrong? What if these are innocent tourists? Because nobody in their right mind would lie so blatantly. So maybe truth is stranger than fiction. Actually, this is what made me delve into it full time and discovered that, yeah, it was a blunder. And it was probably triggered by that statement from Putin that you mentioned. He was at some forum in St. Petersburg where somebody sort of blindsided him with a question, what about these guys that are accused by the UK? And he said, well, they're innocent tourists and they should come out and say it themselves. And this must have been the trigger for that stupid interview. But just one small thing here that I remember is I had to present actually the identity of the second of the two. I think it was Alexander Petrov who turned out to be a medical doctor with experience in chemical weapons to the British parliament. And we needed to really be sure that we're not making a mistake by identifying him as Mishkin the doctor. And that night before I presented in London, we sent a reporter to the little village where Mishkin grew up with the hope that he can get some relative or some neighbor to actually recognize him on the photograph and say that that's the same person. And in fact, they found not only neighbors and relatives who said, yeah, that's him. But they said, oh, that's him. And we've seen a photo of him with President Putin giving him a Hero of Russia award because he did so many things for the state. So we had complete validation from some neighbors in a small village before we presented to parliament.
Dearlove: I mean, like Christo, I think one has to be struck by the incompetence of the GRU. But I would also suggest that the GRU have a sort of slightly cowboy attitude towards a lot of that operational activity. And if you compare it with the other Russian intelligence service, the SVR, I would expect a much higher degree of professionalism.
Mcfarlane: I was gonna ask you, Richard, how do the good folks of the SVR and the FSB feel when these guys in the GRU who are essentially the Chuckle Brothers of the espionage world in Russia keep getting on the news for these kinds of clumsy exploits?
Dearlove: Well, I can't claim any profound insights, but I can imagine that there are SVR officers who've got steam coming out of their ears when they see what the GRU has been up to because the fact is that both services will get blamed for being incompetent. Whereas the SVR, when it was top quality, really was top quality in the way that it ran its operation.
Grozev: Well, the very fact that we haven't published much on SVR operations validates your assessment. It hasn't changed. I think the SVR is still much better. They're playing a longer game, but also they don't have to be as kinetic as the GRU are expected to be. So that's what helps them stay under the radar because they are gathering data and they're gathering intelligence. They rarely kidnap, blow up things, or poison people.
Dearlove: Correct? The GRU do some pretty odd things and they are a military service and under Putin they probably become much more aggressive and much more active. So I think Christo is correct, there is a difference between the two and the SVR has a much longer horizon and is much more careful. Not to say they don't make mistakes as well, but they're a different sort of service. The word is, Christo, as well that Putin relied on intelligence from the FSB in the lead up to the invasion of Ukraine. I don't have any special insights, this is really hearsay, but hearsay from people who are quite well informed. I mean, do you agree that it was probably the FSB that misled the Russians?
Grozev: I've seen. I've investigated. I totally agree with that assessment. I don't think it was the only source of information, but, of course, Putin would have expected the FSB to be in control of information in Ukraine. What I can tell you is that I've identified 160 FSB officers whose sole job was to develop assets in Ukraine in the five years before the war started. They were meeting with these assets around the world on regular intervals in Belarus, on islands, and the Caribbean. And funnily enough, I was able to identify these people because they were traveling on suspiciously short trips to places like the Seychelles or the Maldives. And nobody goes for sixteen hours to the Maldives and then flies back, but they did. Right? Because they had to meet with their vacationing assets from Ukraine there. So these were the people, 160 and maybe more, who had billions of rubles to spend on their assets in Ukraine, and those assets delivered apparently false information, just took the money and gave them nothing.
Dearlove: That is exactly the same story as I've heard.
Mcfarlane: Christo, last question. I want to ask you about your opinion on what's been going on at Twitter. Bellingcat obviously relies quite heavily on harvesting data on the open web, people posting photos. You know, having websites and social media platforms like Twitter, like Instagram is quite crucial to the work that you and your colleagues do. So how did you feel when Elon Musk took over at Twitter and immediately started shaking the company up, axing a lot of the staff, plunging the future of the site into a lot of doubt. I mean, there's a huge amount of digital forensics on the website right now that could, in the future, be key to investigations that you've not even started yet. You know, data that could prosecute war crimes. Do Twitter and other sites like it, do they need to be safeguarded?
Grozev: Well, absolutely, that was our first concern when Elon decided he's proceeding with the deal. His haphazard decision making is not something that is conducive to preserving data as you might imagine. So in fact, the first thing we did is we archived our own data, And fortunately, everything that we have started investigating, we've logged and archived, so it doesn't depend on the tweet continuing to be on the platform. We were more concerned about something else, which is the potential of Twitter if it's broken in terms of its self-moderating capability to become a conduit of very destructive fake news and conspiracy theories. And I'm afraid that that's where we might see it going to. And the other problem, of course, is that with the loss of trust by a lot of its customer base, we're going to be seeing a period of sort of dispersion of important evidentiary data into many, many different platforms. So we'll have to do a lot more harvesting from different places than the convenient system that we were allowing. But it's a shame what's happening there, that's my opinion.
Mcfarlane: Richard, did you have any thoughts on that?
Dearlove: No, not really. I don't personally live in the world of Twitter. I've always avoided it like the plague. I think it served me quite well. I don't do social media. And I think for someone like me, social media is not a place to go, and I think I've avoided some problems by avoiding social media.
Mcfarlane: And now you've proven right. Yeah. Interesting that your successor Richard Moore has a Twitter account and he tweets quite regularly.
Dearlove: Yes. I know. And I'm not going to, as it were, express an opinion.
Mcfarlane: That's very diplomatic. Very diplomatic. We've run out of time. But, Christo, I'm so glad we managed to get you on. And best of luck to your future escapades, and may you continue to catch more Russian baddies. And I hope you don't have any plans to go to Russia anytime soon.
Grozev: Nope. I actually was blacklisted in 2016, so them asking me again to not go was a bit redundant.
Mcfarlane: I'm in awe of your achievements. They're remarkable. You really done a great job.
Grozev: Thank you.
Mcfarlane: We've come to the end of another episode of One Decision. If you enjoyed this week's podcast, why not subscribe to us so you never miss a show? We drop new pods every Thursday. From me and the team, thank you so much for listening, and see you next time.





