In September 2022, the hacktivist group Guacamaya breached the email servers of Mexico's Secretaría de la Defensa Nacional (SEDENA) and released roughly six terabytes of internal communications to Distributed Denial of Secrets. A small team at UC Berkeley's Human Rights Center analyzed the data to investigate how the military targeted journalists and human rights defenders with spyware. The source article, published by Lawfare, describes the project as a case study in conducting such investigations with limited resources.
The team faced a fundamental challenge: turning unstructured email data into evidence without an established methodology. While processing six terabytes is not difficult for modern data science, human rights research often lacks the technical capacity and funding for such work. The Berkeley center is self-funded, which constrained experimental exploration. To work around this, the team turned to graph analytics, treating email addresses as vertices and communications as edges to map networks of military personnel involved in surveillance.
Because testing algorithms on the full dataset was infeasible, the team first worked with a smaller related leak, the Hacking Team archive, to refine their approach. The article notes that the project failed many times before it worked, and it highlights how human lapses—such as an officer emailing slides to a less-secure server—provided key leads. The source does not compare with other investigations, but it offers practical lessons for other resource-constrained teams tackling large leaked datasets.