After the August 9, 2014 fatal police shooting of Michael Brown, the hacktivist collective Anonymous launched 'Operation Ferguson' and on August 14 released what it claimed was the name of the officer who shot Brown. The collective identified the wrong person, and an uninvolved man received threats and harassment. Ferguson police released the actual officer's name, Darren Wilson, the following day.
What happened
On August 9, 2014, Ferguson, Missouri police officer Darren Wilson shot and killed Michael Brown. Protests began within days. The hacktivist collective Anonymous, a loose online network with no fixed membership, announced "Operation Ferguson" and started releasing what it claimed was information on the officers involved.
On August 14, 2014, Anonymous published a name and personal details for the person it identified as the shooter. The name belonged to a man with no connection to the shooting. St. Louis County Police stated the same day that he was neither a Ferguson nor a county officer. Ferguson police released the actual officer's name, Darren Wilson, the next day, August 15. The New York Times and The Washington Post covered the misidentification the same day.
The uninvolved man received threats and harassment before the correct name came out through official channels.
How it started
Anonymous ran on open participation. Anyone could join, research was crowdsourced, and volunteers pushed tips into shared channels. That produced speed, but no verification step.
The misidentification was a research mistake, not a hack. Someone pulled a name from a public source, posted it as the answer, and the network spread it before anyone confirmed it. The correction never reached everyone who had seen the original claim.
Operation Ferguson also produced separate releases aimed at St. Louis County dispatchers and other personnel. Government Technology documented the broader pattern.
Why this case matters
This is the case where vigilante doxxing hit the wrong person. An uninvolved man absorbed the threats while the actual officer's name was still being held back through internal review.
Two things went wrong. Crowdsourced doxxing rewards speed, so the first name that fit the question got amplified before anyone checked it. And the harm fell on someone who had nothing to do with the shooting.
The broader campaign
Operation Ferguson targeted more than one agency. The misidentification drew the most press, but the campaign also pushed personal information about agency leadership and their families.
On August 12, 2014, an Anonymous-linked account published the home address and phone number of St. Louis County Police Chief Jon Belmar, along with photos of his family, and threatened to release his daughter's personal information if the shooter's name was not made public. The account said it acted after Belmar publicly called the group's threats hollow. It later backed off, saying that releasing the family's information hurt the message, and did not follow through on the daughter. The Washington Post and Time covered the campaign as it happened.
The pressure still reached the chief's family, not just the officer the campaign wanted named. Family members' home addresses and photos are a common pressure point in doxxing, which is why a home address matters even when the officer is not the person being searched for.
What this means for you
For a sworn officer, the risk here is not only being the intended target. A name collision can pull you in. If your name is close to a colleague's, or a public record ties a similar name to your address, you can end up on someone else's target page for something you had no part in.
Broker sites return the address that best matches a name. They do not check who was on duty. If the closest match is yours, your home address is what a searcher gets.
The fix is the same as for any doxxing exposure. Find your address on broker and people-search sites, file removals, and keep checking when it comes back. The record that powers a misidentification is the same record that powers a targeted search. See /doxxing for the full pattern and the LulzSec Arizona DPS breach for the earlier case that set the template.
What reduces this risk
An uninvolved man took the threats here because a name was matched to the wrong person and spread before anyone checked it. Broker and people-search sites work the same way. They tie a name to a home address using voter rolls, property records, and similar sources, without confirming who the person is. A common name, or a name close to a colleague's, can surface your home address on someone else's profile. Removing your address from those sites lowers the chance that a name collision points a searcher to your door. Frontline Privacy finds those listings, files removals, and keeps checking when they come back.
Public sources
- Ferguson Case Roils Collective Called Anonymous — The New York Times, 2014-08-14
- Hackers have the names and Social Security numbers of Ferguson police, but should they share them? — The Washington Post, 2014-08-14
- How Hackers Wreaked Havoc in St. Louis County — Government Technology, 2014-09-01
- Amid Ferguson protests, hacker collective Anonymous wages cyberwar — The Washington Post, 2014-08-13
- Why Is Anonymous Involved in Ferguson? — Time, 2014-08-21