Press "Enter" to skip to content

“Hacker X”—the American who built a pro-Trump fake news empire—unmasks himself


Aurich Lawson | Getty Images

This is the story of the mastermind behind one of the largest “fake news” operations in the US.

For two years, he ran websites and Facebook groups that spread bogus stories, conspiracy theories, and propaganda. Under him was a dedicated team of writers and editors paid to produce deceptive content—from outright hoaxes to political propaganda—with the supreme goal of tipping the 2016 election to Donald Trump.

Through extensive efforts, he built a secret network of self-reinforcing sites from the ground up. He devised a strategy that got prominent personalities—including Trump—to retweet misleading claims to their followers. And he fooled unwary American citizens, including the hacker’s own father, into regarding fake news sources more highly than the mainstream media.

Pundits and governments just might have given Russia too much credit, he says, when a whole system of manipulating people’s perception and psychology was engineered and operated from within the US.

“Russia played such a minor role that they weren’t even a blip on the radar,” the hacker told me recently. “This was normal for politicians, though… if you say a lie enough times, everyone will believe it.”

Previously dubbed “Hacker X,” he’s now ready to reveal who he is—and how he did it.

A note on sourcing: In a rigorous effort to fact-check the claims made here, Ars has seen written correspondence between the hacker and notable entities involved in producing fake news; emails sent to him by prominent personalities publicly known to own (or be associated with) fake news sites; tax forms showing income received by him from fake-news generation companies; receipts for IT asset purchases, such as domain names; emails from him to staff explaining strategy and assigning them tasks on a regular basis; and archived copies of webpages, forums, and tweets produced as a part of this large operation. We have also communicated with sources, both named and unnamed, some of whom are “writers” who worked at the same company and have corroborated the hacker’s claims.

Because he requests that the company he worked for not be explicitly named, Ars has referred to the fake news company with… a fake name, Koala Media.

The samurai

The fake new impresario who has now decided to break his silence is “ethical hacker” Robert Willis.

Some in the information security community might know “Rob” today as an active member who speaks at conferences and works with the Sakura Samurai ethical hacking group. (The Sakura Samurai have, on many occasions, responsibly disclosed vulnerabilities in the computer systems of government and private entities. I have previously interacted with Rob on about two occasions, minimally, when I had questions regarding Sakura Samurai’s vulnerability writeups.)

But back in 2015, Willis was just another hacker looking for an IT job. He had already received one job offer—but still had an interview scheduled at one final company.

“I was thinking of not showing up to the interview,” he told me. “I had, after all, just committed to another company.”

That final company was opaque—it would not reveal either its name or the actual job duties until Willis showed up in person. But the opacity was itself intriguing. Willis decided to do the interview.

Enlarge / What does a content farm look like? It’s not glamorous. This is the Koala office.
Robert Willis
Enlarge / The lobby of Koala’s building.
Robert Willis

Cancer-curing lemons

The owners of Koala Media reeled in good money at the time. Koala’s main site covered “health” topics and hawked supplements and alternative cures. A tiny front-page ad would bring in $30,000 a month, Willis tells me, with mailing lists enriching the Koala Media empire further.

“Getting highly targeted individuals to sign up was huge for financial gain,” he said. “[Koala] would advertise products directly to individuals and sell thousands of them at a time.”

Emails were sent out twice a week, one promoting a sale and the other some new product. Additionally, affiliate links and virtual event promotions garnered further income in the “hundreds of thousands of dollars” range for a single opportunity.

But as Willis came on board, Koala’s stories got more controversial.

A former Koala Media writer who has worked with Willis told Ars, “In the beginning, the job was fine, writing regular AP-style news articles. Then, it went toward goofy stuff, like ‘lemon curing cancer.’ And eventually, it went to super-inaccurate stuff.” That is when the writer knew it was time to call it quits. But Willis stayed on, even as one of the site owners personally contributed content that made him uncomfortable.

“That was the problem,” Willis told me. “We were trying to build a more legitimate network and were reaching more and more millions weekly, but then the owner—who contributed a story once a day, during the best time for reach—would write crazy stuff.

“What saved me was a couple [of Koala Media] employees,” he added. “One came into my office and closed the door and looked at me and said, ‘You don’t actually believe this stuff, do you?’ and I let out a sigh of relief when I said, ‘God, no’—and laughed. It became an ongoing joke.”

Enlarge / Rob Willis.
Robert Willis

From that moment onward, the hacker and office staff would joke about the stuff they were being assigned to write—like a conspiracy-laden writeup on “chemtrails” or a piece on “lemons curing cancer”—thinking that only a small “ultracrazy” percentage of readers actually believed what was being written.

Just came in:  This Is What Might Happen if the US Defaults on Debt

The ring

Toward the end of 2015, more and more pro-Trump stories started emerging on Koala. But after Trump won the Republican primary in 2016, the focus shifted heavily toward anti-Clinton stories. During this time, Koala’s already-loose editorial standards relaxed even further. Stories became increasingly bizarre or opinionated. Citations that did exist were often placed in a misleading manner, misconstruing the linked stories or pointing to existing stories in the Koala webring, making it hard for readers to fact-check the material. The “search bar” on these news sites even took users to a search engine created by Koala; it showed stories from “independent media,” i.e., sites from the webring. Pieces that ran during this crucial period claimed, among other things, that Clinton had plans to “criminalize” gun owners, to kill the free press, to forcefully “drug” conservatives, to vaccinate people against their wills, to euthanize some adults, and to ban the US flag.

Yet Facebook, which directed plenty of traffic to Koala, never cut the site off. In the two years of the operation that Willis oversaw, Facebook banned only one of Koala’s posts, Willis said.

Through it all, Willis did what he was hired to do: he put his technical skills in the service of boosting Koala’s reach—by any means possible.

The basic approach involved the creation of a massive syndication network of hundreds of specialty “news” websites, where articles from the main Koala website could be linked to or syndicated. But these additional websites were engineered so that they looked independent of each other. They were “a web ring where the websites didn’t look like they had any real associations with each other from a technical standpoint and couldn’t be traced,” said Willis.

Each fake news website was on a separate server and had a unique IP address. Each day’s stories were syndicated out to the fake news sites through a multistep sync operation involving “multiple VPNs” with “multiple layers of security.” Eventually, each public-facing fake news site received its daily content payload, and the stories would go live at scheduled times. In addition to Americans, Willis’ team also comprised outsourced web developers working from Mexico, Eastern Europe, South Africa, and Taiwan.

“I oversaw everything and even had stacks of SIM cards purchased with cash to activate different sites on Facebook since it was needed at that point in time,” admitted Willis. “Every website had a fake identity I made up. I had them in a sheet where I put the name, address, and the SIM card phone number. When I accessed their account I created on Facebook, I would VPN into the city I put them in as living in. Everything attached to a website followed these procedures because you needed to have a ‘real’ person to create a Facebook page for the websites. We wanted no attachment, no trace of the original source. If anyone were to investigate who owned a page, they would be investigating a fake person.”

Eventually, carriers started asking for Social Security numbers (SSNs) prior to issuing and activating SIM cards. But “they took anything resembling an SSN, even ones generated from dead people,” Willis said. As a test, Willis once provided Elvis Presley’s SSN, which he had found on Google Images. The number worked.

Independent studies, seen by Ars, have confirmed that in 2015, shortly after Willis had started at Koala, hundreds of fake news domains sprang up. A British think tank has also linked this network of hundreds of domains to Koala Media.

Enlarge / Just another day at the office… brainstorming Facebook group names.
Robert Willis

The schedule

After carefully studying the Facebook pages maintained by Koala staff, which were reaching about 3 million people weekly, Willis began using information-warfare tactics, some inspired by young Macedonians. Willis studied the connection between Koala headlines and the emotions they triggered among readers. The next time Koala Media’s owners came into the office, Willis showed them a carefully outlined posting schedule.

“I surprised them by holding up a large poster board with what became the schedule and deep explanations from a psychological standpoint on what articles to put at what times,” he said. “Early morning was positive articles—people will interact with positive things when they first wake up, they had the big story of the day at 11 am already, which they previously noticed was the most powerful slot of the day, afternoon prior to 2 pm was articles to really push hard, late night (11 pm to the early morning) was fringe content.”

These claims have been corroborated to Ars by former Koala Media staff who prefer to remain anonymous.

The new publishing strategy, along with the additional fake news sites, caused a rapid spike in traffic. As Willis puts it, this all felt “like playing a video game and getting new high scores to me. I did not think of the readers as people but more like background characters in a video game. I am neurodiverse and have major issues with understanding empathy due to my condition. Crunching numbers is something I love to do; these were numbers I wanted to go up, and I would do it with no emotional attachment to the material or people.”

Soon enough, Koala’s published “news” pieces reached over 30 million people a week.

“I was completely caught off guard while pushing nonstop Trump news through the election cycle,” said Willis. “One of our websites was the No. 1 Google search result for the term ‘Trump News’!”

Just came in:  New trailers: King Richard, Uncharted, Ozark, and more

At one point, then-candidate Trump himself retweeted a shout-out from the Twitter account “@debateless.” The account was set up by Willis for his personal BloodyRubbish.com blog, as confirmed by Ars.

Enlarge / Trump retweeting “debateless” account managed by Willis.
Enlarge / Rob Willis also managed BloodyRubbish.com.

The results of the 2016 election left Willis and his team in shock.

“The shock was around the power of the machine”

Willis and his army of fake news editors knew that millions of Americans targeted by their pro-Trump and anti-Clinton propaganda were real people who actually showed up to vote. “There were other pro-Trump news organizations,” Willis told me, “but nothing was built [as] extreme as ours. We had without a doubt contributed to Donald Trump winning the presidency.”

Countless studies, including one from Stanford, attempted to pin the election outcome on fake news. Ars has seen the news articles produced by Willis’ operation but cannot disclose these, as doing so would divulge the Koala website.

By the end, Willis was hoping that he and his team would be caught, that someone would be able to connect the dots. But it didn’t quite happen.

By 2017, after being with the fake news farm for nearly two years, Willis couldn’t take it anymore. “I had a soul-searching moment and money in the bank and decided what I liked doing most was hacking, and I wanted to get back to it. So I decided to get a job in the security industry as a hacker,” he said.

He knew he should talk about the system he had helped to build. “I helped contribute to the monster of fake news,” he said. “I knew I had a responsibility to be a whistleblower on what exactly went down—even though the network I helped build looks like a shell of its former self, especially after they’ve been banned from basically every platform, along with other ‘alternative’ news outlets.”

But back then, Willis wasn’t yet ready to be named. He confessed to a trusted friend, podcast producer Matt Stephenson, what he had done.

In a Zoom call, Stephenson told me that, as a podcast producer, he is constantly looking for ways to expand his network and frequently travels to attend social events like conferences. It was at the interactive media and film festival South by Southwest (SXSW) in March 2018 that Stephenson first met Willis. Over a period of time, the two became well acquainted. When Willis confessed to Stephenson the details of the operation and stressed that he needed the truth to come out, Stephenson agreed to act as his “handler.”

Enlarge / Stephenson and Willis at a marketing event in San Francisco, April 2018.
Robert Willis

Around that time, former White House chief information officer and renowned cybersecurity expert Theresa Payton was working on her book Manipulated. She was seeking sources who were either the victims of misinformation campaigns or “manipulators” involved in fake news production. Payton was already one of Stephenson’s connections, and Stephenson put Payton and Willis in touch.

But Payton did not know Willis’ real name—referring to him only as “Hacker X” in her book. In the beginning, Payton and “Hacker X” would communicate over Zoom calls with the latter’s video turned off. In June 2019, though, the trio met in Austin, Texas. Even then, on meeting “Hacker X” and Stephenson in person, Payton did not know Willis’ real name—although Willis did reveal his face. The detailed account of the rendezvous is shared in Payton’s book.

One interesting detail that caught my eye in the book was that Payton had no trouble guessing how “Hacker X” might look months before they had even met:

Without ever laying eyes on him—as his video was turned off during our first interview—I ask if he would let me guess what he looks like. He laughs heartily, thinking I’ll never guess correctly. Based on our two hours speaking and my profiling skills, I hazard a guess. “You’re a five-ten to six-foot twentysomething male. Earnest-looking face, perhaps—someone who could be in a J. Crew or Brooks Brothers ad or lacrosse-team picture of an Ivy League school.”

I wait.

“Wow!” his handler says. “That description was stunningly accurate.”

In the same book, “Benefactors” is a catch-all phrase used by Payton to describe Koala Media owners. The chapter titled “Anatomy of a Manipulation Campaign” goes over the Benefactors’ intentions:

Hacker X tells me that the Benefactors wanted to initiate a massive manipulation campaign with three goals: “run an online news campaign that would net them a lot of money, make sure they did not get caught, and not let the deep state get Hillary elected.” The Benefactors had admired the Obama campaign and its ability to mobilize and energize voters through social media to gather, donate, and get the word out. They told him they had heard Hacker X was the best at building algorithms that could target the right message to the right people—and at hiding his tracks; they wanted to keep this operation and his existence covert. They wanted him to build this operation from the ground up, with security and privacy in mind. “I’m sitting at a table with them, and they say to me, ‘Don’t you want to be part of something big? You can help us make sure the country picks the right person for the next president. Are you up for the challenge?’ And I said, ‘Heck, yeah—I’m ready!” Hacker X quietly adds, “I gave up almost two years of my life serving the cause.” Not once does he mention anything about “moral values.” I have no idea if Hacker X is religious; he never says anything racial, bigoted, anti-immigrant, or antigay.

He does demonstrate a deep dislike for the “elites” and for Hillary Clinton, repeatedly using the phrase “destroy Hillary”; otherwise, he seems to generally love his fellow Americans and all walks of life.

Payton’s book was published in the spring of 2020, a time when humanity’s focus was on fighting the coronavirus pandemic. With so much devastation all around, unmasking “Hacker X” wasn’t on anyone’s radar.

Just came in:  Estimated ship times for preorders of new MacBook Pro models now into late November, early December

But Willis is now ready to be named.

Enlarge / Willis giving a speech.
Robert Willis

The motive

Despite all the evidence presented by Willis, and despite the multiple sources who helped me corroborate the story, the skeptic in me couldn’t help but wonder: what were Willis’ true motives while all this was happening? What were they now? And what would “whistleblowing” achieve years after the 2016 election—and without naming the news empire he ran?

To ditch a job offer Willis had already accepted, diving instead into the murky waters of an elusive antiestablishment “media company,” raised questions. Was it just the thrill of exploring the unknown and having found a place where his hacker mindset could be applied to its fullest potential? Or did Willis see some higher purpose in denouncing the political “establishment”?

Willis admits the decision to join Koala Media was at least partially motivated by political revenge, but based on my understanding from people who have known Willis, he isn’t actually “right wing.” Willis isn’t a Democrat or even a proper Republican, his handler Stephenson tells me. He’s just antiestablishment. Willis’ self-proclaimed title—”original punk rock right-wing millennial”—aptly describes his ideology.

Sources also told Ars that Koala Media owners realized the massive potential for financial gain in pushing out the pro-Trump and anti-Clinton rhetoric after analyzing Trump’s voter base and their emotional reactions to the fake news articles all adding to traffic. Had Clinton’s voter base earned them more money, the pro-Clinton narrative might have been their focus, claim the sources.

Was Willis the same way? Did he do it for the money?

Born in Stamford, Connecticut, Willis was raised by his mother and her family, who had immigrated to the United States from Italy. “My father was around, but I didn’t know his family,” Willis told Ars.

The hacker says that he comes from a place of poverty, though as a child he was never aware of it. “I had a unique upbringing; I was poor but didn’t know it when I was young,” he said. “I remember that I wasn’t allowed to cross the street since my neighbors were crackheads. I grew up around the gay community from a young age with gay relatives. My schoolmates and friends were very diverse since I was just outside New York City. I was always very open-minded and accepting of everyone. I was the only white kid on my bus. I grew up as diverse as one could imagine.”

In a conversation with Ars, the hacker recounted an episode from his childhood where his younger brother got attacked over food stamps on their school bus, and he described a nomadic life deprived of the basics.

“I built my first computer using parts from computers found at the city dump,” he said. But it was getting involved with technology that helped Willis out of a life of poverty.

“By the time I was in my 20s I had moved over 30 times—very much a nomad, always used to moving but within the same general areas. I put myself through school with the help of government aid, taking many years, struggled very hard, because of no support system. Once government aid ran out, I paid upfront for classes before taking loans for my bachelor’s degree.”

But poverty isn’t what fueled his journey into the secretive Koala empire. Rather, what seemed like a “fun-sounding job” came his way years after he had already left Connecticut and a life of poverty behind.

As for naming himself, if he didn’t do it in Payton’s book, why come out now? After having interviewed Willis several times, Payton believes the hacker just wants to do the right thing. According to her, Willis is an “idealist” and wants people to know the truth. Recounting her meeting with Willis and Stephenson, she tells me, “I saw that in front of my own eyes… He is superimpressed with himself that he got away with it. But he felt disgusted that he got away with it.”

“He has remorse for what he did. I feel protective about him,” stressed Payton. “Not that he needs protecting… but he wants to right the wrongs that he believes he was a part of.”

Willis’ decision to reveal his identity now, he told me, is fueled by the continuing damage that he sees from fake news stories about COVID, especially those spreading anti-vaccination propaganda.

“The new war is to wake up those who have been manipulated, while actively taking out the fake news campaigns,” writes Willis in a blog post. “COVID has shown me the deadly side of fake news and anti-vaccination people. After multiple conversations with my father, who refuses to wear a mask or get vaccinated, I was getting very concerned. I asked him what sites he would read the conspiracy-based things on, and he mentioned the website that ran the network I had built the machine on.”

Prior to approaching me, Willis had disclosed his history with fake news farms to his family, hoping to undo the brainwashing done by these websites. Unfortunately, it was too late. To this day, Willis’ father does not believe the hacker’s story, Willis said, adding, “He has been too manipulated.”

Source