John Scott-Railton Profile picture
Jan 27, 2021 16 tweets 14 min read Read on X
MUST WATCH: investigation by @WSJ shows 100+ Proud Boys coordinating, instigating and leading key elements of the #Capitol breach

Proud Boy 1: "Lets take the f* ** capitol"
Proud Boy 2: "Lets not F*** yell that alright"...

Etc.

wsj.com/video/video-in…
2/ The investigation walks through the footage (props to @WSJ, there's so much!) starting with Proud Boys staging under the direction of leaders including (now-arrested) Joe Biggs outside the #Capitol ImageImageImage
3/ In the staging area, a Proud Boy identified as Dan Scott aka 'Milkshake' yells "lets take the f***ng capitol"
-Milkshake is admonished by another PB.
-Someone makes fun of 'Milkshake' for the indiscretion(?). Some laughter.
-"Don't yell it, do it" says another, quietly. ImageImageImageImage
4/ The @WSJ places key Proud Boys from pre-breach meet-ups as instigators of later violence and activity by the crowd.

This absolutely matches what many of us have observed... ImageImage
5/ Breach begins: @WSJ finds Proud Boys leader Joe Biggs in the crowd at an outer police cordon, communicating with a man in a red hat.

Minutes later, red hat man is the 1st past the breached police line. ImageImageImage
6/ As the first police line goes down we see multiple identifiable Proud Boys at the front. @WSJ names Michael Porter, for example.

Note the orange tape on helmets. This is an identification sign that many of us observed Proud Boys using throughout the day. Image
7/ Proud Boys stay at the front of the rush of people, squaring off as they encounter #Capitol Police at the West Entrance. The @WSJ spots Proud Boy #Spazzo.

Remember him? He was the earpiece-wearing window breacher. ImageImage
@WSJ 7/ Zen sidebar on window-breacher Dominic ‘Spazzo’ Pezzola: his lawyer claimed to the @WSJ that his radio earpiece was "for listening to music" Image
8/ A Proud Boy exhorts the crowd gathering in front of the police line at base of Capitol:

"Do you want your house back?... Take it!"

Note the orange tape. Also, here's now-arrested Robert Gieswein.

Details on how some of us originally ID'd him here👇 ImageImage
9/ After staying in the front of the melee w/police... some Proud Boys flank the officers and join a group fighting their way up the left side, through scaffolding and stairs.

Dominic ‘Spazzo’ Pezzola & Gieswein are spotted. Gieswein sprays something at officers... ImageImage
10/ Its 2:12 pm. Now up the stairs and against the building Dominic ‘Spazzo’ Pezzola uses a police shield to breach the window, then steps back and lets others including Gieswein inside accompanied by cries of "Go go go!" Then joins them. ImageImage
11/ The breaching party is inside. Men including Gieswein & Spazzo encounter, then chase officer Eugene Goodman up the stairs..

They come incredibly close to the undefended lawmakers in the Senate (door highlighted in blue). Thankfully, Goodman distracts them. ImageImage
12/ Proud Boys leader Joe Biggs isn't far behind.

"This is awesome"

Pic right: Biggs has told @DailyMail he
- only went into the #Capitol to find a bathroom
- no planned storming...
- he actually meant "awe-inspiring" & also "awful"

SMH.

Source: dailymail.co.uk/news/article-9… ImageImage
13/ Shortly after, and now back outside, the main police line is breached. Other Proud Boys make it into #Capitol with this larger group. One takes this selfie.

Another roams halls calling out for @SpeakerPelosi to "come out and play" His lawyer says "comments were in jest" ImageImageImage
14/ The @WSJ piece is an excellent, damming illustration of what many of us observed: Proud Boys played a key role at the #Capitol.

Congrats to the team that assembled it & their colleagues that helped out.

Why I'm a @WSJ subscriber. Subscribe here: subscribe.wsj.com
15/ Coda: Robert Gieswein wore several patches, including Woodland Wild Dogs (his own thing), & has some militia connections.

However, remains unclear (to me) whether his co-presence w/Proud Boys around #Capitol points a longer-term relationship.

Image

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with John Scott-Railton

John Scott-Railton Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @jsrailton

Oct 23
NEW: Ex exec at premier private cyber weapons contractor to US accused of selling eight trade secrets to buyer in Russia.

I think this = exploits.

Very bad: at minimum would give adversaries a blueprint for detecting the tip of the spear of US/Allied cyber ops..

Wild story 1/Image
Image
2/ A watch collection studded with fake rolexes...

...is allegedly part of Peter "doogie" Williams haul from selling the hacking labs' secrets.

documentcloud.org/documents/2619…Image
3/ While doogie's watch collection is a joke, the questions couldn't be more serious:

Were cyberweapons paid for by American taxpayers also turned against us?

Were service members, officials, or civilians at physical risk? When was this breach first suspected? Who knew what? When?Image
Read 9 tweets
Oct 22
WARNING: seeing a lot of phishing against @Signal users.

Did you get a message like this?

Don't engage! It's an attempt to steal your account.

Your account is safe & chats are private, but you should use Signal's option to Report Spam & Block. 1/Image
2/ You can make the attackers life harder by clicking Report.

Background: Like any popular secure messaging app, Signal users sometimes get targeted by spam & phishing attempts.

Often, attackers guess large numbers of usernames / phone numbers & send out message requests...Image
3/ Take a minute to remind yourself how message requests & blocking work on @Signal.

FAQ: support.signal.org/hc/en-us/artic…Image
Image
Read 4 tweets
Oct 21
A "damaging" leak of tools from a five eyes exploit developer?

Concerning. We need to know what's under this rug.

Big picture: "trusted, vetted" private sector players offensive cyber are not immune to losing control of tooling... with national security consequences 1/
2/ If true, a tooling leak at boutique firm Trenchant wouldn't be the first time that exploits from commercial offensive vendors wind up... in the wrong place.

Many questions.

In the meantime. Remember when Russian APT29..was caught with exploits first used by NSO & Intellexa? Image
Image
3/ There will always be a push for states to turn towards the private sector to meet offensive needs.

It's appealing. For some, it's very lucrative.

But in practice it brings unavoidable counterintelligence & national security downside risk that shouldn't be downplayed.
Read 11 tweets
Oct 17
NOW: US court permanently bans Pegasus spyware maker from hacking WhatsApp.

NSO Group can't help their customers hack @WhatsApp, etc ether. Must delete exploits...

Bad news for NSO. Huge competitive disadvantage for the notorious company.

Big additional win for WhatsApp 1 /Image
Image
Image
Image
2/ Although the massive punitive damages jury award against NSO Group ($167m) got reduced by the court, as is expected in cases where it is so large (to 9x compensatory damages)...

This is likely cold comfort to NSO since I think the injunction is going to have a huge impact on the value of NSO's spyware product.

Comes as NSO Group has been making noises about getting acquired by a US investor & some unnamed backers...Image
Image
3/ NSO also emerges from the @WhatsApp v NSO case with just an absolute TON of their business splashed all over the court records..

E.g. check out the filings from Sept 15th 2025: courtlistener.com/docket/1639534…
Read 5 tweets
Oct 10
WOW: @Apple donating a thousand new #iPhone17 s to civil society at-risk from mercenary spyware.

Good. This will help get Apple's most secure devices to where they need to be..

Truth is: those at the greatest risk from spyware are often least able to afford more secure phones 1/Image
2/ Memory Integrity Enforcement = big deal Radically hardens iPhones from common attack vectors.

So it was a bittersweet to see this announcement and think "yeah it's going to be a long time before highest risk ppl can get them."..
3/ You're reading this on a device that is probably more secure thanks to the vigilance of an activist somewhere...

Seems @Apple recognizes this & also knows how much of a game changer getting their most secure devices into the hands of civil society could be.

security.apple.com/blog/apple-sec…
Read 4 tweets
Oct 10
NEW: fresh trouble for mercenary spyware companies like NSO Group.

@Apple launching substantial bounties on the zero-click exploits that feed the supply chain behind products like Pegasus & Paragon's Graphite.

With bonuses, exploit developers can hit $5 million payouts. 1/Image
Image
2/ Apple is introducing Target Flags which speeds the process of getting exploits found & submitters rewarded.

This faster tempo is also a strike against the mercenary spyware ecosystem.

And the expanded categories also hit more widely against commercial surveillance vendors. Image
3/ If I contemplating investing in spyware companies I'd want to carefully evaluate whether their exploit pipeline can match what @apple just threw down.

security.apple.com/blog/apple-sec…
Read 4 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(