Shell’s Secret Emergency Offices, Nervous Lawyers and a Little Website Called WikiLeaks: Revisiting a Remarkable 2007 Leak

In February 2007, a Shell insider sent John Donovan details of purported secret business-continuity arrangements. Donovan removed the locations, checked the allegations with other Shell sources and asked Shell’s General Counsel whether the material was genuine. Shell’s answer was essentially: we cannot tell you. Nearly twenty years later, Shell’s own internal emails make the episode considerably more entertaining.

By John Donovan

Sometimes an old article improves with age.

On 5 February 2007, I published an article on ShellNews.net entitled Royal Dutch Shell secret contingency plans. It concerned information supplied by a Shell insider about the company’s confidential Business Continuity Managementarrangements — the plans intended to keep Shell functioning if one of its principal offices became unusable following war, terrorism or some other major emergency. (Shell News)

Reading it again almost twenty years later is rather like opening a corporate time capsule.

There is a worried whistleblower.

There are secret emergency offices.

There are allegations about employees being required to report to remote locations while worrying about their families.

There is a Shell General Counsel trying very carefully to say absolutely nothing about whether any of it is true.

There is the Donovan website receiving confidential Shell material almost in real time.

And, sitting innocently at the bottom of the article, readers interested in securely leaking information are directed towards an obscure new service.

Its name was WikiLeaks. (Shell News)

Welcome back to Shell in 2007.

The leak

The original communication came from someone identifying themselves as a Shell insider.

The source alleged that Shell had established emergency office locations away from its normal headquarters so that business could continue following a major disruption. There is nothing inherently surprising about that. Any multinational energy company would be expected to have extensive business-continuity arrangements.

The allegation was instead about how those arrangements affected employees.

According to the source, staff could be expected during an emergency to leave their families and travel to remote fallback facilities. The source claimed employees had objected and alleged that dissent had been treated sternly. (Shell News)

Those were allegations. They were not established facts.

And that distinction was recognised in the original article.

Indeed, the whistleblower’s message ended with an appeal for anonymity because of fear of losing employment. (Shell News)

So what did we do with this exciting piece of confidential information?

Publish the secret locations immediately?

Put a map on the internet?

Announce that Shell’s emergency command bunker had been discovered?

No.

We deleted the locations.

That rather spoils the caricature of reckless anti-Shell campaigners indiscriminately throwing confidential corporate information onto the internet, but history can be inconvenient like that.

First, ask some other Shell insiders

Before approaching Shell, the allegations were discussed with other Shell sources.

One provided a detailed explanation of why major oil companies required alternative operating centres and backup computer facilities. The insider described contingency arrangements involving corporate computer backups and explained the obvious strategic vulnerability of major oil-company headquarters during war or terrorist attack. (Shell News)

In other words, we didn’t simply receive an anonymous email and shout:

STOP THE PRESSES! SHELL HAS A SECRET BUNKER!

We tried to understand the subject.

Then we did something even more troublesome.

We asked Shell.

Enter Richard Wiseman

On 1 February 2007, I emailed Richard Wiseman, then Shell International’s General Counsel for M&A and Project Finance.

The purpose was explicit.

I told him it seemed proper to give Shell an opportunity to confirm or deny the information and allegations.

And because I apparently could not resist temptation even when discussing terrorism and business continuity, I added that if he supplied the appropriate Shell contact for future enquiries, I would stop bothering him.

I suggested that the prospect of no further Donovan correspondence might please him. (Shell News)

Wiseman responded remarkably quickly.

He said responsibility probably differed between locations and that he would pass the message to the appropriate people.

The following morning he came back.

He explained that circumstances activating Shell’s Business Continuity Plans could include criminal or terrorist activity directed against the company and that it would therefore be inappropriate for Shell to enter into public discussion about them. (Shell News)

Perfectly sensible.

Unfortunately, it created an entertaining problem.

“So it isn’t a hoax, then?”

I replied that I took Shell’s response to mean the information was genuine and said I intended to publish on that basis — while specifically confirming that the sensitive location information would not be disclosed. (Shell News)

Five minutes later, Wiseman was back.

Shell couldn’t say whether the information was true or not.

I tried another route.

If someone had invented the whole thing, I suggested, surely Shell could simply say it was a hoax without compromising any genuine security arrangements?

Shell declined that invitation too.

Wiseman then delivered what may be the definitive corporate-security response:

“it is sensible neither to confirm nor deny”

He specifically warned that neither I nor readers should infer anything from Shell’s refusal to comment. (Shell News)

Which left everybody in an impeccable state of enlightenment.

The whistleblower said the arrangements existed.

Other Shell insiders discussed the logic behind such arrangements.

Shell said business-continuity arrangements could involve terrorist attacks.

But Shell couldn’t say whether these arrangements existed.

And we were instructed not to conclude anything from Shell declining to tell us.

Everybody clear?

Excellent.

Shell’s position was reasonable

There is a serious point here.

Wiseman’s position was entirely defensible.

A multinational energy company should not authenticate information that could assist someone attempting to understand its emergency arrangements. Even denying individual pieces of information can, over time, enable an adversary to establish what information is accurate.

The updated version of this story therefore should not pretend that Shell’s refusal amounted to authentication.

It didn’t.

Indeed, Wiseman expressly told us not to interpret it that way. (Shell News)

What makes the correspondence interesting today is something different.

It shows how publication decisions were actually being made.

A source supplied information.

Other insiders were consulted.

Shell was approached.

Shell’s response was published.

The sensitive locations were removed.

Allegations were presented as allegations.

And readers were shown the correspondence so they could see the evidence and Shell’s response for themselves.

Not quite the image of an irresponsible internet nuisance randomly emptying Shell’s filing cabinets onto the World Wide Web.

Meanwhile, inside Shell…

And here is where twenty years of hindsight transforms the story.

We now possess Shell internal correspondence from March 2007, only weeks after the business-continuity article appeared.

A confidential Shell email dated 21 March 2007 says Shell suspected current and former employees were communicating with Donovan.

It then records something extraordinary.

An IT project had been initiated to monitor internal emails from Shell servers globally to Donovan and to monitor web traffic in order to identify internal traffic to the Donovan website. The email also noted that internal Shell emails had appeared on the site. (Royal Dutch Shell Plc .com)

So while we were wondering who inside Shell was sending us information, Shell was apparently wondering exactly the same thing.

The difference was that Shell had rather more IT infrastructure.

The website Shell couldn’t safely ignore

Another March 2007 internal record is particularly revealing.

Shell’s internal correspondence discussed identifying the Shell sources supplying information and recognised the Donovan website as a significant source of Shell-related news. Later records show continuing internal attention to the website, including legal, security, communications and online-reputation issues. (Royal Dutch Shell Plc .com)

This gives the opening paragraph of the February article a rather different flavour today.

Back then I wrote that we received a fairly constant flow of confidential Shell information and had occasionally published an internal email from CEO Jeroen van der Veer on the same day he sent it. (Shell News)

That might have sounded rather self-important in 2007.

A few weeks later, Shell’s own internal correspondence was discussing current and former employees communicating with us and monitoring global internal email and website traffic in an effort to understand what was happening. (Royal Dutch Shell Plc .com)

Apparently somebody at Shell thought the problem was real.

The wonderful asymmetry

Consider the situation.

Shell was one of the world’s largest corporations.

It had lawyers.

Security specialists.

Corporate affairs professionals.

IT departments.

Government contacts.

Global communications systems.

And an enormous international workforce.

On the other side was a website receiving emails from Shell employees.

Shell’s difficulty was obvious.

It could manage its official communications.

It could not necessarily manage what thousands of employees, former employees, contractors and other insiders decided to tell outsiders.

Once an internal email reached us, corporate communications had lost control of that particular copy.

By March 2007, Shell’s own records show it was attempting to understand the information flow. (Royal Dutch Shell Plc .com)

The irony is rather splendid.

The February article concerned Shell’s plans for maintaining business continuity when normal systems were disrupted.

At roughly the same period, Shell was confronting a completely different continuity problem:

How do you maintain information control when your own people keep emailing John Donovan?

There does not appear to have been a bunker for that.

And then there was WikiLeaks

The finest historical detail appears almost as an afterthought at the bottom of the original article.

After inviting the whistleblower to provide more information, the article suggested secure methods by which insiders might communicate.

One was AnonymousSpeech.

The other was described simply as:

“the new service for whistleblowers”

— WikiLeaks. (Shell News)

Remember the date.

5 February 2007.

WikiLeaks had only recently appeared publicly.

Nobody reading that modest little reference could have known what the name would subsequently become associated with: enormous caches of diplomatic cables, military records and classified government material, international controversy, Julian Assange and one of the defining arguments of the internet age about secrecy, journalism and leaking.

There it sits nevertheless.

At the bottom of an article about leaked Royal Dutch Shell contingency arrangements.

A tiny historical footnote with considerably more significance in hindsight.

Before WikiLeaks became WikiLeaks, Shell already had a leak problem

There is an irresistible temptation to overstate that connection, so let’s resist it.

WikiLeaks had nothing to do with the Shell business-continuity material described in the article.

The original source contacted us.

There is no evidence that WikiLeaks supplied the material or became involved in the episode.

But the reference captures the moment extraordinarily well.

Corporate leaking was changing.

An employee no longer needed to find a national newspaper journalist willing to investigate a story.

Documents could be transmitted electronically.

Specialist websites could publish them globally.

Sources could communicate anonymously.

Search engines could make obscure internal material discoverable indefinitely.

And companies were beginning to discover that controlling information after it had escaped onto the internet was very different from controlling a photocopied document circulating among journalists.

Shell’s March 2007 internal monitoring correspondence provides an unusually good contemporaneous illustration of a corporation confronting that new reality. (Royal Dutch Shell Plc .com)

Nearly twenty years later

The original article is amusing today, but I think it has aged rather well.

We did not establish that every allegation made by the anonymous insider was correct.

We still cannot establish that from the material presently available.

Richard Wiseman did not authenticate the purported details of the plan.

He expressly refused to do so.

Those qualifications matter.

But something else can now be established.

Shell really was concerned about information reaching the Donovan websites.

Shell really did suspect current and former employees of communicating with us.

And within weeks of this article, a confidential Shell communication recorded an IT project involving monitoring of internal emails to Donovan and internal web traffic to the website. (Royal Dutch Shell Plc .com)

So perhaps the most interesting leak in this updated story isn’t the one about Shell’s emergency offices at all.

It is the later leak of Shell’s own internal emails showing what Shell was doing about the leaks.

You couldn’t really make it up.

Fortunately, we don’t have to.


What the record establishes — and what it doesn’t

Established: On 1 February 2007, information purporting to describe Shell business-continuity arrangements was sent to John Donovan by a person presented as a Shell insider. Other Shell sources were consulted. Sensitive location details were withheld. Richard Wiseman was approached before publication and explained that Shell would neither confirm nor deny security-related information. The correspondence was published on 5 February 2007. (Shell News)

Also established: A confidential Shell email dated 21 March 2007 recorded Shell’s suspicion that current and former employees were communicating with Donovan and referred to an IT project monitoring internal emails from Shell servers globally to Donovan and web traffic to the Donovan website. (Royal Dutch Shell Plc .com)

Not established: Wiseman’s refusal to comment did not authenticate the leaked contingency-plan information. It does not prove that every allegation made by the source about employee safety, compulsory attendance, expenditure or treatment of dissenters was accurate.

Also not established: There is no evidence in the material examined here that WikiLeaks played any role in obtaining or publishing the business-continuity information. Its appearance in the February 2007 article was a recommendation to potential future whistleblowers.

That distinction between what the documents establish and what they merely suggest is as important now as it was then.


Postscript: Shell’s contingency plan for the internet

Perhaps Shell’s business-continuity specialists deserve the final word — or at least the final joke.

The company had apparently thought seriously about what happened if a major office became unavailable.

Backup offices.

Backup computers.

Alternative locations.

Emergency procedures.

Very sensible.

But the corporate world of 2007 was discovering another sort of disaster-recovery problem.

What happens when confidential information leaves the building but the information itself remains perfectly operational?

It can be copied.

Forwarded.

Published.

Indexed.

Archived.

Rediscovered twenty years later.

And sometimes the documents eventually escaping from the corporation include the corporation’s own confidential discussion about how to stop documents escaping from the corporation.

That is a business-continuity problem of almost philosophical perfection.

Shell apparently had fallback arrangements for its offices.

Unfortunately, there was no fallback arrangement for the internet.

And there still isn’t.

Site wide disclaimer applies.

*This website and sisters royaldutchshellgroup.com, shellnazihistory.com, royaldutchshell.website, johndonovan.website, shellnews.net, and shellwikipedia.com, are owned by John Donovan - more information here. There is also a Wikipedia segment, the Shell DPA Files, "Shell and the Spies", the Shell Leaks files, as well as books written and published by John Donovan - Kindle eBooks. Timeline of the Donovan Shell Feud. Toxic History of Royal Dutch Shell Group. Shell and the Donovans: The Full Media Record — 550+ Articles, 110 Books, 40 Years. *All created and supported by internet wizz, Nick Gill.

Comments are closed.