CACrown ArchivesThe cinema collection
Menu
Research dossier · General Reference

2016–2021 literary phishing thefts

ongoing international crime incident

Cross-disciplinary reference desk with index cards, atlas, dictionary and catalogue
General referenceInterpretive dossier study · Crown Archives visual atlas
Record originEnglish Wikipedia
Text licenseCC BY-SA 4.0
Source revisionJun 26, 2026
Entity authorityQ110443243 ↗
Source-derived summary

Between 2016 and 2021, multiple prepublication manuscripts were stolen via a phishing scheme that investigators believed were conducted by an industry insider or insiders. In 2022, the FBI arrested Filippo Bernardini, a 29-year-old Italian citizen living in London and working for Simon & Schuster.

Background

Piracy in the publishing industry can have a negative impact on profits and royalties, and some industry professionals take extreme precautions with highly-anticipated releases. Translators for some books in The Da Vinci Code series were reported by Vulture to have been "required to work in a basement with security guards clocking trips to the bathroom".

Phishing attempts

In 2016, individuals involved in the publishing industry as authors, editors, agents, and publishers reported successful attempts to coerce authors into emailing unpublished manuscripts to email addresses impersonating publishing professionals known to those authors. The attempts were made by emailing from a domain name that resembled a legitimate one; the domain names were created using "common phishing techniques" such as using the letters "rn" to mimic the look of the letter "m" in an organizational name such as Macmillan, instead spelling it Macrnillan. The emails ostensibly came from other publishing industry professionals who worked closely with the target on the manuscript in question. In 2020, a cybersecurity firm found that the thief or thieves had registered over 300 domain names, and that their own security measures were amateurish. Some of the domains may have been paid for with stolen credit cards, according to Vulture.

Many of the phishing attempts involved approaching multiple people involved in a particular book's release; in the case of The Girl Who Takes an Eye for an Eye, the phisher, impersonating the book's Italian translator, emailed the book's publisher and the author's agent within minutes of each other.

Editorial summary

The public source identifies “2016–2021 literary phishing thefts” as ongoing international crime incident. This brief keeps that definition visible, then builds a research path around literary, phishing and thefts.

Editorial reviewA concise reference frame for defining the subject, testing terminology and identifying the institution closest to the evidence. The current lead gives the account dated anchors—2016, 2021, 2022, 2020—that can be checked directly. The selected authority fields contribute no independent date. Its value is orientation rather than verdict, with literary, phishing and thefts providing the first useful test.
Editorial analysis

Why this record matters

A short description can identify a subject without explaining its stakes. For “2016–2021 literary phishing thefts”, the useful work is to connect “ongoing international crime incident” to the records capable of establishing context and consequence.

Evidence profile

Vocabulary and entity names are the principal evidence signals here, because they determine the precision of every later search. The source revision retrieved here is dated Jun 26, 2026. The linked authority identifier is Q110443243. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2016, 2021, 2022 and 2020.

Critical limits

Overview language is designed for orientation and should not be treated as a substitute for the evidence cited beneath it. The source lead contains qualifying language; that uncertainty should survive quotation, summary and reuse. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.

How to read it

Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.

Best used for
  • Subject orientation
  • Search vocabulary
  • Locating named sources
Verify next

The closest primary source, responsible institution and strongest cited specialist reference.

Three-step research path

  1. Establish the record: confirm the title “2016–2021 literary phishing thefts”, its source revision and the description used here.
  2. Expand the search: follow 2016–2021 literary phishing thefts primary sources, 2016–2021 literary phishing thefts archive and literary research across catalogues and specialist indexes.
  3. Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.

Questions for further research

  1. Which source most directly establishes the central claim about “2016–2021 literary phishing thefts”?
  2. Which cited source is closest to the event, object or claim?
  3. Which institution is responsible for the underlying evidence?
Subject index

Search terms from this dossier

Source & attribution

This entry incorporates text from “2016–2021 literary phishing thefts” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.