hddn Hide what matters.

Guides03 of 03

Three redaction failures worth studying

The Calipari report, the TSA screening manual, and a Manafort court filing. Different organisations, twenty years apart, the same mistake each time.

Last updated: September 16, 2026

03

The interesting thing about failed redactions is not that they happen. It’s who they happen to. These three were produced by organisations with review processes, legal teams, and every reason to get it right.

2005

The Calipari report

On 4 March 2005 US soldiers at a checkpoint near Baghdad airport fired on a car carrying the freed Italian journalist Giuliana Sgrena and two Italian intelligence officers. Nicola Calipari, the officer who had negotiated her release, was killed shielding her.

The US Army investigated and published an unclassified version of its report as a PDF in April. Names of the soldiers involved, the identity of the second SISMI agent, and detail on coalition troop movements were blacked out.

Copying the text out of the PDF and pasting it into a word processor brought all of it back. Italian journalists noticed within days. The Pentagon withdrew the file. The uncensored version had already been mirrored and is still circulating.

2009

The TSA screening manual

In December 2009 the Transportation Security Administration posted a version of its Screening Management Standard Operating Procedures to a federal contracting site. Sections marked Sensitive Security Information were covered with black rectangles.

Researchers had the underlying text out within hours. What came back included screening exemptions for certain diplomatic and intelligence personnel, and detail on physical security procedures at checkpoints. Specifics that only work as security controls while they are not public.

The TSA opened an internal review. Congress asked questions. The document, again, was already everywhere.

2019

The Manafort filing

In January 2019, lawyers for Paul Manafort filed a response to allegations that he had breached his plea agreement. Several passages were covered with black bars.

Reporters selected the text and pasted it. Behind the bars was the claim that Manafort had shared 2016 campaign polling data with Konstantin Kilimnik, and detail about a meeting between them in Madrid. It became one of the significant disclosures of that period, and it was disclosed by the filing that was supposed to withhold it.

04

The same mistake three times

Fourteen years separate the first and the last. Different sectors, different tools, different stakes. The mechanism is identical every time: someone drew an opaque shape on top of text instead of deleting the text, and the shape only exists for the eye.

Two things make this failure mode durable.

It passes every check the author can make. You look at the page, the text is not visible, so it is gone. There is no error, no warning, no visual difference at all between a real redaction and a drawn box. The document that leaks looks exactly like the document that doesn’t.

And the tools make both operations available in the same place. A rectangle is a general-purpose drawing tool that happens to be opaque. Redaction is a specific feature that removes content. On most toolbars they sit a few pixels apart, and only one of them is named in a way that tells you what it does to the file.

05

What each of these would have needed

Not better intentions. A different operation, and one verification step.

The operation: a redaction feature that deletes glyphs from the content stream, rather than a shape drawn over them. Every serious PDF application has one. It is usually separate from the drawing tools, and it usually warns that the change cannot be undone.

The verification: open the exported file, select the redacted area, copy, paste somewhere plain. If text appears, it is not redacted. The Calipari report, the TSA manual, and the Manafort filing would each have failed that test in under a minute, before anyone outside the building saw them.

That is the whole lesson, and it is annoyingly cheap. Check the file you are about to send, not the one you were editing. Twenty years of this going wrong at organisations with far more process than you have, and the fix is still a copy and a paste.

If you want the mechanical detail on why the text survives, that’s in the other guide.