Famous PDF redaction failures — and the 30-second check that prevents them

Every few months, a 'redacted' document makes the news for the wrong reason: someone drew black boxes over sensitive text, published the file, and a reader simply copied the text out from underneath. The names, the numbers, the settlement figures — all still in the file, just hidden from the eye and nothing else.

It keeps happening to sophisticated organizations because the mistake is invisible: the document looks redacted. This guide explains why the failure recurs, the pattern behind the well-known cases, and a 30-second verification anyone can run before a redacted PDF leaves their hands.

Step by step

  1. 1
    The select-all test

    Open the redacted PDF, press Ctrl/Cmd-A to select everything, copy it, and paste into a plain text editor. If any text you meant to redact appears, the redaction failed — the black box is only a picture drawn on top of live text.

  2. 2
    The search test

    Use the PDF viewer's Find (Ctrl/Cmd-F) and search for a term you redacted — a name, a number. Zero results means it's gone from the content layer. Any hit means it's still in the file.

  3. 3
    The metadata check

    Open the document's Properties/Details. Author, title, and edit history can carry the very identities you redacted from the body — and some PDFs embed earlier revisions. Clean metadata is part of a real redaction.

Why the same mistake keeps happening

Almost every public redaction failure shares one root cause: the tool drew a shape over the text instead of removing the text. A black rectangle is an annotation — a graphic layered on top. The words underneath are untouched, so select-all, copy-paste, search, and text extraction all still reveal them.

The second most common cause is metadata: the body is genuinely redacted, but the author name, document title, or an embedded prior version still names the person the redaction was meant to protect.

Both failures look identical to a correct redaction on screen. That's exactly why they slip through review — and why a mechanical check beats a visual one.

The famous failures, case by case

2005 — the Calipari report. The U.S. military published its investigation into the shooting of Italian intelligence officer Nicola Calipari as a redacted PDF. The blacked-out passages — classified operational details and names — could be recovered with select-all and copy-paste. The incident prompted the NSA to publish official guidance that same year warning that drawing black boxes over text does not remove it.

2009 — the TSA screening manual. The TSA posted its airport Standard Operating Procedures to a federal contracting website with the sensitive parts covered by black boxes. The boxes were trivially removable, exposing screening secrets — including sample law-enforcement credentials and the fact that only a fraction of checked bags were hand-searched. Congress opened an inquiry.

2011 — the UK nuclear submarine report. Responding to a freedom-of-information request, the Ministry of Defence published a report on Royal Navy submarine safety in which the 'redacted' text had simply been set on a black background. Copy-paste revealed assessments of how a structural failure could lead to a reactor meltdown aboard a nuclear submarine.

2019 — the Manafort filing. Paul Manafort's own defense lawyers filed a court document with black-box redactions over live text. Reporters pasted the contents into a text editor within minutes, revealing that Manafort had shared 2016 presidential campaign polling data with Konstantin Kilimnik — one of the biggest stories of the Mueller investigation, published by the defense itself.

2020 — the Maxwell deposition. This one is the cautionary counterexample: the redacted text really was removed. But the released transcript kept its alphabetized index, and Slate journalists used each redacted entry's position between known words to reconstruct the hidden names — including Bill Clinton, Alan Dershowitz, and Prince Andrew — within hours. Redaction isn't just removing the words; it's removing every path back to them.

Different institutions, fifteen years apart, same result: covered is not removed. The lesson isn't 'those people were careless.' It's that overlay-style redaction is a trap that produces a convincing-looking result while leaving the data intact. If your workflow can draw a box without destroying what's under it, you are one distracted afternoon away from the same headline.

How to redact so this can't happen to you

Use a tool that removes the underlying text and image data from each redacted region — not one that draws over it — and then run the three checks above before you share the file.

PDF Redactly destroys the underlying data inside every redacted region (copy-paste and search reveal nothing), strips metadata, and does it entirely in your browser, so the document is never uploaded in the first place. But whatever tool you use, run the select-all, search, and metadata checks: 30 seconds of verification has prevented every failure on this list.

FAQ

What are famous examples of PDF redaction failures?

The 2005 U.S. military Calipari report, the 2009 TSA screening manual, the UK Ministry of Defence's 2011 nuclear-submarine safety report, and the 2019 Manafort court filing all shipped with black boxes over recoverable text. The 2020 Ghislaine Maxwell deposition failed differently: the text was removed, but the transcript's alphabetized index let journalists reconstruct the hidden names.

Why do redacted PDFs still contain the hidden text?

Because most 'redaction' just draws a black box over the text instead of deleting it. The box is a graphic on top; the words underneath stay in the file and are revealed by copy-paste, search, or text extraction. Real redaction removes the underlying data.

How do I check if my redaction actually worked?

Three fast checks: select-all and paste into a text editor (redacted text must not appear), search the PDF for a redacted term (must return nothing), and inspect the document properties for names in the metadata.

Does covering text with a black rectangle redact it?

No. A black rectangle is an overlay — the text under it is intact and recoverable. You must remove the underlying text and image data, which is what true redaction does.

How does PDF Redactly prevent these failures?

It destroys the underlying text and image data in each redacted region rather than covering it, strips metadata, and runs entirely in your browser so the file is never uploaded. You can still verify the result with the select-all and search tests.

Redact your PDF without uploading it

Free, in your browser, with automatic detection. Your file never leaves your device.

Open the redactor
Related guides