Hewlett-Packard's boardroom had a leak. That part was not unusual. What the company did about it — and what happened as a result — became a landmark case in corporate governance, privacy law, and the specific question of how far a company can legally go to find its own leaker.
The answer, as HP discovered in 2006, is considerably less far than it went.
The leak
In January 2006, CNET published an article containing details of HP's long-term corporate strategy. The information had come from somewhere inside HP's boardroom — the kind of leak that damages competitive position, signals internal instability to investors, and infuriates senior management.
Chairwoman Patricia Dunn authorized an investigation to identify the source.
The investigation
The investigation was conducted by outside private investigators under the oversight of HP's internal team. Its scope, as it later emerged, was extraordinary.
The investigators obtained phone records for nine HP board members or directors, over 20 HP employees and contractors, and nine journalists — including reporters from CNET, the New York Times, and the Wall Street Journal. They also reportedly obtained phone records for personal contacts of some journalists, including, in at least one case, a journalist's children's phone numbers.
The method was pretexting: investigators called telecommunications companies and impersonated the people whose records they wanted, posing as customers to obtain call logs. This is the practice of lying to a third party to obtain private information you are not entitled to.
The target of the investigation was eventually identified as a board member suspected of speaking to reporters. The identification came from cross-referencing phone records — calls between the board member and journalists around the time of the CNET article.
The exposure
The scandal became public in September 2006, reported initially by the Wall Street Journal. The method — pretexting to obtain phone records — became the story.
Thomas Perkins, a Silicon Valley venture capitalist who had been on the HP board, resigned in protest at the tactics. His resignation was the spark: he made clear that his departure was specifically because of how the investigation had been conducted.
Chairwoman Patricia Dunn resigned immediately after the story broke. HP CEO Mark Hurd, who had not been directly involved in the investigation, apologized publicly: "I extend my sincerest apologies to those journalists who were investigated and to everyone who was impacted."
The legal consequences
California Attorney General Bill Lockyer filed felony charges against Patricia Dunn and four other individuals involved in the investigation, alleging identity theft and fraud related to the pretexting operation. Kevin Hunsaker, HP's former ethics chief, was among those charged. Three private investigators also faced criminal charges.
The House Committee on Energy and Commerce convened a hearing on September 28, 2006, to investigate HP's practices. The session produced testimony from Dunn, Hurd, Perkins, and General Counsel Ann Baskins, among others. Dunn testified that she had authorized an external investigation but said she was unaware of the specific illegal methods used.
All felony charges were ultimately dismissed or resolved without felony conviction. Dunn's charges were dropped outright; the remaining defendants entered misdemeanor no-contest pleas and the charges against them were to be dismissed after 96 hours of community service. HP paid a separate civil settlement of approximately $14.5 million. That legal outcome did not change the broader damage: resignations at the board level, a congressional hearing, a company-wide apology from the CEO, and a lasting reputation as the case study for what corporate leak investigations are not allowed to do.
What went wrong, specifically
Pretexting — impersonating someone to obtain their private records — is illegal. The Telephone Records and Privacy Protection Act of 2006 was passed partly in response to the HP case, explicitly criminalizing the practice of obtaining phone records through false pretenses.
HP's investigation crossed from trying to identify an internal leaker into conducting covert surveillance on journalists, board members who were not themselves suspects, and private individuals with no connection to the original leak. The scope expanded beyond the original question — who told CNET — into something that resembled a broad intelligence operation conducted without legal authority.
The investigation also operated on a faulty premise: that obtaining private communications records of people outside the company was a legitimate extension of protecting internal information. It isn't. The leaker was an HP insider. Musk's reported approach at Tesla — however disputed — stayed within the company's own information and avoided this overreach entirely. The appropriate investigative universe was HP's own information management — who had access to the specific strategy discussions that appeared in the CNET article.
Same trick, in your pocket. Tell each friend a slightly different version — Gossip Finder tells you which one came back.
What Would a Canary Trap Have Looked Like?
A canary trap would have resolved the leak without any of the legal exposure. The method is straightforward: give each suspect a slightly different version of the sensitive information, then wait to see which version surfaces. No third parties, no phone records, no pretexting required. The full approach is laid out in how to find out who leaked your secret.
The boardroom leak problem HP faced was exactly the kind of situation the canary trap is designed for: a small, defined group of people had access to sensitive information, and one of them talked.
The canary trap approach: provide different versions of a sensitive strategic discussion — different figures, different timelines, different terminology — to different board subsets or individuals. Monitor which version surfaces in reporting. The version that appears in CNET's article identifies the source or narrows the suspect list significantly.
No private investigators. No phone records. No impersonation. No congressional hearing. No felony charges. No apologies from the CEO. The ethical framework for why the canary trap stays within acceptable bounds — and what takes an investigation outside them — maps directly onto what HP got wrong.
The boring version of this investigation was available. HP chose the version that required lying to phone companies and obtaining the private records of journalists' children. The boring version would have been legal, cheaper, and more likely to survive public scrutiny.
This is the lesson: the canary trap is not exciting. It is methodical and slow. It requires patience after the setup is in place. It doesn't give you phone calls, movement histories, or intercepted communications. It gives you one piece of evidence: the version of the information that leaked, matching one recipient.
That evidence is enough. It is also, unlike the HP alternative, legal.
The part about your group chat
Patricia Dunn was trying to find out who was talking to journalists. You're trying to find out who mentioned your salary to your cousin. The stakes are different. The legal constraints are the same: you cannot obtain someone else's phone records, and you don't need to.
You can set a canary trap. Plant slightly different versions of the information with each person in the circle. Wait. When the version comes back, it names the source. No pretexting required. No congressional subpoena possible. And once you have a verdict, the question of what to do with it is yours to answer — quietly, or not at all.
Gossip Finder handles the variant records. The investigation stays inside your phone and outside the legal system.
Sources
- Hewlett-Packard spying scandal — Wikipedia
- HP spying scandal: a timeline — CIO
- Dunn steps down as HP chairwoman — Al Jazeera
- Dunn resigns from HP, effective immediately — NBC News
- Attorney General Lockyer files criminal charges against former Hewlett Packard — California Attorney General press release
- Dunn pleads not guilty in HP board spy case — NBC News
- HP spying scandal — NPR transcript
Scope of use: Gossip Finder is built for your personal social life — friends and family, using information you yourself chose to share. The corporate and institutional examples on this blog are historical case studies. They are not guides for workplace monitoring, employee investigation, legal evidence gathering, surveilling a romantic partner, or accessing any device or account you don't own. For the full ethical framework, see Is It Fair to Set a Trap for a Friend?.
Privacy: Gossip Finder collects no user data. There is no server. All information stays on your device.