Attribution is the process of determining who conducted an action, with what intent, and through what means. It is the backbone of intelligence analysis and the prerequisite for response: retaliation, deterrence, diplomacy, and legal prosecution all require knowing who did what.

Attribution rests on three components: identity (who), action (what), and intent (why). Classical intelligence developed methods for each: HUMINT sources provide context on intent, SIGINT intercepts identify communicating parties, IMINT records physical evidence, and forensic analysis links material traces to known actors. Attribution is rarely certain — it is an assessment that synthesizes evidence from multiple collection disciplines into a probabilistic judgment.

The concept faces a crisis in the age of autonomous adversarial agents and synthetic ecologies, as documented in Agents of Angletonian Wilding. When adversaries can fork identities, operate without stable intent, and generate effects through emergent interaction rather than deliberate strategy, all three components of attribution collapse: identity is a shifting distribution, action fragments across systems, and intent becomes undecidable. The Stasi’s blob-first model represents a historical precursor to this crisis — a surveillance system that recognized the primacy of pattern over person and treated identity as a late-stage administrative collapse of an already-constructed analytic object.

In contemporary practice, OSINT-based attribution — exemplified by Bellingcat’s investigations — has demonstrated that open-source methods can achieve attribution results once reserved for state intelligence services, but these methods share the same fundamental vulnerability to fabrication and manipulation.

  • counterintelligence — the discipline whose failure enables false or impossible attribution
  • wilderness of mirrors — the epistemic condition that emerges when attribution becomes unreliable
  • HUMINT — the collection discipline most capable of providing intent, the hardest component of attribution