Elections Alberta has identified the source of a leak from its electoral list by using a canary trap — bogus voter entries seeded into the copy released to the Republican Party of Alberta. The fake entries turned up in an online lookup tool run by The Centurion Project, a separatist group, giving the agency the forensic certainty it needed to act. A Canadian court ordered the Centurion site shut down last week, and both organizations pledged to respect the law.
The electoral list contains names, addresses, and voting districts for millions of Albertans. Political parties can legally request copies but face strict limits on redistribution; sharing the data with a third party is forbidden. How the data moved from the Republican Party of Alberta to Centurion has not been publicly explained, but Elections Alberta's salted entries made the chain of custody impossible to deny.
Canary traps work because they are dumb in the best way. You hand each recipient a slightly different version of a document or database, and if a leaked copy carries the unique tells of recipient number seven, you know who leaked it. No cryptography, no watermarking pipeline, no machine learning — just deliberate, recipient-specific errors that the leaker can't filter out without knowing they're there.
Key facts
- 01Elections Alberta caught a voter-list leak by seeding bogus entries into the copy released to the Republican Party of Alberta.
- 02The Centurion Project, a separatist group, used the leaked list to run an online voter lookup tool before a court ordered it shut down last week.
- 03The canary-trap concept comes from Tom Clancy's 1980s novel Patriot Games, where 96 numbered copies carried 1,000 possible paragraph permutations.
- 04Dartmouth's V.S. Subrahmanian built WE-FORGE in 2021, an AI tool that auto-generates plausible but incorrect documents to bait leakers.
The technique has a long corporate history. Tesla and Apple have both reportedly used canary traps to catch internal leakers, and the method was once deployed to stop the leak of Star Trek film scripts. The term itself comes from Tom Clancy's 1980s novel Patriot Games, in which Jack Ryan explains how 96 numbered copies of a CIA report were each built from six different versions of every summary paragraph, yielding more than 1,000 possible permutations.
“Each summary paragraph has six different versions, and the mixture of those paragraphs is unique to each numbered copy of the paper. There are over a thousand possible permutations, but only ninety-six numbered copies.”— Jaeden Schafer
Ryan's pitch in the book is worth quoting in full: "Each summary paragraph has six different versions, and the mixture of those paragraphs is unique to each numbered copy of the paper. There are over a thousand possible permutations, but only ninety-six numbered copies of the actual document. The reason the summary paragraphs are so—well, lurid, I guess—is to entice a reporter to quote them verbatim in the public media."
Clancy's character even anticipated the automation step: "You can do it by computer. You use a thesaurus program to shuffle through synonyms, and you can make every copy of the document totally unique." That was the 1980s vision. The 2026 version is generative models that can rewrite entire passages while preserving meaning, producing recipient-unique copies at industrial scale.
Dartmouth professor V.S. Subrahmanian built one such tool in 2021, called WE-FORGE, which "automatically creates false documents to protect intellectual property such as drug design and military technology." The aim, Subrahmanian said, was to generate "documents that are sufficiently similar to the original to be plausible, but sufficiently different to be incorrect" — decoys that waste an attacker's time while flagging the leak when a fake detail surfaces.
The Alberta case is a reminder that the canary trap does not need an AI backend to work. Elections Alberta appears to have used the simplest possible version — a handful of fake voter records — and it was enough to attribute the leak within days. The deterrent effect compounds once recipients know the practice exists, because every shared copy becomes a potential trap.
There are limits. A canary trap only catches leaks of data that is shared with a known, finite set of recipients. It does nothing about external breaches, infostealer malware, or insiders who exfiltrate raw upstream data before any salting happens. And a sufficiently careful leaker who suspects salting can sometimes scrub or normalize the data before passing it on, which is precisely the gap that AI-generated decoys like WE-FORGE are designed to close — by spreading the tells across prose, not just into a few obvious rows.
The broader lesson for AI-era security teams is that the cheapest controls often outperform the elaborate ones. Companies spending heavily on data-loss prevention pipelines, behavioral analytics, and confidential-computing stacks can still get more attribution value out of a few well-placed fake records than out of an enterprise dashboard. As generative models make it trivial to mint plausible decoys at scale, the canary trap is about to get a lot more useful — and a lot harder to spot.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




