In May 2013, a 29-year-old NSA contractor named Edward Snowden boarded a flight to Hong Kong. He carried with him laptops loaded with as many as 1.5 million classified documents, a conservative estimate later offered by the House Intelligence Committee. In the weeks that followed, he handed a portion of that trove to journalists, revealing that the National Security Agency was collecting phone metadata on millions of Americans and tapping into the servers of major tech companies through a program called PRISM.

He called himself a whistleblower.

He claimed that he was exposing a surveillance apparatus the public had a right to know about. But when authorities moved to charge him with theft of government property and violations of the Espionage Act, he didn’t stay to make his case in court. He ran. First to Hong Kong, then to Moscow, where he’s lived ever since – granted first asylum, then residency, and finally, in 2022, Russian citizenship.

Whatever you might think of the surveillance programs he exposed, his choice of flight path is telling. Real whistleblowers don’t make a getaway to an adversary’s capital. They don’t seek sanctuary from the intelligence services of a rival government. Details matter, and Snowden’s escape to a communist country complicates the mythology.

He painted himself as a hero of transparency. Supporters point to his self-described motive – alerting Americans to a surveillance state operating beyond its legal bounds – as proof of his courage as a whistleblower. But motive alone has never been the test to which the law or the literature applies, and it’s worth working through what that test actually is before deciding who passes it.

Defining a Whistleblower

Defining what constitutes a whistleblower can get complicated. American law doesn’t use a single definition for the term, but a consistent thread runs through the major statutes that address it.

The Whistleblower Protection Act of 1989 shields federal employees who disclose a violation of law, gross mismanagement, gross waste of funds, abuse of authority, or a substantial danger to public health or safety – provided the disclosure goes through recognized channels, such as an inspector general or a congressional committee. The False Claims Act’s qui tam provisions let insiders report fraud against the government. At the same time, the Dodd-Frank Act created an SEC program rewarding people who report securities violations directly to the agency.

Scholars studying the phenomenon, most notably Janet Near and Marcia Miceli in their foundational 1984 work, generally define whistleblowing as “the disclosure by an organization’s members, current or former, of illegal, unethical, or illegitimate practices to parties who can act on them.” Both traditions – legal and scholarly – converge on the same core concept: a whistleblower is an insider with genuine knowledge of wrongdoing who directs that information to an authority – a regulator, an inspector general, a court, sometimes the press – capable of correcting it, and who does so to serve the public interest rather than a private one.

Crucially, legal protection typically attaches to the channel used and the good-faith belief that a law or rule was actually broken, not just to the act of disclosure itself. Someone who simply dislikes a policy, disagrees with a classification decision, or objects to a program on ideological grounds has not, by that fact alone, blown a whistle in any legal or scholarly sense of the term.

The Whistleblower

Legitimate whistleblowing generally rests on a few recognizable elements: the discloser has direct, verifiable knowledge of specific wrongdoing, not secondhand suspicion or policy disagreement; the disclosure is proportionate, targeting the misconduct rather than dumping vast, unrelated troves of information; the whistleblower generally attempts internal or legal channels before going public, or has good reason to believe those channels are compromised; and the discloser is willing to stand behind the claim, often accepting professional or legal risk rather than evading accountability entirely.

Three cases illustrate this well. Sherron Watkins, an Enron vice president, wrote directly to CEO Kenneth Lay in 2001 warning that the company’s accounting practices could cause it to “implode in a wave of accounting scandals” – a narrow, internal disclosure that later helped unravel one of the largest corporate frauds in American history. We all know how that ended.

Frances Haugen, a former Facebook data scientist, copied thousands of internal research documents showing the company knew its products harmed teenagers’ mental health, then filed a formal SEC complaint and testified before Congress under her own name. Coleen Rowley, an FBI staff attorney, sent a detailed memo up the bureau’s own chain of command in 2002, and then to the Senate Intelligence Committee, documenting how headquarters had brushed aside warnings before the September 11 attacks – a disclosure aimed precisely at the failure she had witnessed, delivered through channels designed to receive it.

In each case, actions speak volumes. The whistleblower remained within recognizable legal and institutional frameworks and accepted personal exposure rather than seeking refuge abroad.

THE LEAKER

Not every high-profile leaker fits the mold, and many self-proclaimed whistleblowers fail the sniff test outright. Snowden didn’t take his concerns to the inspector general. He didn’t contact his elected representatives or reach out to a congressional oversight committee. He didn’t even pursue his so-called concerns through the legal system. Instead, he took a bulk trove of documents – many unrelated to the very surveillance programs he claimed motivated him – to Russia, where he remains today.

Chelsea Manning, a former Army intelligence analyst, funneled roughly 750,000 classified and sensitive files to WikiLeaks in 2010, including classified diplomatic cables with no connection whatsoever to any specific abuse. The disclosure was absolutely indiscriminate and clearly wasn’t intended to target any identifiable wrongdoing, regardless of her claims, which is why she was convicted under the Espionage Act rather than protected as a whistleblower.

More recently, Jack Teixeira, a young Massachusetts Air National Guardsman, leaked classified documents about the war in Ukraine and allied intelligence operations in 2023 – not to expose misconduct, but to impress a small circle of friends on a Discord server. He was sentenced to 15 years in prison.

None of them directed narrow, credible evidence of wrongdoing to an authority positioned to fix it; instead, they executed a mass disclosure of classified material driven by personal conviction, ego, or self-preservation, with little regard for the consequences. That distinction – between exposing a specific abuse through legitimate means and unilaterally deciding which state secrets the public deserves to see – is exactly what separates a whistleblower from a leaker.

Related News

Steve Leonard is a former senior military strategist and the creative force behind the defense microblog, Doctrine Man!!. A career writer and speaker with a passion for developing and mentoring the next generation of thought leaders, he is a co-founder and emeritus board member of the Military Writers Guild; the co-founder of the national security blog, Divergent Options; a member of the editorial review board of the Arthur D. Simons Center’s Interagency Journal; a member of the editorial advisory panel of Military Strategy Magazine; and an emeritus senior fellow at the Modern War Institute at West Point. He is the author, co-author, or editor of several books and is a prolific military cartoonist.