Doxing each other, dropping private information on the internet for the public to see, has cultural roots in the hacking community. However, cybersecurity researchers were surprised when intelligence agencies, who traditionally prized their secrecy, followed suit and revealed details on other countries’ cyber operations. An increasing number of states have published information regarding cyber espionage operations discovered on networks within their jurisdiction. So far, little research has been published analyzing what motivates such behavior. Understanding why states chose to publish sensitive details is important, as practices of strategic interaction in cybersecurity are only just emerging into public view. This talk will offer a rough account of the identified practices in selected empirical cases and offer first possible explanations on what the respective strategic communities may have wanted to achieve when releasing such information. The talk is based on a larger empirical research project looking into this question. Particularly, I will argue that more states investing in attribution capabilities (both on the intelligence and policy side) has changed the strategic context, the result of which we are now seeing. Drawing on research from political science, the talk contributes towards bridging the gap between policy and information security communities. The talk is aimed at information security professionals, who would like to better understand the politicization of their field. Focusing on a controversial topic, public attribution, this talk will contribute towards a more comprehensive understanding of what public attribution is used for at the state level.