On January 8, 2019, Paul Manafort's defense lawyers filed a court brief with the sensitive parts hidden behind black boxes. Within hours, journalists had highlighted the boxes, pressed copy, pressed paste, and read every word, including the admission that Manafort had shared 2016 campaign polling data with Konstantin Kilimnik, a man the FBI tied to Russian intelligence. That redaction failure, and what it revealed about the Manafort case, is part of the public court record now.
Nobody hacked anything. The lawyers had drawn rectangles over the text. The text was still there. If you're about to redact a PDF the same way, with a black highlighter or a filled shape, the document you publish will contain everything you think you removed. Here's why, and how to do it properly.
The Black Box Is a Decoration, Not a Deletion
A PDF page is a stack of instructions: draw this text here, place that image there. Add a black rectangle with a shape or markup tool and you've appended one more instruction on top. The text-drawing instruction underneath is untouched. Select-all reads instructions, not pixels. So do search engines, screen readers, and any script that opens the file.
A true PDF redaction removes the underlying text and image data from the file rather than just covering it up. A black rectangle drawn with a highlighter or shape tool is a separate object sitting on top of the page — the words underneath remain intact and fully extractable by copy-paste, text search, or any script that reads the file's contents.
This exact failure has embarrassed institutions that should know better, repeatedly, and it predates PDF-specific redaction tools by years. In May 2005, the U.S. military published a report on the death of Nicola Calipari, an Italian intelligence officer shot at a checkpoint in Iraq, with sensitive passages hidden behind opaque blocks; readers discovered within days that the blocked-out text pasted cleanly into a word processor. AT&T's lawyers made the identical mistake in May 2006, in a legal brief about the company's cooperation with NSA wiretapping — pages 12 through 14 carried black bars over text that copy-paste lifted straight out. Manafort's filing in 2019 is simply the most recent entry on a list that keeps growing, because the underlying error — treating a visual cover as a deletion — is easy to make and expensive to notice too late.
The NSA's own guidance on the subject, a document called "Redacting with Confidence" written to help government staff sanitize reports before public release, says it in one line: sensitive information has to be actually removed from the document, not visually hidden or made illegible. That guidance predates most of the incidents above, and none of the organizations that got burned by ignoring it worked for the NSA.
Why Copy-Paste Beats a Highlighter
The mechanics are worth understanding, because they explain every failure above and tell you exactly what "real" redaction has to do.
Every page in a PDF is described by a content stream: a sequence of low-level drawing instructions. Text is placed with an operator that says, in effect, "show these characters, in this font, at this position." Images are placed the same way, as a reference to embedded image data plus a position and size. When you draw a black box with a highlighter, a shape tool, or even the "redaction" feature in some general-purpose PDF editors, you are adding a new drawing instruction, usually a filled rectangle or a separate annotation object, on top of the instructions that were already there. Nothing about the original text instruction changes. It still exists, in its original position, spelling out the original words, one drawing command underneath the one you just added.
That's why the fix isn't a smarter black box. It's removing the text-drawing instructions themselves, or discarding the content stream entirely and replacing it with something that never contained text objects in the first place: typically a rasterized image of the finished page. Either approach leaves nothing behind for copy-paste, text search, or a scripted extraction to find, because the data simply no longer exists in the file.
Annotation-based redaction tools split into two camps for exactly this reason. Some genuinely burn the annotation into the page and delete the content underneath it — real redaction. Others just draw the annotation and leave the content stream untouched, counting on the black box always rendering on top in every viewer, forever — fake redaction, visually indistinguishable from the real thing and completely different to a script.
What Real Redaction Requires
Four things, and skipping any one of them has burned someone publicly.
- Remove the content itself. Delete the text and image data, or rasterize the page so no text objects exist at all. Covering is not removing.
- Flatten everything. No annotation layer a reader can select, move, or delete to peek underneath.
- Scrub the hidden data. PDFs carry document properties (author, title, creator), comments, attachments, form data, and sometimes prior revisions of themselves, since PDF edits can be appended rather than rewritten. Scanned PDFs hide one more channel: the invisible OCR text layer that makes them searchable sits under the image, and it holds every word on the page even after you paint over the picture.
- Verify. Select all, copy, paste into a text editor. Search the output for the string you redacted. Open the document properties. Thirty seconds, and it would have saved every organization named in this article.
A fifth item belongs on this list even though it isn't a redaction step: know what you're actually obligated to remove. U.S. federal court rules are explicit about it. Federal Rule of Civil Procedure 5.2 requires anyone filing electronically to redact Social Security and taxpayer-ID numbers down to the last four digits, financial account numbers down to the last four digits, birth dates down to the year, and minors' names down to initials, before the document reaches the public docket. The rule puts that duty on the person filing, not the court clerk. That's what makes the copy-paste test in step four, in a court filing, the difference between compliance and a sanctionable disclosure.
Even Technically Perfect Redaction Can Still Leak
One more failure mode is worth knowing, because it has nothing to do with sloppy tooling. A redaction can strip every trace of the covered text from the file and still give away what it said, through everything left standing around it.
A table of contents entry naming a section your redaction blacked out. A running header repeating a term you removed from the body text. An index, common at the back of depositions and long reports, whose entries sit in strict alphabetical order, so a blacked-out entry's position on the page narrows the possible words down to whatever falls alphabetically between its neighbors. Two versions of the same document released months apart, one leaked and unredacted, one official and redacted, sitting side by side for anyone patient enough to diff them line by line. None of these require breaking the redaction itself. They infer the content from context the redaction never touched.
So after you redact, reread the surrounding structure, not just the covered text, and ask what it still gives away: a heading, a cross-reference, a caption, an index entry sitting in a suspiciously specific place in the alphabet. No tool does that step for you, because no tool understands what the rest of the document says about the part it just blacked out.
The stakes here are not hypothetical. When the Police Service of Northern Ireland accidentally published the surnames, initials, ranks, and work locations of roughly 9,500 officers and staff in an August 2023 freedom-of-information response, the UK's Information Commissioner's Office fined it £750,000 in September 2024 for failing to have adequate safeguards in place. Given Northern Ireland's security history, the regulator's finding wasn't only about a compliance gap. For some of those officers, exposure meant a physical safety risk, not just a paperwork one.
The Part Where You Discover the Price
People searching for Acrobat's redaction tool tend to discover two things in short order. It works properly, marking content and genuinely deleting it, with a sanitize step for the hidden data. And it lives exclusively in Acrobat Pro, at $19.99 a month on an annual plan as of September 2026. Not in the free Reader or the free online tools. Not even in Acrobat Standard.
So the next search is "free online redaction tool," which leads somewhere worse. Think about what that workflow is: taking your most sensitive document, the one whose contents you specifically need to control, and uploading the unredacted original to a server you know nothing about. Copies in transit and at rest, retention you'll never get to audit. The whole point of redacting is defeated before the first box is drawn.
Redact Without the Upload
OxygenPDF's Redact PDF tool runs entirely in your browser. The file never leaves your machine, which for this job is the entire point.
Here's the actual workflow, step by step:
- Upload your PDF. If it's password-protected, you'll be asked to unlock it first. The tool has to read the real page content to redact it, the same as any PDF reader would.
- Choose a mode. Find & Redact searches the document's text and blacks out every match, case-insensitively, across every page. Type "Kilimnik" once instead of hunting page by page. Full Pages blacks out entire pages, for exhibits or attachments that shouldn't survive at all.
- Review the preview. Every affected page gets a red outline and a badge showing either the match count or a "Redact" marker, so you can see exactly what's about to disappear before it does.
- Apply the redactions. Under the hood it takes the most destructive path available, on purpose. Each page is re-rendered to pixels at twice the base resolution, the black boxes are burned directly into those pixels, and a brand-new PDF is built from the result, a fresh document rather than an edited copy of the original. The original text objects don't exist in the output, so the Manafort copy-paste test comes back empty, and because the file is new rather than edited, none of the source document's metadata, comments, form data, or buried revisions ride along either.
- Download and verify. The redacted file downloads automatically. Open it, select all, copy, paste (the thirty-second check from the previous section) before you send it anywhere.
The honest trade-off: the result is image-based. Pages are re-encoded as JPEG, so text anywhere in the document is no longer selectable or searchable, and the file can get larger than the original. That's the cost of scorched earth, and it's the same trade-off every redaction tool that works by rasterizing makes, not something unique to one implementation. If you only need to clean document properties or strip scripts from a file without touching the visible content, Sanitize PDF does the lighter job instead.
Redacting Edge Cases You'll Actually Hit
The two modes above cover most documents, but a few situations trip people up.
- Scanned documents and photos. If the sensitive information is a photo of an ID, a signature, or a page scanned with no real text layer underneath, Find & Redact has nothing to search: there's no text object to match, only pixels. Use Full Pages instead. This is the one situation where covering pixels is genuinely sufficient, because there's no separate text layer hiding underneath them to leak later.
- Documents that are secretly scans. A PDF can display normal-looking typed text and still be a raster image of a scanned page with an invisible, searchable OCR text layer sitting underneath it, added by whatever scanner or app produced the file. Find & Redact will find and black out matches in that hidden layer exactly as it would in ordinary text. But if you're not sure whether a document is "real" text or an OCR'd scan, treat it as a scan and check the output carefully afterward.
- Repeated headers and footers. A case number, a client name, or a file reference that repeats on every page is exactly what Find & Redact is built for: one search catches every occurrence, instead of forty individual black boxes drawn by hand across forty pages.
- Unusually large pages. Architectural drawings, oversized exhibits, and other pages far bigger than a standard sheet get processed in horizontal strips rather than as one giant image, so an extremely tall or wide page doesn't hit a browser memory ceiling partway through and fail silently. You don't have to do anything differently; it's handled automatically. But it's worth knowing if a huge exhibit takes noticeably longer to process than a normal page.
- Multiple sensitive terms in one document. Run the search-and-redact pass once per term. There's no bulk find-and-replace-list step, so a document with a name, a case number, and an account number needs three separate searches, not one.
FAQ
Does drawing a black box over text in a PDF actually redact it?
No. A black rectangle drawn with a highlighter, shape, or markup tool sits on top of the page as a separate object. The text underneath is untouched and can be recovered by selecting it, copying it, and pasting it into any text editor. That's the exact mistake that exposed Paul Manafort's court filing in 2019 and AT&T's NSA-wiretapping brief in 2006.
Is there a free way to redact a PDF without uploading it anywhere?
Yes. OxygenPDF's Redact PDF tool runs entirely client-side, using the same open-source PDF-rendering engine (pdf.js) your browser already relies on to display PDFs, plus a PDF-writing library to rebuild the file. Your file is read, redacted, and rebuilt on your own device, and no copy of it is ever sent to a server.
How do I verify a PDF is really redacted?
Open the finished file, press Ctrl+A (or Cmd+A on a Mac) to select all, copy it, and paste it into a plain text editor. If any text you meant to redact appears in the pasted output, the redaction failed. Then check the document properties panel for author names, comments, or other metadata you meant to strip out.
What's the difference between redacting and sanitizing a PDF?
Redacting removes specific sensitive content from the visible page — names, numbers, whole exhibits. Sanitizing strips hidden data that isn't part of the visible page at all: document metadata, embedded scripts, comments, and attachments. A file can need one, the other, or both; Sanitize PDF handles the metadata side without touching page content.
Can I redact a scanned PDF that's really just an image?
Yes, but text search won't find anything to match, because there's no text object to search: only pixels. Use Full Pages mode to black out an entire scanned page, since there's nothing to redact selectively on a page that has no text layer at all.
Am I legally required to redact certain information?
For U.S. federal court filings, yes. Federal Rule of Civil Procedure 5.2 requires redacting Social Security numbers, taxpayer ID numbers, and financial account numbers down to their last four digits, birth dates down to the year, and minors' names down to initials, before filing. Other contexts, like medical records, employment files, and state-court rules, carry their own requirements, so check what applies to your specific document before you publish it.
Before You Hit Send
Redact the content, not the view of it. Scrub what travels with the file. Reread what's left standing around the redaction, because context leaks too. Then run the copy-paste test like the last four paragraphs of your career depend on it, because for a few unlucky lawyers, they did.
Redact your PDF in the browser, on your machine, and the unredacted version never exists anywhere but with you.
Rohman

