“When the Channel Was the Trap”

A letter hidden in a beer barrel sounds faintly comic until you remember that, in 1586, paper could carry a death sentence.
Mary, Queen of Scots, believed she had a secret channel. She was wrong. The channel was the trap.
Images in this article are generated by

EU AI Act Regulation 2024/1689
That is what makes the Babington cipher such a sharp artefact for this series. It is not just a story about a cipher being broken. It is a story about interception, authentication, compromised transport, forged message handling, legal evidence and political violence. In other words, cybersecurity with ruffs, wax seals and the executioner’s axe.
The previous article looked at Catherine of Aragon using cipher as agency: a way to speak across hostile space. Mary’s story begins in similar territory but ends somewhere much darker. Mary was a captive queen, held in England for nearly nineteen years. She was not simply waiting to be rescued, pitied, executed or painted. She wrote. She negotiated. She instructed. She complained. She flattered. She threatened. She used correspondence as one of the few remaining levers of power available to her.
Letters were her interface with the world.
Naturally, that interface was monitored.
During her captivity, Mary’s correspondence was repeatedly intercepted by Elizabethan officials. Letters could be delayed, opened, copied, resealed and sent on. The recipient might never know the message had been handled. Modern people call this interception and traffic manipulation. Elizabethan intelligence officers called it routine work.[1]
By 1586, the pressure around Mary had become acute. She was a Catholic claimant with a strong dynastic position, imprisoned by a Protestant queen who had already survived plots. To some Catholics, Mary was the legitimate queen. To Elizabeth’s government, she was a permanent security problem with a crown-shaped silhouette.
Anthony Babington, a young Catholic gentleman, became involved in a plot to assassinate Elizabeth, free Mary, and place her on the English throne. The plan depended on secret communication with Mary at Chartley Hall, where she was being held under Sir Amias Paulet. The channel looked clever: letters smuggled in and out, hidden in beer barrels.
Unfortunately for Mary, the route was already compromised.
Gilbert Gifford, the man helping establish the correspondence, was working for Walsingham. Sir Francis Walsingham, Elizabeth I’s principal secretary and spymaster, had spent years watching Mary’s correspondence and Catholic networks. By 1586, his intelligence operation was positioned not merely to intercept messages, but to shape the channel through which Mary believed she was communicating.
The brewer involved in the barrel route was also under English control. Messages to and from Mary passed through the hands of Elizabeth’s intelligence network before continuing to their intended destination. This was not merely an intercepted message. This was a hostile communications platform pretending to be a secure one.[2]
The cipher used in the fatal correspondence was not just a Caesar shift with a crown on it. It was a nomenclator: a hybrid system combining symbols for individual letters with symbols for common words, names or politically sensitive terms[3]. That made it more serious than a simple substitution cipher. It also made it more work to break.
But more work is not the same as enough work.
Thomas Phelippes, Walsingham’s cryptographer, deciphered the messages. He was one of the central technical actors in the whole operation, though Walsingham usually gets the credit. Phelippes read what Mary and Babington thought was hidden. When he deciphered Mary’s 17 July 1586 letter, he drew a gallows on the address leaf, indicating that he believed the contents would condemn her.[2]
The image is almost too neat: a cryptanalyst, a letter, a gallows mark.
The decrypted letter became the key document in the Babington Plot. The British Library describes it as the “Gallows Letter” and says Mary’s words authorised the plot and agreed to Elizabeth’s assassination. Babington had proposed the “dispatch” of Elizabeth by six gentlemen; Mary’s reply, as deciphered and used by Walsingham, became the proof he had been waiting for.[2]
For a cybersecurity history, the important point is not simply “the cipher was broken”. That is the beginner’s version. The real lesson is worse.
The adversary controlled the channel, read the protected content, altered the message flow and turned the result into evidence.
That is an entire incident lifecycle with a beheading at the end.
The next stage is even more recognisable to modern eyes.

Walsingham and Phelippes did not only read Mary’s letter. Before it was forwarded, passages were amended and a postscript was added, asking Babington to name the six men who would assassinate Elizabeth and explain how they would proceed. The National Archives catalogue identifies this as the forged postscript to Mary’s letter to Babington by Thomas Phelippes.[4]
There it is: confidentiality fails, and then integrity fails too.
Mary’s cipher could hide the words from casual readers. It could not prove that a message had not been altered. It could not authenticate the sender in the modern sense. It could not protect against an attacker who had the cipher, the transport route, the timing and the confidence to inject text into the conversation. Once Phelippes could write in the same cipher, the system had no way to say: that part is not really from Mary.
This is not merely cryptanalysis. It is an active attack.
It also shows the danger of treating a cipher as if it protects the whole system. A secure-looking message travelling through a captured route is not secure. An encrypted letter copied before delivery is not private. A cipher table known to the wrong person is not a shield. A channel that the enemy operates is not a secure channel; it is potentially a confession machine in waiting.
If this feels modern, that is because the shape keeps returning. Compromised endpoints. Entity-in-the-middle attacks. Session hijacking. Message tampering. Lack of authentication. Chain-of-custody disputes. Logs used as evidence. A user trusting an interface because it looks like the one they expect. A state actor quietly sitting in the route and reading everything.
The clothing changes. The failure mode does not.
Mary’s trial then adds another layer. She denied knowing Babington and insisted that there were no letters in her own handwriting conspiring against Elizabeth. Tudor Times notes that her secretary Nau confessed to writing the letter at Mary’s dictation, while Mary denied receiving Babington’s letter and pointed to the lack of handwritten evidence.[5]
That is not a side detail. That is authentication.
Whose hand wrote it? Who dictated it? Who encoded it? Who handled it? Who copied it? Was the document original, deciphered, translated, amended, forged, extracted under interrogation, or presented as transcript? What exactly is being proved, and by which artefact?
Every digital forensics person currently sighing into their cup of tea has met this problem. Evidence is never just information. It is information with provenance, handling, interpretation, and power attached. Mary’s letters became evidence because people with authority made them legible in a particular institutional context. That does not make the contents irrelevant. It does mean the process matters.
This is why the Babington cipher belongs here. It is a communications security failure, an intelligence success, a legal weapon and a political execution path all at once.
It is also a story that needs some historical care.
Mary should not be written as a foolish woman who trusted a silly code. She used one of the available technologies of secrecy under conditions of captivity and surveillance. Her choices were constrained, her channels were hostile, and her enemies were patient. That does not absolve her of political agency. Quite the opposite. It restores it. A person with no agency cannot conspire; a person with no agency cannot be dangerous.
Elizabeth also should not be flattened into jealous rival-queen melodrama. She was the target of assassination plots, a woman sovereign in a profoundly unstable political and religious environment, and the person whose ministers built the surveillance apparatus around Mary. Reducing this to two women in a royal feud would be satisfying television and terrible history.
Then there is Walsingham. He deserves his reputation as Elizabeth’s spymaster, but he should not absorb all the credit. Phelippes did the technical work of deciphering and writing in cipher. Gifford made the channel work as bait. Paulet’s custody regime mattered. The brewer and carriers mattered. Mary’s secretaries, including Nau and Gilbert Curle, mattered. Clerks, copyists, interrogators, messengers, archivists and later editors all shaped what survived and how it could be read.
A cipher system is never only the cipher. It is always the people around it, including the ones the record treats as furniture.
Modern recovery work matters too. Recent (2023) codebreaking has made this even clearer. George Lasry, Norbert Biermann and Satoshi Tomokiyo deciphered 57 previously lost cipher letters by Mary, dating from before the Babington crisis, and historians such as Jade Scott have used Mary’s encrypted correspondence to recover a much richer picture of her as a strategist and political actor, not merely a victim or villain.[6]
That belongs in this article’s shadow. The Babington cipher is the fatal one, but it is not the only one. Mary lived in cipher for years. Secret writing was part of her political life before it became part of the case against her.
The tragedy is that the Babington cipher did what weak security often does. It protected against the wrong threat. It hid meaning from people outside the system, but failed against people who had quietly become the system.
The sender believed in secrecy.
The adversary owned delivery.
The cryptographer read the message.
The same cryptographer could write back.
The court received evidence.
The queen lost her life.
Confidentiality was not enough. It rarely is. A message must also arrive by a trustworthy route, from a trustworthy sender, unchanged, attributable and defensible when challenged. Otherwise secrecy is only a delay before someone more patient turns it into plaintext.
Mary’s Babington cipher did not merely fail to conceal.
It became legible to power.
And power knew exactly what to do with it.

000000110
References
[1] Jade Scott excerpt, “The Decrypted History of Mary, Queen of Scots”, Folger Shakespeare Library, for Mary’s captivity, multilingual correspondence, letters as political strategy, and the surveillance/copying/resealing of her communications. (Folger Shakespeare Library)
[2] British Library, “The Gallows Letter”, for the 17 July 1586 letter, Walsingham’s knowledge of the plot, Phelippes’ decipherment, the beer-barrel channel, and the interception/resealing process. (British Library)
[3] Simon Singh, “The Black Chamber: Mary Queen of Scots”, for the accessible explanation of Mary’s cipher as a nomenclator mixing letter substitutions and code symbols. (simonsingh.net)
[4] The National Archives image record, “Forged postscript to Mary’s letter to Babington, by Thomas Phelippes”, for the forged postscript artefact itself. (The National Archives)
[5] Tudor Times, “Codes & Ciphers: The Babington Plot”, for Gifford, the beer-barrel route, Mary’s secretaries, the added postscript, and Mary’s trial denial around handwriting and receipt. (Tudor Times)
[6] Taylor & Francis Newsroom, “Codebreakers Crack Secrets of Mary Queen of Scots’ Lost Letters”, for the 2023 decipherment of 57 lost cipher letters by George Lasry, Norbert Biermann and Satoshi Tomokiyo. (Taylor & Francis Newsroom)
Previous artefact:
005 | Catherine of Aragon’s Cipher

