Showing posts with label Non-Snowden-leaks. Show all posts
Showing posts with label Non-Snowden-leaks. Show all posts

May 17, 2019

Daniel Hale arrested for being the source of The Drone Papers

(Updated: October 31, 2021)

Since the start of the Snowden revelations in June 2013, there have been more than 25 publications based upon classified documents provided by other leakers than former NSA contractor Edward Snowden.

Now, former intelligence analyst Daniel E. Hale has been identified as the source of six of these non-Snowden leaks. He was arrested on May 9 and charged with providing classified documents to the website The Intercept.

The case is highly remarkable, first because the FBI already found out Hale's identity almost five years ago and did not even arrest him when The Intercept published The Drone Papers in October 2015. Secondly, Hale did just as little to stay out of the picture: he featured in a documentary around the time the FBI raided his home.


Some of the slides and documents which Daniel Hale leaked to The Intercept
The abbreviations in the center slide are explained here
(click to enlarge)



Intelligence career


Daniel Everette Hale was born in 1987, is now 31 years old and living in Nashville, Tennessee. Despite his ideological disagreements with the military, he joined the US Air Force in July 2009 out of desperation because he was homeless. At the Air Force, he became a language analyst and was assigned to work at the National Security Agency (NSA) from December 2011 to May 2013.

From March to August 2012, Hale was deployed as an intelligence analyst in support of a task force of the Joint Special Operations Command (JSOC) at Bagram Airfield in Afghanistan, where he was mainly responsible for identifying and tracking targets for the drone program. He left the Air Force in July 2013.

Update:

In a letter to judge O'Grady from July 18, 2021, Hale says that only a few days after he arrived in Afghanistan, he witnessed how a group of men were killed by a drone strike, just because one of them carried a targeted cell phone and that since that time he questioned the justification for his actions.

In the same letter, he says that in December 2013 he got a job offer from a defense contractor and that at first he felt uneasy about working again for military intelligence, but that he still took the job because "the money I could make was by far more than I had ever made before".

From December 2013 to August 2014, he worked for the defense contractor Leidos (formerly SAIC), for which he was assigned to the National Geospatial-Intelligence Agency (NGA), which derives intelligence from geographical data and aerial and satellite imagery. There, Daniel Hale worked as a political geography analyst, for which he held a Top Secret/SCI clearance, just like for his previous job.



The 1.8 billion US dollar headquarters building for the ca. 16,000 employees of
the National Geospatial-Intelligence Agency in Fort Belvoir, Virginia
(photo: Marc Barnes/U.S. Army Corps of Engineers)


Contact with Scahill


Already in April 2013, almost two months before the start of the Snowden revelations, Hale used his unclassified work computer at the NSA to search for information on Jeremy Scahill, who then worked for Amy Goodman's news program Democracy Now!. In October 2013, Scahill would join Glenn Greenwald and Laura Poitras to establish the investigative website The Intercept.

On April 29, Hale attended a presentation of Scahill's book "Dirty Wars: The World Is a Battlefield" about the drone killings program under president Obama. The next day, Hale used his Top Secret NSA computer to search for classified information about people and issues about which Scahill wrote, according to the indictment.

Investigators had been able to retrieve Hale's text messages and found one which he sent to a close friend in May 2013, which read: " [Scahill] wants me to tell my story about working with drones at the opening screening of his documentary about the war and the use of drones."

On June 8, Hale was again present at a book presentation, where he was seen and recorded on video (see below) sitting right next to Scahill. In the next months they contacted eachother by phone and by e-mail.

Although Hale had already used his classified work computer for searching about related topics, there are no indications that he was already planning to steal and leak classified documents, at least before September 2013, when Scahill asked him to set up a Jabber account for encrypted chat conversations.



Book presentation at Busboys & Poets in Washington, DC on June 8, 2013,
with Jeremy Scahill (center) and Daniel Hale (right)



Printing classified documents


According to the indictment, Daniel Hale used his classified work computer at the National Geospatial-Intelligence Agency (NGA) to print classified documents for the first time on February 28, 2014 and he continued to do so until August 5, 2014.

In total, he printed 36 documents, including four duplicates. Nine documents were related to his work at NGA, but 23 did not. Hale provided at least 17 of these 23 documents to Scahill and/or The Intercept, which published them in whole or in part between July 2014 and December 2016:




A table from the indictment listing the 23 documents that Daniel Hale
printed at the NGA and were not related to his work.
(click to enlarge)


In an earlier posting on this weblog, I listed 28 revelations at various media platforms, accompanied by one or more leaked documents that were not attributed to Edward Snowden.

Trying to identify their source, I assumed that a then unknown "source nr. 3" was responsible for the documents that were scanned from paper and with a more or less military content:

Source nr. 3 (someone from US military intelligence?)
- NCTC watchlisting guidance
- NCTC terrorist watchlist report
- Ramstein AFB supporting drone operations
- The Drone Papers
- Cellphone surveillance catalogue
- FBI & CBP border intelligence gathering

Comparing the dates of these six publications with those in the table from the indictment leads to the following conclusions:

- Daniel Hale provided the documents for the first five revelations I attributed to Source nr. 3: from the "NCTC watchlisting guidance", which was published by The Intercept on July 23, 2014, to the "Cellphone surveillance catalogue" from December 17, 2015.

- The 14 original documents about "FBI & CBP border intelligence gathering", which I assumed could also have been provided by source nr. 3, are actually not among those that Hale printed out. Therefore, those files have to be leaked by someone else, probably an FBI or CBP employee.

- The indictment lists four unclassified documents (O, P, Q and R) and says these were published in December 2016, but so far no one seemed aware of a similar intelligence or national security revelation in that month.


Clapper's blog

Looking for articles that Jeremy Scahill published in December 2016 led me to a short story about James Clapper's blog called Intercept. It's indeed based upon four unclassified documents, which are again scanned from paper: a screenshot of a blog post from May 29, 2013, handwritten letters to and from Clapper and a few comments on that blog post.

This blog post is just a curiosity compared to the other documents, so it seems the only reason that Hale printed this out, is that the main comment, posted under the nickname "Wormy", is his own. The comment warns against increasing restrictions on civil liberties, with arguments based upon the US Constitution and the Bill of Rights - it reminds of how Snowden usually argues.



The documents leaked by Daniel Hale and published by The Intercept
(click to enlarge)



Raided by the FBI


On August 8, 2014, right after Daniel Hale's assignment at the NGA had ended, the FBI raided his home. This was just three days after he had printed out his last document at the NGA and some two weeks after The Intercept published its first article based upon his material, which means the FBI identified and found him rather quickly.

At his home, FBI agents found a thumb drive with the TOR software and the TAILS operating system, both used for anonymous internet communications. Also found was the unclassified (and unpublished) document T on his computer and one page of document A, which was classified Secret and published in October 2015, on a thumb drive.

Why Hale brought these files in digital form to his home, after having already printed the documents at his work place at the NGA, is not clear, but it was careless and unnecessarily risky.

It is not known how exactly Hale was traced, but a tweet from his lawyer, Jesselyn Radack seems to suggest that The Intercept failed at their source protection. That would be their third time, because NSA linguist Reality Winner and former FBI agent Terry Albury had already been arrested due to The Intercept's sloppyness.

But Daniel Hale was bad at operational security (OPSEC) too and did little to stay out of the picture: already in November 2013 he began speaking out publicly against the government's drone program at the "Ground the Drones" summit organized by Code Pink, where he apologized for his own participation in the program.

In January 2014, Hale also spoke at a rally outside the White House against the Guantanamo Bay prison camp. Again very similar to Snowden, who organized a Crypto Party while he was working for the NSA in Hawaii.

The big difference is that Hale just took a handful of selected documents that he thought were in the public interest, while Snowden (and Manning) acted just like the NSA: "collect before you select."



Featuring in National Bird


And just like Edward Snowden was being recorded on camera when his leaks came out in Laura Poitras' film Citizenfour, Daniel Hale was being interviewed for the drone whistleblower documentary National Bird around the time the FBI raided his home.

In National Bird it's mentioned that Hale was being investigated under the Espionage Act, allegedly because he was seen as a source for information about the drone program. The Intercept had already begun publishing the files he stole at the NGA, but of course Hale did not admit that on camera.

He just pretended that he didn't knew the reason for the investigation: it might had to do with the fact that he had worked for intelligence agencies and that he was politically active, which could have made the government suspicious.

Right after the release of National Bird in February 2016, at least some people must have noticed that Daniel Hale would make a perfect fit for being the source of The Drone Papers, but it seems they all kept quiet.



The full version of the 2016 documentary National Bird with German voice-over



Featuring in Citizenfour


Almost two years before Hale himself could be seen in National Bird, the information he leaked already appeared in Laura Poitras' film Citizenfour, which was released in October 2014. It shows Glenn Greenwald visiting Snowden in Moscow, telling him about a new source and writing the most sensitive details on sheets of paper.

When the camera zoomed in on the notes, it could be seen that the new source provided information about the chain of command for the drone strikes, the fact that their signals are relayed through Ramstein AFB in Germany (which would cause "a huge controversy") and that some 1.2 million people are in one way or another on a government watch list.

When Snowden expressed his concerns about the safety of the source, Greenwald reassured that they were "very careful in handling the source." Maybe they tried during the time Hale was handing over the documents, but given their prior non-secure contacts and Hale's public appearances, it was already too late for a sufficient source protection.



Glenn Greenwald informing Edward Snowden about The Intercept's new source
(still from the documentary film Citizenfour)


Interesting is that just before the scene in the Moscow hotel room, Citizenfour shows Jeremy Scahill talking to Bill Binney, former technical director of the NSA's World Geopolitical and Military Analysis Reporting Group, about how to handle confidential sources.

Binney gives the advice that the best way to talk to such sources is like Bob Woodward and Deep Throat did: meet physically in the basement of a parking garage.

We can assume that Daniel Hale met in a similar way with Scahill to hand over the documents he had printed out at the NGA. It's not clear though whether the conversation with Binney was recorded before or after these meetings, so at least Binney's advice was also meant for any future leakers.


Mission

For the relation between Hale and The Intercept the advice had come too late, and both must have known that, so apperently both were too eager to go along with publishing the files.

For The Intercept, the drone program seems to present the most clear and direct link between the NSA and actual illegal killings - despite the fact that these operations were actually run by the CIA, before Obama tried to transfer them to a military command.

Also, one of the slides leaked by Hale says that drone strikes will only occur when the presence of the target is based upon two forms of intelligence and all parties involved, being the local Task Force, the Geographic Combatant Command, the US Ambassador, the CIA Station Chief and the government of the host nation, have to concur or no strike occurs.

For Daniel Hale it may have become a moral mission to inform the public about the secret details behind the drone program and maybe this was also his way of making up his own involvement in the program during his time in Afghanistan.


Trial

Hale will appear before a judge on May 17. Under the Espionage Act of 1917, which doesn't distinguish between providing information to enemies or to the press, he can be sentenced to up to a maximum of 50 years imprisonment.

At least he has one of the best (and expensive) defense attorneys: Abbe Lowell, who recently represented Trump's son-in-law Jared Kushner(!), and who apparently does Hale's case pro bono.

Update #1:

Daniel Hale's lawyers sought to have the case dismissed, arguing that the Espionage Act was intended to target spying and should not be used against whistleblowers who expose government wrongdoing. US District Judge Liam O'Grady rejected this motion and in December 2019, prosecutors were allowed to move forward with their case against Hale.


Update #2:

On March 31, 2021, Daniel Hale eventually pleaded guilty to leaking classified documents, just days before he was slated to go on trial in federal court in Alexandria, Virginia, for violating the Espionage Act. Sentencing is scheduled for July 13.


Update #3:

On July 27, 2021, Daniel Hale was sentenced to 45 months in prison for violating the Espionage Act: "You could have been a whistleblower … without taking any of these documents" according to District Judge Liam O'Grady.



Links and sources

- Emptywheel: Daniel Hale, Citizenfive
- Intercepted Podcast: The Espionage Axe: Donald Trump and the War Agianst a Free Press
- Emptywheel: On the Curious Timing of Daniel Everette Hale’s Arrest
- Mint Press News: Another Whistleblower Bites the Dust as The Intercept Adds a Third Notch to Its Burn Belt
- The Washington Post: Former intelligence analyst charged with leaking drone details to news outlet
- Lawfare Blog: German Courts Weigh Legal Responsibility for U.S. Drone Strikes
- Zone d'Intérêt: U.S. Intelligence Support to Find, Fix, Finish Operations
- The Drone Papers: Acronyms, abbreviations, and initialisms


September 14, 2017

Are the Shadow Brokers identical with the Second Source?

(Updated: December 7, 2020)

What a lot of people don't know, is that a range of classified documents from the NSA have not been attributed to Edward Snowden, which means that there was at least one other leaker inside the NSA.

Initially, this leaker was called the "Second Source", and although he was responsible for significant leaks, they got little attention in the US. More media coverage gained the release, since 2016, of NSA hacking tools by the mysterious "Shadow Brokers".

Now, a close look at documents published by the German magazine Der Spiegel in December 2013 provided new indications that the Second Source could be identical with the leaker behind the Shadow Brokers.



NSA's Cryptologic Center in San Antonio, Texas (2013)
(photo: William Luther - click to enlarge)


The second source

The first leak that was not attributed to Snowden, was of an internal NSA tasking record, showing that German chancellor Angela Merkel was apparently on the NSA's targeting list. The second revelation that was said to come from the same source as the Merkel record, was that of the ANT product catalog, containing a wide range of sophisticated eavesdropping gadgets and techniques.

Security expert Bruce Schneier, who was probably the first to write about the possibility of a second source, said that this source apparently passed his documents to a small group of people in Germany, including hacktivist Jacob Appelbaum and documentary film maker Laura Poitras.

Because Poitras also received one of the initial sets of documents from Snowden, it is sometimes assumed that the documents from the Second Source may actually stem from the Snowden trove, despite not being attributed as such. For some of the individual documents this was contradicted by Glenn Greenwald and Edward Snowden though.


Spiegel reportings

The ANT catalog was published by the German magazine Der Spiegel on December 29, 2013. The original article was in German and written by Jacob Appelbaum, Judith Horchert, Ole Reißmann, Marcel Rosenbach, Jörg Schindler and Christian Stöcker. A translation in English mentioned the names of Jacob Appelbaum, Judith Horchert and Christian Stöcker.

Although this catalog got most of the attention, not at least because Appelbaum explained the various tools during a presentation at the hackers conference CCC on December 30, it was actually just an addition to Der Spiegel's extensive main piece about the hacking division of the NSA, called Tailored Access Operations (TAO).

This article was written by Jacob Appelbaum, Marcel Rosenbach, Jörg Schindler, Holger Stark and Christian Stöcker, with the cooperation of Andy Müller-Maguhn, Judith Horchert, Laura Poitras and Ole Reißmann. There was also a translation in English prepared by the Spiegel staff based upon reporting "by Jacob Appelbaum, Laura Poitras, Marcel Rosenbach, Christian Stöcker, Jörg Schindler and Holger Stark."


TAO documents

This main piece was accompanied by various NSA documents: one slide about FOXACID, a partial presentation about QUANTUM, two separate pages from other documents, as well as complete powerpoint presentations about QUANTUM tasking, the TAO unit at NSA/CSS Texas, and the QFIRE architecture:



(click to go to the various documents)


Not Snowden?

Apparently never noticed before, is that not only the ANT product catalog, but also these other presentations and documents were not attributed to Snowden. In both the German and the English version, the whole lengthy article contains multiple times phrases like "internal NSA documents viewed by SPIEGEL" but never in combination with the name of Edward Snowden.

This is remarkable, because for the media, it's usually almost some kind of honor to publish documents provided by Snowden, which is then clearly mentioned in their reporting. In those cases, the byline includes the name of the one who actually provided the documents on Snowden's behalf, often Glenn Greenwald and for Der Spiegel, Laura Poitras.

But both articles from December 29 have Jacob Appelbaum, instead of Poitras in the byline, which seems to be an indication that here, the top secret NSA documents were provided by Appelbaum, likely as the middleman for the mysterious second source.


Exception: FOXACID slide

There's one exception though: the description of the FOXACID slide says that it is from an NSA presentation from the Snowden cache - this was confirmed when on August 19, 2016, The Intercept eventually published the full presentation about FOXACID.

This slide was probably provided by Laura Poitras, from her cache of Snowden documents, which would explain why she was mentioned as one of the persons that provided assistance for Der Spiegel's main piece of December 29.

The other presentations have not been published as part of the Snowden revelations, there's only one with a similar layout (from Booz Allen's SDS unit), but is about a different topic.


Significance

If not only the ANT Product Catalog, but also these other NSA presentations about the TAO division were not provided by Snowden, but by the second source, what's the significance of that?

Analysing the range of revelations that were not attributed to Snowden, resulted in the following list of documents that were likely leaked by the second source:

- Chancellor Merkel tasking record
- TAO product catalog
- XKEYSCORE rules: TOR and TAILS
- XKEYSCORE rules: New Zealand
- NSA tasking & reporting France, Germany, Brazil, Japan
- XKEYSCORE agreement between NSA, BND and BfV(?)
- NSA tasking & reporting EU, Italy, UN

Except for the TAO catalog, one of the things that all these documents have in common, is that they are different from the usual powerpoint presentations, program manuals and internal wiki pages that make up the biggest part of the Snowden revelations.

(Of course, absence of evidence is no evidence of absence, but as these second source documents are often more significant than many other Snowden files, there seems to be no reason not to publish them)

The additional December 29 files do actually fit the typical sort of documents from Snowden, which makes it more difficult to distinguish between documents from Snowden and those from the other leaker(s).



The Shadow Brokers

If we look at the content of the files, we see that those from Der Spiegel's December 29 article are all about NSA's hacking operations. There have been several Snowden stories about that topic, but more spectacular became the release, since August 2016, of actual NSA hacking tools by a mysterious person or group called The Shadow Brokers (TSB or SB).

There has been a lot of speculation about who could be behind this and how he, she or they got access to these sensitive files. One option is an NSA insider, either on his own, in cooperation with crypto-anarchists, or as a mole directed by a hostile intelligence agency.

Another suggestion was that an NSA hacker mistakenly uploaded his whole toolkit to a server outside the NSA's secure networks (also called a "staging server" or "redirector" to mask its true location) and that someone was able to grab the files from there - this option was for example favored by Snowden.


Insider

The latter theory was falsified when on April 14, 2017, the Shadow Brokers did not only publish an archive containing a series of Windows exploits, but also several documents and top secret presentation slides about NSA's infiltration of the banking network SWIFT - things unlikely to be on a staging server, which makes that the source behind the Shadow Brokers is most likely an insider. Also, maybe one or two of these hacking tools may have been on a staging server for a specific mission, but not all those that were published by the Shadow Brokers?

On July 28, the website CyberScoop reported that as part of their investigation into the Shadow Brokers leaks, US government counterintelligence investigators contacted former NSA employees in an effort to identify a possible disgruntled insider.

(just a few days ago, the Shadow Brokers released a manual for the hacking framework UNITEDRAKE, strangely enough without date and classification markings, but again something that one wouldn't find on an outside staging server)



Same source?

With the documents published by the Shadow Brokers apparently being stolen by an insider at NSA, the obvious question is: could the Shadow Brokers be identical with the Second Source? (see update)

One interesting fact is that the last revelation that could be attributed to the second source occured on February 23, 2016, and that in August of that year the Shadow Brokers started with their release of hacking files. This could mean that the second source decided to publish his documents in the more distinct and noticeable way under the guise of the Shadow Brokers.

But there's probably also a much more direct connection: the batch of documents published along with Der Spiegel's main piece from December 29, 2013 include a presentation about the TAO unit at NSA's Cryptologic Center in San Antonio, Texas, known as NSA/CSS Texas (NSAT):



TAO Texas presentation, published by Der Spiegel in December 2013
(click for the full presentation)


And surprisingly, the series of three slides that were released by the Shadow Brokers on April 14 were also from NSA/CSS Texas. They show three seals: in the upper left corner those of NSA and CSS and in the upper right corner that of the Texas Cryptologic Center:



TAO Texas slide, published by the Shadow Brokers in April 2017
(click for the full presentation)


NSA/CSS Texas

It's quite remarkable that among the hundreds of NSA documents that have been published so far, there are only these two sets from NSA/CSS Texas. This facility is responsible for operations in Latin America, the Caribbean, and along the Atlantic littoral of Africa in support of the US Southern and Central Commands.

Update: The three Shadow Brokers slides from NSA/CSS Texas show operations against EastNets and Business Computer Group (BCG), which are both Service Bureaus for the banking network SWIFT. EastNets has offices in Belgium, Jordan, Egypt and UAE and was targeted under the codename JEEPFLEA_MARKET, while BCG serves Panama and Venezuela and was targeted under JEEPFLEA_POWDER.

Besides the one in San Antonio, Texas, NSA has three other regional Cryptologic Centers in the US: in Augusta, Georgia, in Honolulu, Hawaii and in Denver, Colorado. These four locations were established in 1995 as Regional Security Operations Centers (RSOC) in order to disperse operational facilities from the Washington DC area, providing redundancy in the event of an emergency.

So far, no documents from any of these regional centers have been published, except for the two from NSA/CSS Texas. This could be a strong indication that they came from the same source - and it seems plausible to assume that that source is someone who actually worked at that NSA location in San Antonio.

Access

This person may only have stolen files that were available at his own workplace, as it should be realized that not every leaker necessarily has similar broad access like Snowden had (and gained) in his job as a systems administrator.

Snowden on the other hand may only have downloaded things from an intranet for NSA as a whole (assuming that would contain the most interesting files) and leaving the local network for his Hawaii office untouched - which would explain why we never saw any documents marked NSA/CSS Hawaii (another reason could be that such documents would have made it easier to identify him).
Update: One rare 2007 message from NSA Hawaii was, among some other documents, published by The Intercept on March 1, 2018.

Given the many hacking files, it's tempting to assume that the second source/Shadow Brokers was an NSA hacker at the Texas TAO unit. It's not clear though whether someone in such a position would also have had the access to the intelligence reports and traditional tasking lists which were published by Wikileaks. It's also possible that those documents came from a different source.


Motivation

One final thing that the revelations from the second source and the Shadow Brokers seem to have in common is the motivation: none of their documents reveal serious abuses or illegal methods, but only compromise methods and operations, and discredit US intelligence.

Most of these documents weren't vetted by professional journalists either: although initially published by Der Spiegel and some other German media, later files were made public by the uncritical website Wikileaks, while the Shadow Brokers postings come without any intermediary on sites like Pastebin, Medium and Steemit.

(In March 2017, Wikileaks started the "Vault 7" series in which they publish secret hacking tools from the CIA. These files have dates between November 2003 and March 2016 and are therefore more recent that those from the Shadow Brokers, with their newest files being dated October 18, 2013 - some 5 months after Snowden left the NSA and around the same time when Der Spiegel published the first document from the second source)
 

Update #1:

On the weblog Emptywheel.net there are some additional thoughts about this issue: the author is, for various reasons, skeptical about the Shadow Brokers being a disgruntled NSA employee or contractor, and therefore that he could be identical with the Second Source. As an alternative, Emptywheel suggests that Jakob Appelbaum and the Shadow Brokers may have a mutually shared source.

I can agree with that, as I may not have made clear enough that the Second Source is the person who was able to actually steal documents from inside NSA, while the Shadow Brokers is a group or a single person who is responsible for publishing the files, just like Der Spiegel and Wikileaks did for most of the documents attributed to the Second Source.

Of course it would be possible that the Second Source eventually started to publish his documents himself under the covername Shadow Brokers, but as noted by Emptywheel, there are several indications that makes this less likely.

A slightly different option is that the Second Source provided his documents to Jacob Appelbaum and that he had them published by Der Spiegel and Wikileaks, and that later on, either Appelbaum himself acted as the Shadow Brokers, or gave the files to someone else operating under that guise.

Update #2:

In November 2013, the New York Times published a slide with a pie chart showing the sources of 103 collection accesses at the NSA's station in San Antonio, Texas. It's not clear though whether only this individual slide/chart is about NSA Texas, or the presentation as a whole.

Update #3:

An updated overview of the Shadow Brokers story was published by the New York Times on November 12, 2017, saying that investigators were worried that one or more leakers may still be inside NSA and also that the small number of specialists who have worked both at TAO and at the CIA came in for particular attention, out of concern that a single leaker might be responsible for both the Shadow Brokers and the files published by Wikileaks as part of their Vault7 and Vault8 series (although the CIA files are more recent).

Update #4:

In November 2020, national security blogger emptywheel reported that she had information that someone had logged into one of the Guccifer 2.0 accounts (involved in leaking the DNC documents hacked by the GRU) using the same IP address as someone who logged into the early staging sites (either Pastebin or GitHub) used by the Shadow Brokers. This could be an indication that the Shadow Brokers was an operation of Russian intelligence.





Links and sources
- The New York Times: Security Breach and Spilled Secrets Have Shaken the N.S.A. to Its Core (2017)
- Emptywheel.net: UNITEDRAKE and hacking under FISA Orders (2017)
- Emptywheel.net: Shadow Brokers' Persistence: Where TSB has signed, message, hosted, and collected
- Schneier.com: The US Intelligence Community has a Third Leaker (2014)

October 19, 2016

With NSA contractor Martin arrested, other leakers may still be at large

(Latest UPDATE: January 9, 2017)

Earlier this month we learned the name of a second person who stole top secret documents from the US National Security Agency (NSA). After Edward Snowden admitted doing so publicly in June 2013, the FBI has now arrested the 51-year old Harold T. Martin III at his home in Maryland.

Martin hoarded lots of classified documents, not only from NSA but also from a number of other military and intelligence agencies. The FBI is still comparing them with those from the recent Shadow Brokers leak and a range of other NSA leaks from the past few years, but given what's known now, it seems likely that at least one other leaker is still at large.



The house of Harold T. Martin III in Glen Burnie, Maryland
(photo: Jose Luis Magana/The Associated Press)


The New York Times reported that when the FBI raided Martin's house on August 27, they found paper documents and many terabytes of highly classified information, even going back the 1990s. At least six documents were from 2014. It was reported that Martin first took the classified documents on paper, later on CDs and more recently on thumb drives.

The reason why Harold Martin brought home and stored such large numbers of top secret documents isn't yet clarified. One suggestion is that he may have used them for research for his dissertation about "new methods for remote analysis of heterogeneous & cloud computing architectures", which he was working on at the University of Maryland.


Documents from multiple agencies

It should be noted that not everything Martin stole comes from NSA. In the official charges there are no names of the agencies where the documents come from, they are only described as highly classified, including ones that are marked as Top Secret and Sensitive Compartmented Information (SCI).

With the documents going back to the 1990s, he may well have started hoarding them from the places where he worked in those days. From 1987 to 2000, Martin served at the US Navy, achieving the rank of lieutenant, but he left active duty in 1992.

As the Washington Post found out, he then took a variety of tech jobs with government contractors, like at Computer Sciences Corp. (CSC) somewhere in the 1990s and later, until 2009, at Tenacity Solutions, for which he worked at the Office of the Director of National Intelligence (ODNI). Over the course of 18 years, Martin worked for a total of 8 different defense contractors.

In 2009, Harold Martin started to work for Booz Allen Hamilton, for which he was a contractor at NSA from 2012 to 2015, when Booz transferred him to the Pentagon’s Office of Acquisition, Technology and Logistics (AT&L), which is responsible for often highly sensitive and classified procurement programs. There he stayed until the moment of his arrest last August, after which he was also fired by Booz.

Officials have meanwhile said that Martin took classified documents not only from NSA, but also from his other workplaces, including ODNI and AT&L.

It's interesting as well that in the charges against Martin, a whole paragraph is dedicated to the at least six documents from 2014, which are described as being produced "through sensitive government sources, methods, and capabilities". As signals intelligence is traditionally seen as the most sensitive capability, maybe just these six documents are from NSA.



The building of the Office of the Director of National Intelligence (ODNI)
where Harold Martin worked as a contractor before 2009
(photo: Microsoft, via Cryptome.org - click to enlarge)


Shadow Brokers investigation

After the "Shadow Brokers" disclosed a large set of secret NSA hacking tools last August, the FBI began investigating this leak. At the same time there was a lot of speculation: was NSA hacked from the outside? Had an NSA hacker been sloppy? Were the tools leaked by an insider? Maybe the same insider responsible for earlier leaks that hadn't been attributed to Snowden?


On September 22, it was reported that during the FBI investigation, NSA officials had said that a former agency operative had carelessly left the hacking tool files available on a remote computer, where Russian hackers found them. If that's correct, then it seems likely that the FBI traced Harold Martin when they were looking for that careless NSA hacker. It has not yet been confirmed that Martin was that person though.

Harold Martin was working at NSA's hacking division TAO around the time when the tools were considered to be left exposed, somewhere after October 18, 2013, but a former TAO hacker told the Washington Post that Martin "worked in the unit’s front office carrying out support roles such as setting up accounts, not conducting actual operations."

Even if Martin was the man who left the hacking tools exposed, then we still don't know who found them and published them under the name Shadow Brokers. It's not very likely that this was done by Martin himself, as Shadow Brokers published additional messages on August 28, October 1, October 15, and October 31, when he was already in custody. The actual publication can therefore be the work of for example Russian, Iranian or North Korean hackers or even independent hacktivists.


Other sources?

Could Harold Martin also be the source of earlier leaks, that were not attributed to Edward Snowden? In theory he could have been that "second source" next to Snowden: none of these other leaked documents (like the TAO catalog, XKEYSCORE code, tasking lists and end reports) are newer than 2015, when Martin left NSA. Contrary to this Martin is described as very patriotic, which doesn't fit the fact that these particular leaks were clearly meant to harm and embarrass the US and NSA.


Also, Martin hasn't (yet) been charged with espionage or the attempt to provide classified information to a third party or a foreign government - which doesn't seem something the US government would leave out or keep secret after the recent and unprecedented statement in which the Office of the Director of National Intelligence accused Russia of hacking the Democratic National Committee (DNC) and other political organizations.

Should the FBI investigation confirm that Harold Martin was only responsible for leaking the NSA hacking tools (after which unknown others published them) and that none of his documents were provided to foreign intelligence agencies or showed up in the earlier revelations, then there's most likely yet another leaker from inside NSA.

The Shadow Brokers leak standing alone and not related to the earlier non-Snowden leaks is of some importance, because only among the stuff published by the Shadow Brokers there are files with a date (October 18, 2013) after the day that Snowden left NSA (May 20, 2013).

This means that when Harold Martin is the initial source of the Shadow Brokers files, we can no longer exclude the possibility that the earlier leaks do come from the Snowden trove. If that would be the case, then someone with access to them went rogue and had them published on his own account. But it should also be noted that both Glenn Greenwald and Bruce Schneier explicitly said that some of these leaked documents did not come from Snowden.

The more likely option is therefore that there's still another leaker at large, someone with a more evil intent than Harold Martin and Edward Snowden - a conclusion which is not very comforting and which also raises questions about NSA's internal security...



Some NSA buildings at the Friendship Annex (FANX) complex near Baltimore
(photo: live.com, via Cryptome.org - click to enlarge)


NSA's internal security measures

The NSA's hacking division TAO, where Harold Martin worked for some time, is apparently not located in the well-known NSA headquarters building at Fort Meade, but in one or more leased office buildings outside, one of them at an office complex called Friendship Annex (FANX) near Baltimore. TAO also has units at NSA's four Cryptologic Centers across the US.

Entrance to the highly secured TAO headquarters building is strictly controlled: one has to go through an imposing steel door, protected by armed guards, and entrance is only possible after entering a six-digit code and passing a retinal scanner to ensure that only specially cleared individuals are allowed in.

Such security measures are more aimed at keeping outsiders out, than at insiders in. And when it comes to finding inside moles of hostile foreign intelligence agencies, the NSA is also said to have a rather bad track record. The Manning and Snowden leaks made NSA painfully aware of this and so preventive insider-threat detection programs were put in place.

It's not clear whether these new systems failed in the case of Harold Martin, or that they simply weren't yet implemented at the TAO location where he worked - anti-leak software that was designed by Raytheon to "spot attempts by unauthorized people to access or download data" was also not yet installed at the NSA facility in Hawaii when Snowden was working there.

Tracking what employees are doing inside is one thing, checking what they take out is another. But according to The Washington Post, the NSA (like other agencies) does not impose universal checks of personnel and their belongings as they enter and leave agency buildings. Security guards only conduct random checks and use their discretion in order to keep en build the trust of the employees.

"If you have a bag full of stuff, you’re probably going to get stopped" said a former TAO operator to the Post, but, in general, "Disneyland has more physical security checks than we had". This was confirmed by two other former NSA employees, saying that "nobody does pocket checks" and that "Anything that could fit in a pocket could go out undetected".

It would also take hours to screen every person leaving NSA buildings, and because the vast majority of employees go through extensive vetting, so there's an inherent amount of faith in staff at the agency. Besides checks, NSA facilities will also have detection gates, but it seems that it was easier for Snowden to walk out with his thousands of documents than many would have thought.

As former NSA general counsel Rajesh De explained, it is unlikely "you’re going to be able to stop every incident of somebody taking documents if they’re determined to do so. But the real question is how quickly can you detect it, how quickly can you mitigate the harm of any such incident."



An old sign inside the NSA headquarters building
showing what kind of items are not allowed in.
(screenshot from a documentary about NSA)


Conclusion

Harold Martin stole a lot of classified documents from multiple military and intelligence agencies where he worked over the past 20 years, with maybe just a small number from NSA. The still ongoing FBI investigation has to make clear whether Martin was responsible for exposing the TAO hacking tools.

If not, then there has to be yet another careless NSA employee, but then it's also still possible that the hacking tools came from a source responsible for a range of earlier leaks. So far it seems that Martin isn't the source of those earlier leaks, which means that the so-called "second source" is still at large.

The case of Harold Martin also made clear that security measures at NSA, and other US agencies, were not as strict and tight as outsiders would have expected: even for someone without a strong ideological or financial drive like Martin it was apparently not that difficult to regularly walk out with top secret documents.

Many things have not yet been confirmed or clarified, but at least the Shadow Brokers leak and the subsquent arrest of Harold Martin created more awareness among the American public of the fact that there have been more leaks than just those from Snowden.

In August 2014, Bruce Schneier was probably one of the first who identified a second and a third leaker besides Snowden. Many more similar leaks followed and a full list of them was compiled on this weblog in December 2015 (still being updated). As an excerpt of this listing, a short overview of the most important non-Snowden leaks was published in The New York Times last week.

Update #1:

Shortly after this blog posting was published, The New York Times came with a new report saying that the volume of classified documents Harold Martin had in his possesion seems larger than those stolen by Edward Snowden and even than those of the Panama Papers from 2015.
FBI investigators apparently also found that the TAO hacking tools were among Martin's documents, but because he is not very cooperative, it is still not clear how they came in the hands of the mysterious Shadow Brokers, who subsequently published them. So far there's no evidence that Martin was hacked or that he sold information.
He seems to have hoarded all these documents in order to get better at his job, as he is described as someone who imagined himself a top spy and an important player in the world of digital espionage.

Update #2:

On October 20, it was reported that the FBI had found the huge amount of 50 terabytes of data at Martin's home, but it is not yet clear how much of that is actually classified. Also found were "hard-copy documents that were seized from various locations during the search that comprise six full bankers’ boxes worth of documents" with many of the documents marked Secret and Top Secret.
One document was marked Top Secret/SCI and had this additional caveat at the top of the document: "THIS CONOP [Concept of Operation] CONTAINS INFORMATION CONCERNING EXTREMELY SENSITIVE U.S. PLANNING AND OPERATIONS THAT WILL BE DISCUSSED AND DISSEMINATED ONLY ON AN ABSOLUTE NEED TO KNOW BASIS. EXTREME OPSEC [Operational Security] PRECAUTIONS MUST BE TAKEN" - Martin had no need to know for this operation.

Update #3:

Harold Martin appeared in court for the first time on Friday, October 21. There, his lawyer said that things like an "unlocked garden shed, stuffed with more classified documents than the contractor [...] could ever read, might be a symptom of a mental disorder" - and also that keeping top secret material in plain view in his home and car was not the conduct of a spy or a political activist.
Although he was charged with the relatively minor criminal offenses of theft of government property and unauthorized retention of classified material, Martin had to stay in jail because he could be a threat to national security as investigators couldn't rule out that he might have hidden classified information in other, yet undisclosed locations.
Even after seven weeks of investigation, the FBI was still not able to show whether Martin gave any of his documents to anyone else, nor could they link him to the Shadow Brokers.

Update #4:

A legal document filed by federal prosecutors on October 27 says that the information stolen by Harold Martin included numerous names of intelligence officials working under cover outside the United States. It is not clear whether these officials were from NSA or from other US intelligence agencies where Martin had worked as a contractor.

We also don't know how many documents Harold Martin actually stole from NSA: everything that matters within that agency is classified under the SCI compartment SI (Special Intelligence), but so far, the FBI investigation only mentioned very few documents that were classified as Top Secret/SCI.

On February 6, 2017, The Washington Post reported that, according to US officials, Harold Martin allegedly took more than 75 percent of TAO’s library of hacking tools with him, which would be an unprecedented security breach.

Harold T. Martin III was indicted on February 8, 2017, on charges of stealing and retaining the largest heist of classified information in US history. The documents were taken from US Cyber Command, CIA, National Reconnaissance Office (NRO) and NSA. Martin was not accused of passing information to foreigners, nor of being the source for the Shadow Brokers publications.


Links and Sources
- New York Times: Government Contractor Indicted in Theft of Top-Secret Documents
- New York Times: N.S.A. Appears to Have Missed ‘Big Red Flags’ in Suspect’s Behavior
- John Schindler: It’s Time to Rename NSA the National INsecurity Agency
- The Washington Post: NSA contractor thought to have taken classified material the old-fashioned way
- Daily Beast: Democrats Say WikiLeaks Is a Russian Front, U.S. Intelligence Isn’t So Sure
- Defense One: Data-Theft Arrest Shows that Insider Threat Remains Despite Post-Snowden Security Improvements
- John Schindler: Has the Russian Mole inside NSA finally been arrested?
- New York Times: N.S.A. Suspect Is a Hoarder. But a Leaker? Investigators Aren’t Sure.
- Defense One: The Man in Charge of Stopping the Next Snowden
- The Cipher Brief: First on The Cipher Brief: Snowden's Boss Shares Lessons Learned

August 20, 2016

Is the Shadow Brokers leak the latest in a series?

(Updated: December 7, 2020)

Earlier this week, a group or an individual called the Shadow Brokers published a large set of files containing the computer code for hacking tools. They were said to be from the Equation Group, which is considered part of the NSA's hacking division TAO.

The leak got quite some media attention, but so far it was not related to some earlier leaks of highly sensitive NSA documents. These show interesting similarities with the Shadow Brokers files, which were also not attributed to Edward Snowden, but seem to come from an unknown second source.



Screenshot of some computer code with instructions
from the Shadow Brokers archive from August 2016
(click to enlarge)


The Shadow Brokers files

Since August 13, Shadow Brokers posted a manifesto and two large encrypted files on Pastebin, on GitHub, on Tumblr and on DropBox (all of them closed or deleted meanwhile).

One of the encrypted files could be decrypted into a 301 MB archive containing a large number of computer codes for server side utility scripts and exploits for a variety of targets like firewalls from Cisco, Juniper, Fortinet and TOPSEC. The files also include different versions of several implants and instructions on how to use them, so they're not just the malware that could have been found on the internet, but also files that were only used internally.

A full and detailed list of the exploits in this archive can be found here.

Security experts as well as former NSA employees considered the files to be authentic, and earlier today the website The Intercept came with some unpublished Snowden documents that confirm the Shadow Brokers files are real.

Besides the accessible archive, Shadow Brokers also posted a file that is still encrypted, and for which the key would only be provided to the highest bidder in an auction. Would the auction raise 1 million bitcoins (more than 500 million US dollars), then Shadow Brokers said they would release more files to the public. This auction however is likely just meant to attract attention.

Updates:

Shadow Brokers, or people posing like them, posted an short announcement on Pastebin on August 28, and a third, long message including a "self-interview" on Medium.com on October 1. On October 15, a fourth message was published on Medium, saying that the auction was cancelled.

On October 31, 2016, Shadow Brokers came with a "Halloween message" on Medium, this time including a new file, which contains "configuration data for an as-yet-undisclosed toolkit for a variety of UNIX platforms" and also a list of 352 IP addresses and 306 domain names the NSA's hacking team Equation Group may have used for their operations. These addresses include timestamps from August 22, 2000, to August 18, 2010. The 10 most impacted countries are China, Japan, Korea, Spain, Germany, India, Taiwan, Mexico, Italy and Russia.

On December 14, 2016, someone calling himself Boceffus Cleetus published a post on Medium, saying that Shadow Brokers were now selling the supposed NSA hacking tools one by one, for prices between 1 and 100 bitcoins (780 - 78,000 USD), or 1000 bitcoins (780,000 USD) for the whole lot. Included is a list with codenames of the exploits as well as a file signed with a PGP key with an identical fingerprint as the original Shadow Brokers dump from August.

On January 12, 2017, the Shadow Brokers published a final message accompanied by 61 Windows-formatted binary files, including executables, dynamic link libraries, and device drivers, which are also considered to have been tools from the NSA's TAO hacking division. Most of these files had remained undetected by the most-used anti-virus tools. Images included with these files showed they were included on a Drive D that was most likely a USB drive, which, according to an independent researcher "lends credibility to the argument the leak came from an insider who stole, and subsequently lost control of, a USB stick, rather than a direct hack of the NSA."

On April 8, 2017, the Shadow Brokers were back and released a range of exploits for the Unix operating system Solaris and on April 14, 2017 they published an archive containing a series of Windows exploits that it had offered for sale in January and documents about NSA's infiltration of SWIFT, for the first time also including several Top Secret NSA powerpoint presentations, similar to those leaked by Snowden. The latest timestamp found in these files is October 17, 2013, which is one day before the latest one in the first Shadow Brokers release.




Screenshot of a file tree from the Shadow Brokers archive from August 2016
(click to enlarge)


From the Snowden documents?

According to security experts Bruce Schneier and Nicholas Weaver the new files aren't from the Snowden trove. Like most people, they apparently assume that Snowden took mostly powerpoint presentations and internal reports and newsletters, but that's not the whole picture. The Snowden documents also include various kinds of operational data, but this rarely became public.

Most notable was a large set of raw communications content collected by NSA under FISA and FAA authority, which also included incidentally collected data from Americans, as was reported by The Washington Post on July 5, 2014. The Snowden documents also include technical reports, which are often very difficult to understand and rarely provide a newsworthy story on their own.

Someone reminded me as well that in January 2015, the German magazine Der Spiegel published the full computer code of a keylogger implant codenamed QWERTY, which was a component of the NSA's WARRIORPRIDE malware framework. So with the Snowden trove containing this one piece of computer code, there's no reason why it should not contain more.

Contradicting the option that the Shadow Brokers files could come from Snowden is the fact that some of the files have timestamps as late as October 18, 2013, which is five months after Snowden left NSA. Timestamps are easy to modify, but if they are authentic, then these files have to be from another source.


A second source?

This brings us to a number of leaks that occured in recent years and which were also not attributed to Snowden. These leaks involved highly sensitive NSA files and were often more embarrassing than stuff from the Snowden documents - for example the catalog of hacking tools and techniques, the fact that chancellor Merkel was targeted and intelligence reports proving that NSA was actually successful at that.


It is assumed that these and some other documents came from at least one other leaker, a "second source" besides Snowden, which is something that still not many people are aware of. The files that can be attributed to this second source have some interesting similarities with the Shadow Brokers leak. Like the ANT catalog published in December 2013, they are about hacking tools and like the XKEYSCORE rules published in 2014 and 2015 they are internal NSA computer code.

This alone doesn't say much, but it's the choice of the kind of files that makes these leaks look very similar: no fancy presentations, but plain technical data sets that make it possible to identify specific operations and individual targets - the kind of documents many people are most eager to see, but which were rarely provided through the Snowden reporting.

As mainstream media became more cautious in publishing such files, it is possible that someone who also had access to the Snowden cache went rogue and started leaking documents just for harming NSA and the US - without attributing these leaks to Snowden because he would probably not approve them, and also to suggest that more people followed Snowden's example.

Of course the Shadow Brokers leak can still be unrelated to the earlier ones. In that case it could have been that an NSA hacker mistakenly uploaded his whole toolkit to a server outside the NSA's secure networks (also called a "staging server" or "redirector" to mask his true location) and that someone was able to grab the files from there - an option favored by for example Edward Snowden and security researcher the grugq.



Diagram showing the various stages and networks involved
in botnet hacking operations by NSA's TAO division
(source - click to enlarge)


An insider?

Meanwhile, several former NSA employees have said that the current Shadow Brokers leak might not be the result of a hack from the outside, but that it's more likely that the files come from an insider, who stole them like Snowden did earlier.

Of course it's easier for an insider to grab these files than for a foreign intelligence agency, let alone an ordinary hacker, to steal them from the outside. But if that's the case, it would mean that this insider would still be able to exfiltrate files from NSA premises (something that shouldn't be possible anymore after Snowden), and that this insider has the intent to embarrass and harm the NSA (Snowden at least said he just wanted to expose serious wrongdoings).

Here we should keep in mind that such an insider is not necessarily just a frustrated individual, but can also be a mole from a hostile foreign intelligence agency.

Update:
On August 21, NSA expert James Bamford also confirmed that TAO's ANT catalog wasn't included in the Snowden documents (Snowden didn't want to talk about it publicly though). Bamford favors the option of a second insider, who may have leaked the documents through Jacob Appelbaum and Julian Assange.


Russian intelligence?

On Twitter, Edward Snowden said that "Circumstantial evidence and conventional wisdom indicates Russian responsibility", but it's not clear what that evidence should be. It seems he sees this leak as a kind of warning from the Russians not to take revenge for the hack of the Democratic National Committee (DNC) e-mails, which was attributed to Russian intelligence.

This was also what led Bruce Schneier to think it might be the Russians, because who other than a state actor would steal so much data and wait three years before publishing? Not mentioned by Schneier is that this also applies to the documents that can be attributed to the second source: they also pre-date June 2013.

A related point of speculation is the text that accompanied the Shadow Brokers files, which is in bad English, as if it was written by a Russian or some other non-western individual. This is probably distraction, as it looks much more like a fluent American/English speaker who tried to imitate unexperienced English.

The text also holds accusations against "Elites", in a style which very much resembles the language used by anarchist hacker groups, but that can also be faked to distract from the real source (it was also noticed that the e-mail address used by Shadow Brokers (userll6gcwaknz@tutanota.com) seems to refer to the manga Code Geass in which an exiled prince takes revenge against the "Britannian Empire").



Screenshot of some file folders from the Shadow Brokers archive
(click to enlarge)


Conclusion

With the authenticity of the Shadow Brokers files being confirmed, the biggest question is: who leaked them? There's a small chance that it was a stupid accident in which an NSA hacker uploaded his whole toolkit to a non-secure server and someone (Russians?) found it there.

Somewhat more likely seems the option that they came from an insider, and in that case, this leak doesn't stand alone, but fits into a series of leaks in which, since October 2013, highly sensitive NSA data sets were published.

So almost unnoticed by the mainstream media and the general public, someone was piggybacking on the Snowden-revelations with leaks that were often more embarrassing for NSA than many reportings based upon the documents from Snowden.

Again, obtaining such documents through hacking into highly secured NSA servers seems less likely than the chance that someone from inside the agency took them. If that person was Edward Snowden, then probably someone with access to his documents could have started his own crusade against NSA.

If that person wasn't Snowden, then it's either another NSA employee who was disgruntled and frustrated, or a mole for a hostile foreign intelligence agency. But for an individual without the protection of the public opinion like Snowden, it must be much harder and riskier to conduct these leaks than for a foreign state actor.

Former NSA counterintelligence officer John Schindler also thinks there could have been a (Russian) mole, as the agency has a rather bad track record in finding such spies. If this scenario is true, then it would be almost an even bigger scandal than that of the Snowden-leaks.

Update #1:
During an FBI-led investigation of the ShadowBrokers leak, NSA officials reportedly said that a former agency operative carelessly left the hacking tool files available on a remote computer, where Russian hackers found them. After this was discovered, NSA tuned its sensors to detect use of any of the tools by other parties, like China and Russia. But as that wasn't the case, NSA did not feel obligated to warn the US manufacturers.

Update #2:
On October 6, 2016, The New York Times reported that on August 27, 2016, the FBI arrested 51-year old Harold T. Martin III, who worked at NSA as a contractor for Booz Allen Hamilton. In his home in Glen Burnie, Maryland, "many terabytes" of highly classified information was found, from the 1990s until 2014. Hal Martin was described as a hoarder, but so far, investigators are not sure he was also responsible for the various leaks that could not be attributed to Snowden.

Update #3:
On November 19, it was reported by the Washington Post that there had been yet another, previously undisclosed breach of cybertools, which was discovered in the summer of 2015. This was also carried out by a TAO employee, who had also been arrested, but his case was not made public. An official said that it is not believed that this individual shared the material with another country.

Update #4:
In November 2020, national security blogger emptywheel reported that she had information that someone had logged into one of the Guccifer 2.0 accounts (involved in leaking the DNC documents hacked by the GRU) using the same IP address as someone who logged into the early staging sites (either Pastebin or GitHub) used by the Shadow Brokers. This could be an indication that the Shadow Brokers was an operation of Russian intelligence.



Links and Sources
- EmptyWheel.com: The Shadow Brokers: “A nice little NSA you've got here: It'd be a shame if…”
- TheWeek.com: How the NSA got hacked
- EmptyWheel.com: Where Are NSA’s Overseers on the Shadow Brokers Release?
- Observer.com: NSA ‘Shadow Brokers’ Hack Shows SpyWar With Kremlin Is Turning Hot
- TechCrunch.com: Everything you need to know about the NSA hack (but were afraid to Google)
- WashingtonPost.com: Powerful NSA hacking tools have been revealed online
- NYTimes.com: ‘Shadow Brokers’ Leak Raises Alarming Question: Was the N.S.A. Hacked?
- LawfareBlog.com: NSA and the No Good, Very Bad Monday

Some older articles on this weblog that are of current interest:
In Dutch: Volg de actuele ontwikkelingen rond de Wet op de inlichtingen- en veiligheidsdiensten via het Dossier herziening Wiv 2017