Security Breach and Spilled Secrets Have Shaken the N.S.A. to Its Core

The N.S.A.’s headquarters at Fort Meade in Maryland. Cybertools the agency developed have been picked up by hackers from North Korea to Russia and shot back at the United States and its allies. Credit Jim Lo Scalzo/European Pressphoto Agency
The N.S.A.’s headquarters at Fort Meade in Maryland. Cybertools the agency developed have been picked up by hackers from North Korea to Russia and shot back at the United States and its allies. Credit Jim Lo Scalzo/European Pressphoto Agency
TT
20

Security Breach and Spilled Secrets Have Shaken the N.S.A. to Its Core

The N.S.A.’s headquarters at Fort Meade in Maryland. Cybertools the agency developed have been picked up by hackers from North Korea to Russia and shot back at the United States and its allies. Credit Jim Lo Scalzo/European Pressphoto Agency
The N.S.A.’s headquarters at Fort Meade in Maryland. Cybertools the agency developed have been picked up by hackers from North Korea to Russia and shot back at the United States and its allies. Credit Jim Lo Scalzo/European Pressphoto Agency

Jake Williams awoke last April in an Orlando, Fla., hotel where he was leading a training session. Checking Twitter, Mr. Williams, a cybersecurity expert, was dismayed to discover that he had been thrust into the middle of one of the worst security debacles ever to befall American intelligence.

Mr. Williams had written on his company blog about the Shadow Brokers, a mysterious group that had somehow obtained many of the hacking tools the United States used to spy on other countries. Now the group had replied in an angry screed on Twitter. It identified him — correctly — as a former member of the National Security Agency’s hacking group, Tailored Access Operations, or T.A.O., a job he had not publicly disclosed. Then the Shadow Brokers astonished him by dropping technical details that made clear they knew about highly classified hacking operations that he had conducted.

America’s largest and most secretive intelligence agency had been deeply infiltrated.

“They had operational insight that even most of my fellow operators at T.A.O. did not have,” said Mr. Williams, now with Rendition Infosec, a cybersecurity firm he founded. “I felt like I’d been kicked in the gut. Whoever wrote this either was a well-placed insider or had stolen a lot of operational data.”

The jolt to Mr. Williams from the Shadow Brokers’ riposte was part of a much broader earthquake that has shaken the N.S.A. to its core. Current and former agency officials say the Shadow Brokers disclosures, which began in August 2016, have been catastrophic for the N.S.A., calling into question its ability to protect potent cyberweapons and its very value to national security. The agency regarded as the world’s leader in breaking into adversaries’ computer networks failed to protect its own.

“These leaks have been incredibly damaging to our intelligence and cyber capabilities,” said Leon E. Panetta, the former defense secretary and director of the Central Intelligence Agency. “The fundamental purpose of intelligence is to be able to effectively penetrate our adversaries in order to gather vital intelligence. By its very nature, that only works if secrecy is maintained and our codes are protected.”

With a leak of intelligence methods like the N.S.A. tools, Mr. Panetta said, “Every time it happens, you essentially have to start over.”

Fifteen months into a wide-ranging investigation by the agency’s counterintelligence arm, known as Q Group, and the F.B.I., officials still do not know whether the N.S.A. is the victim of a brilliantly executed hack, with Russia as the most likely perpetrator, an insider’s leak, or both. Three employees have been arrested since 2015 for taking classified files, but there is fear that one or more leakers may still be in place. And there is broad agreement that the damage from the Shadow Brokers already far exceeds the harm to American intelligence done by Edward J. Snowden, the former N.S.A. contractor who fled with four laptops of classified material in 2013.

Mr. Snowden’s cascade of disclosures to journalists and his defiant public stance drew far more media coverage than this new breach. But Mr. Snowden released code words, while the Shadow Brokers have released the actual code; if he shared what might be described as battle plans, they have loosed the weapons themselves. Created at huge expense to American taxpayers, those cyberweapons have now been picked up by hackers from North Korea to Russia and shot back at the United States and its allies.

Millions of people saw their computers shut down by ransomware, with demands for payments in digital currency to have their access restored. Tens of thousands of employees at Mondelez International, the maker of Oreo cookies, had their data completely wiped. FedEx reported that an attack on a European subsidiary had halted deliveries and cost $300 million. Hospitals in Pennsylvania, Britain and Indonesia had to turn away patients. The attacks disrupted production at a car plant in France, an oil company in Brazil and a chocolate factory in Tasmania, among thousands of enterprises affected worldwide.

American officials had to explain to close allies — and to business leaders in the United States — how cyberweapons developed at Fort Meade in Maryland came to be used against them. Experts believe more attacks using the stolen N.S.A. tools are all but certain.

Inside the agency’s Maryland headquarters and its campuses around the country, N.S.A. employees have been subjected to polygraphs and suspended from their jobs in a hunt for turncoats allied with the Shadow Brokers. Much of the agency’s arsenal is still being replaced, curtailing operations. Morale has plunged, and experienced specialists are leaving the agency for better-paying jobs — including with firms defending computer networks from intrusions that use the N.S.A.’s leaked tools.

“It’s a disaster on multiple levels,” Mr. Williams said. “It’s embarrassing that the people responsible for this have not been brought to justice.”

(The New York Times)



Israel Warns of ‘Prolonged’ War Against Iran

This picture shows the heavily damaged building of the Islamic Republic of Iran Broadcasting (IRIB) after it was hit a few days earlier in an Israeli strike, in Tehran, on June 19, 2025. (AFP)
This picture shows the heavily damaged building of the Islamic Republic of Iran Broadcasting (IRIB) after it was hit a few days earlier in an Israeli strike, in Tehran, on June 19, 2025. (AFP)
TT
20

Israel Warns of ‘Prolonged’ War Against Iran

This picture shows the heavily damaged building of the Islamic Republic of Iran Broadcasting (IRIB) after it was hit a few days earlier in an Israeli strike, in Tehran, on June 19, 2025. (AFP)
This picture shows the heavily damaged building of the Islamic Republic of Iran Broadcasting (IRIB) after it was hit a few days earlier in an Israeli strike, in Tehran, on June 19, 2025. (AFP)

Israel's war against Iran, now in its second week, will be "prolonged", military chief Eyal Zamir said Friday as the arch rivals traded fire and European powers held talks with the country.

"We must be ready for a prolonged campaign," Zamir told Israelis in a video statement, eight days after his country launched a massive wave of strikes it said aimed at stopping Iran from developing nuclear weapons -- an ambition Tehran has denied.

"We have embarked on the most complex campaign in our history to remove a threat of such magnitude," said Zamir.

"The campaign is not over. Although we have made significant achievements, difficult days still lie ahead."

Iran has responded with barrages of missiles and drones, which Israeli authorities say have killed at least 25 people.

A hospital in the Israeli port of Haifa reported 19 injured, including one person in serious condition, after the latest Iranian salvo, which President Isaac Herzog said hit a mosque.

Iran said on Sunday that Israeli strikes had killed at least 224 people since June 13, including military commanders, nuclear scientists and civilians.

As US President Donald Trump mulls the prospect of entering the war between the two foes, top diplomats from Britain, France and Germany were meeting with their Iranian counterpart Abbas Araghchi on Friday.

French President Emmanuel Macron said the Europeans were "putting a diplomatic solution on the table".

On the ground, Israel's military said it struck missile launchers in southwestern Iran after overnight air raids on dozens of targets including what it called a "nuclear weapons project" research and development center.

In Israel, sirens sounded in the afternoon after missiles were launched from Iran for the second time on Friday, with a military official saying that "approximately 20 missiles were launched towards Israel".

Iran's Revolutionary Guards said they had targeted military sites and air forces bases.

- 'Betrayal' of diplomacy -

Trump has said he will decide "within the next two weeks" whether to involve the United States in the fighting.

Britain's Foreign Secretary David Lammy said "a window now exists within the next two weeks to achieve a diplomatic solution", while agreeing with US Secretary of State Marco Rubio that "Iran can never develop or acquire a nuclear weapon".

Western governments suspect Iran of seeking a nuclear weapons capability.

The International Atomic Energy Agency said that while Iran is the only country without nuclear weapons to enrich uranium to 60 percent, there was no evidence it had all the components to make a functioning nuclear warhead.

"So, saying how long it would take for them, it would be pure speculation because we do not know whether there was somebody... secretly pursuing these activities," the agency's chief Rafael Grossi told CNN.

"We haven't seen that and we have to say it."

France's foreign ministry spokesperson Christophe Lemoine said that "military solutions are not long-term solutions" to ensure Iran respects its obligations under the nuclear Non-Proliferation Treaty.

Addressing the UN Human Rights Council on Friday, Araghchi said Israel's attacks were a "betrayal" of diplomatic efforts to reach a nuclear deal between Tehran and Washington.

"We were attacked in the midst of an ongoing diplomatic process," he said.

In an interview with German publication Bild, Israel's top diplomat Gideon Saar said he did not "particularly" believe in diplomacy with Iran.

"All diplomatic efforts so far have failed," said Saar, whose country had supported Trump's 2018 decision to abandon a previous nuclear agreement between Iran and world powers.

- 'Madness' -

The UN Security Council convened on Friday for a second session on the conflict, which was requested by Iran with support from Russia, China and Pakistan, a diplomat told AFP on Wednesday.

The escalating confrontation is quickly reaching "the point of no return", Turkish President Recep Tayyip Erdogan warned on Friday, saying "this madness must end as soon as possible".

UN chief Antonio Guterres meanwhile pleaded with all sides to "give peace a chance".

Any US involvement in Israel's campaign would be expected to involve the bombing of an underground uranium enrichment facility in Fordo, using powerful bunker-busting bombs that no other country possesses.

In Iran, people fleeing Israel's attacks described frightening scenes and difficult living conditions, including food shortages.

Government spokeswoman Fatemeh Mohajerani said authorities had restricted internet access to avoid "problems" like cyberattacks.

Iranian authorities have arrested a European "who sought to spy on sensitive areas of the country", Tasnim news agency reported on Friday.

Protests were held in Tehran and other cities after Friday prayers, with demonstrators chanting slogans in support of their leaders, state television showed.

"I will sacrifice my life for my leader," read a protester's banner, a reference to supreme leader Ali Khamenei.

Switzerland announced it was temporarily closing its embassy in Tehran, adding that it would continue to fulfil its role representing US interests in Iran.