Security Breach and Spilled Secrets Have Shaken the N.S.A. to Its Core

The N.S.A.’s headquarters at Fort Meade in Maryland. Cybertools the agency developed have been picked up by hackers from North Korea to Russia and shot back at the United States and its allies. Credit Jim Lo Scalzo/European Pressphoto Agency
The N.S.A.’s headquarters at Fort Meade in Maryland. Cybertools the agency developed have been picked up by hackers from North Korea to Russia and shot back at the United States and its allies. Credit Jim Lo Scalzo/European Pressphoto Agency
TT

Security Breach and Spilled Secrets Have Shaken the N.S.A. to Its Core

The N.S.A.’s headquarters at Fort Meade in Maryland. Cybertools the agency developed have been picked up by hackers from North Korea to Russia and shot back at the United States and its allies. Credit Jim Lo Scalzo/European Pressphoto Agency
The N.S.A.’s headquarters at Fort Meade in Maryland. Cybertools the agency developed have been picked up by hackers from North Korea to Russia and shot back at the United States and its allies. Credit Jim Lo Scalzo/European Pressphoto Agency

Jake Williams awoke last April in an Orlando, Fla., hotel where he was leading a training session. Checking Twitter, Mr. Williams, a cybersecurity expert, was dismayed to discover that he had been thrust into the middle of one of the worst security debacles ever to befall American intelligence.

Mr. Williams had written on his company blog about the Shadow Brokers, a mysterious group that had somehow obtained many of the hacking tools the United States used to spy on other countries. Now the group had replied in an angry screed on Twitter. It identified him — correctly — as a former member of the National Security Agency’s hacking group, Tailored Access Operations, or T.A.O., a job he had not publicly disclosed. Then the Shadow Brokers astonished him by dropping technical details that made clear they knew about highly classified hacking operations that he had conducted.

America’s largest and most secretive intelligence agency had been deeply infiltrated.

“They had operational insight that even most of my fellow operators at T.A.O. did not have,” said Mr. Williams, now with Rendition Infosec, a cybersecurity firm he founded. “I felt like I’d been kicked in the gut. Whoever wrote this either was a well-placed insider or had stolen a lot of operational data.”

The jolt to Mr. Williams from the Shadow Brokers’ riposte was part of a much broader earthquake that has shaken the N.S.A. to its core. Current and former agency officials say the Shadow Brokers disclosures, which began in August 2016, have been catastrophic for the N.S.A., calling into question its ability to protect potent cyberweapons and its very value to national security. The agency regarded as the world’s leader in breaking into adversaries’ computer networks failed to protect its own.

“These leaks have been incredibly damaging to our intelligence and cyber capabilities,” said Leon E. Panetta, the former defense secretary and director of the Central Intelligence Agency. “The fundamental purpose of intelligence is to be able to effectively penetrate our adversaries in order to gather vital intelligence. By its very nature, that only works if secrecy is maintained and our codes are protected.”

With a leak of intelligence methods like the N.S.A. tools, Mr. Panetta said, “Every time it happens, you essentially have to start over.”

Fifteen months into a wide-ranging investigation by the agency’s counterintelligence arm, known as Q Group, and the F.B.I., officials still do not know whether the N.S.A. is the victim of a brilliantly executed hack, with Russia as the most likely perpetrator, an insider’s leak, or both. Three employees have been arrested since 2015 for taking classified files, but there is fear that one or more leakers may still be in place. And there is broad agreement that the damage from the Shadow Brokers already far exceeds the harm to American intelligence done by Edward J. Snowden, the former N.S.A. contractor who fled with four laptops of classified material in 2013.

Mr. Snowden’s cascade of disclosures to journalists and his defiant public stance drew far more media coverage than this new breach. But Mr. Snowden released code words, while the Shadow Brokers have released the actual code; if he shared what might be described as battle plans, they have loosed the weapons themselves. Created at huge expense to American taxpayers, those cyberweapons have now been picked up by hackers from North Korea to Russia and shot back at the United States and its allies.

Millions of people saw their computers shut down by ransomware, with demands for payments in digital currency to have their access restored. Tens of thousands of employees at Mondelez International, the maker of Oreo cookies, had their data completely wiped. FedEx reported that an attack on a European subsidiary had halted deliveries and cost $300 million. Hospitals in Pennsylvania, Britain and Indonesia had to turn away patients. The attacks disrupted production at a car plant in France, an oil company in Brazil and a chocolate factory in Tasmania, among thousands of enterprises affected worldwide.

American officials had to explain to close allies — and to business leaders in the United States — how cyberweapons developed at Fort Meade in Maryland came to be used against them. Experts believe more attacks using the stolen N.S.A. tools are all but certain.

Inside the agency’s Maryland headquarters and its campuses around the country, N.S.A. employees have been subjected to polygraphs and suspended from their jobs in a hunt for turncoats allied with the Shadow Brokers. Much of the agency’s arsenal is still being replaced, curtailing operations. Morale has plunged, and experienced specialists are leaving the agency for better-paying jobs — including with firms defending computer networks from intrusions that use the N.S.A.’s leaked tools.

“It’s a disaster on multiple levels,” Mr. Williams said. “It’s embarrassing that the people responsible for this have not been brought to justice.”

(The New York Times)



Russia Pledges ‘Full Support’ for Venezuela Against US ‘Hostilities’

The US Navy replenishment oiler USNS Kanawha (T-AO-196) arrives at port in Ponce, Puerto Rico, amid ongoing military movements, December 21, 2025. (Reuters)
The US Navy replenishment oiler USNS Kanawha (T-AO-196) arrives at port in Ponce, Puerto Rico, amid ongoing military movements, December 21, 2025. (Reuters)
TT

Russia Pledges ‘Full Support’ for Venezuela Against US ‘Hostilities’

The US Navy replenishment oiler USNS Kanawha (T-AO-196) arrives at port in Ponce, Puerto Rico, amid ongoing military movements, December 21, 2025. (Reuters)
The US Navy replenishment oiler USNS Kanawha (T-AO-196) arrives at port in Ponce, Puerto Rico, amid ongoing military movements, December 21, 2025. (Reuters)

Russia on Monday expressed "full support" for Venezuela as the South American country confronts a blockade of sanctioned oil tankers by US forces deployed in the Caribbean, the two governments said.

In a phone call, the foreign ministers of the two allied countries blasted the US actions, which have included bombing alleged drug-trafficking boats and more recently the seizure of two tankers.

A third ship was being pursued, a US official told AFP Sunday.

"The ministers expressed their deep concern over the escalation of Washington's actions in the Caribbean Sea, which could have serious consequences for the region and threaten international shipping," the Russian foreign ministry said of the call between ministers Sergei Lavrov and Yvan Gil.

"The Russian side reaffirmed its full support for and solidarity with the Venezuelan leadership and people in the current context," it added.

"The ministers agreed to continue their close bilateral cooperation and to coordinate their actions on the international stage, particularly at the UN, in order to ensure respect for state sovereignty and non-interference in internal affairs."

The UN Security Council is to meet Tuesday to discuss the mounting crisis between Venezuela and the United States after a request from Caracas, backed by China and Russia.

On Telegram, Venezuela's Gil said he and Lavrov had discussed "the aggressions and flagrant violations of international law being perpetrated in the Caribbean: attacks on vessels, extrajudicial executions, and illicit acts of piracy carried out by the United States government."

US forces have since September launched strikes on boats Washington said, without providing evidence, were trafficking drugs in the Caribbean Sea and eastern Pacific Ocean.

More than 100 people have been killed, some of them fishermen, according to their families and governments.

US President Donald Trump on December 16 announced a blockade of "sanctioned oil vessels" sailing to and from Venezuela.

Trump has claimed Caracas under Maduro is using oil money to finance "drug terrorism, human trafficking, murder and kidnapping.

Gil said Lavrov had affirmed Moscow's "full support in the face of hostilities against our country."


Turkish Agents Capture an ISIS Member on the Afghan-Pakistan Border

A Turkish soldier stands guard outside the Silivri Prison and Courthouse complex near Istanbul, Turkey. (File/Reuters)
A Turkish soldier stands guard outside the Silivri Prison and Courthouse complex near Istanbul, Turkey. (File/Reuters)
TT

Turkish Agents Capture an ISIS Member on the Afghan-Pakistan Border

A Turkish soldier stands guard outside the Silivri Prison and Courthouse complex near Istanbul, Turkey. (File/Reuters)
A Turkish soldier stands guard outside the Silivri Prison and Courthouse complex near Istanbul, Turkey. (File/Reuters)

Turkish intelligence agents have captured a senior member of the ISIS terror group in an area along the Afghanistan-Pakistan border, allegedly thwarting planned suicide attacks in Türkiye and elsewhere, Türkiye's state-run news agency reported Monday.

Anadolu Agency said the suspect was identified as Mehmet Goren and a member of the group's Afghanistan-based ISIS-Khorasan branch. He was caught in a covert operation and transferred to Türkiye.

It was not clear when the operation took place or whether Afghan and Pakistani authorities were involved.

The report said the Turkish citizen allegedly rose within the organization’s ranks and was given the task of carrying out suicide bombings in Türkiye, Pakistan, Afghanistan and Europe.

ISIS has carried out deadly attacks in Türkiye, including a shooting at an Istanbul night club on Jan. 1, 2017, which killed 39 people.

Monday's report said Goren’s capture allegedly also exposed the group's recruitment methods and provided intelligence on its planned activities.


Iran Arrests Norwegian-Iranian Dual Citizen

Iran's Evin Prison (File photo: Reuters)
Iran's Evin Prison (File photo: Reuters)
TT

Iran Arrests Norwegian-Iranian Dual Citizen

Iran's Evin Prison (File photo: Reuters)
Iran's Evin Prison (File photo: Reuters)

A Norwegian-Iranian dual citizen has been arrested in Iran, Norway's foreign ministry told AFP on Monday.

"The Ministry of Foreign Affairs is aware that a Norwegian citizen has been arrested in Iran, but due to our obligation to respect confidentiality we cannot provide further details," ministry spokesman Mathias Rongved said in an email.

He confirmed the individual was a dual Norwegian-Iranian national and noted the government advises against travel to Iran.

On its website, the Norwegian government states that Iran does not recognise dual citizenship, and it is "therefore very difficult -- virtually impossible -- for the embassy to assist Norwegian-Iranian citizens if they are imprisoned in Iran".

The US-based Human Rights Activists News Agency (HRANA) identified the dual national as Shahin Mahmoudi, born in 1979.

It said she was arrested on December 14 after being ordered to report to authorities in Saqqez, in Iran's western Kurdistan province.

She is being held at a detention center in Sanandaj, it added.

HRANA said her family had not been informed of the reason for her arrest nor had they received any news of her health and well-being.