Intelligence Portal Compromises — Research Reference

The thesis: every surveillance capability governments build eventually gets turned against them.

2026-06-16 6 min read Research file
Contents

The thesis: every surveillance capability governments build eventually gets turned against them.

The Pattern

InfrastructureBuilt ByCompromised ByResult
CALEA lawful interceptUS Congress/telecomsSalt Typhoon (China)China surveilled the surveillance
Law enforcement portals (LEIA)DEA/DOJTeenagers (ViLE)16 federal databases accessed with one password
Emergency data requestsTech companies/policeLAPSUS$, variousThousands of fraudulent requests fulfilled
Threat intel sharing (InfraGard)FBI“USDoD” (Brazilian)87,000 CI professionals’ data sold for $50K
Government spyware (Hacking Team)ItalyUnknown hackers400GB including client lists, zero-days dumped
Government spyware (FinFisher)Germany/UKCriminal investigationDissolved amid a criminal investigation into alleged unlicensed exports
Government spyware (Pegasus)Israel/NSORogue employee; Citizen LabCode stolen for dark web; operations exposed
Security clearance (OPM)US governmentChina (MSS)21.5M SF-86 forms — 40-year CI damage
Phone forensics (Cellebrite)IsraelHacktivists; Signal1.7TB leaked; forensic evidence integrity undermined
Encryption backdoor (Dual EC DRBG)NSA via JuniperChina (suspected)NSA’s own backdoor was backdoored

DEA Portal Hack (2022)

Hackers gained access to LEIA (Law Enforcement Inquiry and Alerts) — queries 16 federal databases simultaneously. One compromised username/password, no MFA. Members of “ViLE” cybercriminal group. Sagar Steven Singh (19) and Nicholas Ceraolo (25) charged 2023; both pleaded guilty and were sentenced in 2024 (Singh 27 months, Ceraolo 25 months).


Fraudulent Emergency Data Requests

Hackers compromised police email accounts to submit fake EDRs to Apple, Google, Meta, Snap, Discord. No warrant needed — EDRs rely on attestation of immediate risk to life. Companies complied because requests came from legitimate law enforcement addresses. FBI issued advisory November 2024 warning of spike.


FBI InfraGard Hack (December 2022)

Hacker “USDoD” applied using stolen CEO identity (name, DOB, SSN), was approved, scraped 87,000+ member records. Sold for $50,000 on BreachForums. Arrested October 2024 (33-year-old Brazilian man).


Hacking Team (July 5, 2015)

400GB+ dumped publicly. Internal emails, invoices, source code for RCS spyware, zero-day exploits, complete client list. 70 government clients including Ethiopia, Sudan, Saudi Arabia, Russia, Kazakhstan, Bahrain. Sudan contract ($960K) violated UN arms embargo. Ethiopia used it to target journalists. Passwords like “P4ssword.” WikiLeaks published the archive.


FinFisher/FinSpy

German-British surveillance company. Sold to Bahrain, Ethiopia, Egypt, Turkey. €5.04M contract to Turkey’s intelligence without export authorization, routed through Bulgarian shell company. Munich prosecutor raided offices (October 2020), indicted four managers (May 2023). FinFisher filed insolvency March 2022, dissolved.


NSO / Pegasus — Loss of Control

Rogue employee (2018): Former senior programmer (hired Nov 2017, fired April 2018) stole Pegasus source code on USB drive, attempted to sell on dark web for $50 million. Prospective buyer informed NSO. Employee arrested June 5, 2018.

WhatsApp verdict (May 2025): Jury awarded $167.3M in punitive damages + $444,719 compensatory. On appeal a judge cut the punitive award to roughly $4M (capped at 9x the compensatory) but left the permanent injunction against targeting WhatsApp in place; NSO is appealing, and its controlling stake was acquired by US investors in 2025.

Citizen Lab systematic exposure: Since 2016, identified 130+ targets in 45+ countries. Forced repeated takedowns of Pegasus front-end servers.


OPM — The Counterintelligence Catastrophe

21.5M SF-86 forms: family members, roommates, foreign contacts, psychological evaluations, financial history, substance abuse, affairs. Fingerprints for 5.6M. Attributed to Jiangsu State Security Department (MSS).

CIA pulled officers from Beijing. FBI Director Comey: “a treasure trove of information about everybody who has worked for the United States government.” Former CIA Director Hayden: damage would last at least 40 years. House Oversight: “The intelligence and counterintelligence value cannot be overstated, nor will it ever be fully known.”

No DOJ indictment filed for OPM specifically.


Cellebrite Compromised

2023 leak: 1.7TB of Cellebrite data + 103GB of MSAB data dumped by hacktivists via DDoSecrets. Full UFED suite, Physical Analyzer, license tools.

2021 Signal counterattack: Moxie Marlinspike obtained a Cellebrite kit, found it used FFmpeg DLLs from 2012 with 100+ unpatched vulnerabilities. A specially formatted file on any scanned phone could execute arbitrary code on the Cellebrite machine — modifying all past and future reports on all devices, potentially invalidating forensic evidence in court.


Juniper / Dual EC DRBG — The Backdoor of a Backdoor (2015)

December 2015: Juniper disclosed “unauthorized code” in ScreenOS for NetScreen firewalls. VPN encryption relied on Dual EC DRBG — an algorithm with a known NSA-designed backdoor (documented since 2007). Juniper adopted it as far back as 2008. In 2012, an unknown third party (suspected China per Bloomberg) modified the parameters to give themselves access instead of the NSA.

The NSA’s own backdoor was backdoored.

Congressional inquiry: NSA told Wyden’s staff in 2018 there was a “lessons learned” report, then claimed it could not locate the document.

The case for lawful access (steelman)

These portals and tools exist because lawful process is real: warrants compel data, forensic unlocks solve crimes, and the “going dark” problem — investigators locked out of evidence — is genuine. The dossier’s argument is not that the capability shouldn’t exist; it is that a capability built for lawful access is, by construction, an abuse surface when the access control is one password, the oversight is dormant, or the vendor sells to a regime that plants spyware with it.

Get updates on the Evil Robots series

Newsletter essays on AI escape, deception, and the humans who built them.