Security Industry Capture & Surveillance Vendors — Research Reference
AI safety teams dissolved when they conflicted with product velocity; surveillance vendors selling to authoritarian regimes; security vendors captured or owned by state actors. Routed from the security-charlatans corpus.
Contents
Routed from the Security Charlatans & Institutional Failures corpus during stream separation: the charlatan and public-shaming record lives at troll.fan; the capture and surveillance analysis lives here. Entries below are ported verbatim from that corpus.
AI Safety Theater
Every major tech company created an AI ethics/safety team, then dissolved it when it conflicted with product velocity.
Google (Ethical AI)
Status: Still operating
Hired Dr. Timnit Gebru as co-lead of its Ethical AI team, then fired her on December 3, 2020, after she co-authored a paper on risks of large language models (“stochastic parrots”) that conflicted with Google’s business interests. Jeff Dean claimed the paper “didn’t meet our bar for publication.” Gebru was cut off from her corporate email before returning from vacation. Over 1,400 Google staff and 1,900 external supporters signed a protest letter. The firing demonstrated that “ethical AI” was a PR function, not an engineering constraint — the team existed to provide cover, not to actually constrain product decisions.
Sources:
- MIT Technology Review — “We read the paper that forced Timnit Gebru out of Google”
- Washington Post — “Google hired Timnit Gebru to be an outspoken critic of unethical AI. Then she was fired for it.”
- TechCrunch — “Google’s co-lead of Ethical AI team says she was fired for sending an email”
- CNBC — “Google AI ethics team demands changes”
Microsoft (Ethics and Society)
Status: Still operating
The Ethics and Society team was cut from 30 to 7 employees in an October 2022 restructure, then the remaining 7 were eliminated entirely in March 2023 during mass layoffs — told via Zoom call. This happened while Microsoft was doubling down on its $10 billion OpenAI investment and racing to integrate GPT into every product. The team had been specifically working on identifying risks in Microsoft’s OpenAI integration. Former employees noted that Microsoft’s Office of Responsible AI published principles that product teams couldn’t operationalize: “People would look at the principles… and say, ‘I don’t know how this applies.’” The specific harm: dissolved the team responsible for translating safety principles into product design at the exact moment the company was shipping the largest AI integration in its history.
Sources:
- TechCrunch — “Microsoft lays off an ethical AI team as it doubles down on OpenAI”
- Popular Science — “Microsoft axed AI Ethics and Society team”
- Fortune — “Microsoft’s A.I. ethics layoffs send a worrying signal”
- TechTarget — “Reasons for and effects of Microsoft cutting AI ethics unit”
Meta (Responsible AI)
Status: Still operating
Launched the Responsible AI team in 2019. Cut its Responsible Innovation team in September 2022. Then disbanded the Responsible AI division entirely in November 2023, during Zuckerberg’s “year of efficiency.” Most employees were reassigned to the Generative AI arm — the unit whose output the RAI team was supposed to be auditing. The team was dissolved while Meta was racing to compete with OpenAI and Google in the LLM space. The specific harm: a company with 3+ billion users across its platforms eliminated the only internal team responsible for ensuring its AI products were built safely, then reassigned those people to work on the products they were supposed to be scrutinizing.
Sources:
- CNBC — “Facebook-parent Meta breaks up its Responsible AI team”
- The Register — “Meta scraps its Responsible AI team in latest reshuffle”
- TechTarget — “Possible reasons for Meta disbanding its responsible AI team”
- Interesting Engineering — “Meta dissolves its ethical AI watchdog team”
OpenAI (Safety Teams)
Status: Still operating
In May 2024, both co-leaders of the Superalignment team resigned within 24 hours. Ilya Sutskever (co-founder, board member who led the brief Altman firing in November 2023) left for a personal project. Jan Leike wrote publicly that “safety culture and processes have taken a backseat to shiny products” and that the Superalignment team was “sailing against the wind” and chronically under-resourced. The team was dissolved entirely, one year after its creation. In October 2024, Miles Brundage (head advisor for AGI Readiness) also resigned. In February 2026, OpenAI disbanded its Mission Alignment team after just 16 months. The pattern: OpenAI creates safety teams, starves them of resources, then dissolves them when leadership departs. The specific harm: the company building the most powerful AI systems in the world has demonstrated through repeated action that safety is a PR function subordinate to product velocity.
Sources:
- CNBC — “OpenAI dissolves Superalignment AI safety team”
- Fortune — “Top OpenAI researcher resigns, saying company prioritized ‘shiny products’”
- CNBC — “OpenAI disbands another safety team, AGI Readiness head resigns”
- WinBuzzer — “OpenAI Disbands Its Mission Alignment Team After Just 16 Months”
- Center for AI Policy — “OpenAI Safety Team’s Departure is a Fire Alarm”
- LessWrong — “Ilya Sutskever and Jan Leike resign from OpenAI”
Surveillance Vendors
Surveillance tech sold to authoritarian regimes. Pegasus spyware. The Khashoggi connection.
NSO Group / Hacking Team / Cellebrite
Status: Under sanctions / Hacked / Still operating
These three companies share a business model: sell surveillance capabilities to whoever pays, disclaim responsibility for what buyers do, and insist they comply with all applicable export controls — a defense that becomes awkward when the buyers include Sudan, Ethiopia, Saudi Arabia, Kazakhstan, and Azerbaijan. Hacking Team was itself hacked in July 2015, with 400GB of internal data published; the dump revealed active contracts with Sudan despite UN arms embargo restrictions. Italian export authorities revoked Hacking Team’s global license. NSO Group’s Pegasus spyware was found on the iPhone of Omar Abdulaziz, a confidante of Washington Post columnist Jamal Khashoggi, in the months before Khashoggi’s murder inside the Saudi consulate in Istanbul in October 2018. The Washington Post’s 2021 Pegasus Project investigation (17 media organizations, Amnesty International forensics) found Pegasus on phones of heads of state, journalists, and human rights lawyers. The U.S. Commerce Department added NSO to its Entity List in November 2021. Apple sued NSO in November 2021. Cellebrite rounds out the roster: in April 2021, Signal’s Moxie Marlinspike demonstrated that Cellebrite’s own software contained unpatched FFmpeg libraries from 2012 with over a hundred CVEs, and that a crafted file on a seized device could execute arbitrary code on the Cellebrite machine — potentially corrupting evidence in every case the examiner had ever worked on.
Sources:
- The Intercept — “Hacking Team Sells Spyware to Repressive Countries”
- Privacy International — “Hacking Team’s global license revoked”
- Washington Post — Pegasus Project
- Apple complaint (November 2021)
- CyberScoop — “Commerce Department blacklists NSO Group”
- Signal blog — Cellebrite vulnerabilities
- Amnesty International — “The Pegasus Project”
- Stanford CIS — Signal/Cellebrite legal analysis
- Schneier on Security — Cellebrite vulnerabilities
- CyberScoop — Cellebrite/Signal
State Capture and Foreign Espionage in Security Vendors
Security vendors whose record is state capture or foreign-intelligence compromise rather than grift.
RSA Security / Dual_EC_DRBG
Status: Still operating
In 2004, RSA Security accepted a $10 million contract from the NSA to make Dual_EC_DRBG — a random number generator with a suspected backdoor — the default in BSAFE, RSA’s flagship cryptographic toolkit deployed across financial, medical, government, and SSL/TLS infrastructure globally. In 2007, Microsoft researchers publicly demonstrated the backdoor mechanism. RSA did not change the default. In December 2013, Edward Snowden’s documents confirmed Dual_EC_DRBG was an intentional NSA backdoor (Bullrun program), and Reuters reported the $10 million figure. RSA categorically denied knowing the algorithm was backdoored but did not deny the $10 million contract. Eleven speakers cancelled RSA Conference 2014 appearances, including Mikko Hyppönen (F-Secure), Christopher Soghoian (ACLU), and Chris Palmer and Adam Langley (Google). TrustyCon formed as an alternative conference, organized by DEF CON/EFF/iSEC Partners, with all proceeds to EFF. RSA Conference 2014 attendance: a record 24,000+. The boycott had zero measurable effect on the vendor floor. Matthew Green’s December 2017 analysis uncovered “Extended Random” — a second, separate mechanism that further weakened the backdoored generator. The specific harm: the company whose name is literally a cryptographic algorithm sold the integrity of its cryptographic products to the NSA for $10 million, left the backdoor in place for six years after public demonstration, and faced no commercial consequences.
Sources:
- The Register — “NSA paid RSA $10 million”
- EFF — “After NSA Backdoors, Security Experts Leave RSA Conference” / TrustyCon
- Dark Reading — “9 Security Experts Boycott RSA Conference”
- Washington Post — RSA Conference boycott
- Wikipedia — Dual_EC_DRBG
- Matthew Green — “Extended Random” second backdoor (2017)
Kaspersky Lab
Status: Banned from US sales 2024
Eugene Kaspersky attended the Technical Faculty of the KGB Higher School at age 16, graduated in 1987, and subsequently served as a software engineer for Soviet military intelligence — a biography Kaspersky Lab acknowledges while calling concern about it “Cold War paranoia.” In 2017, the Wall Street Journal reported that Russian government hackers had used Kaspersky antivirus software to identify and exfiltrate NSA source code and offensive tools from a contractor’s home computer — the antivirus’s legitimate file-scanning functionality serving as a search engine for classified material. Israeli intelligence, which had hacked into Kaspersky’s own network, watched this in real time and tipped the NSA. DHS banned Kaspersky from all federal civilian agencies in September 2017. The Biden administration completed the eviction in June 2024, using Commerce Department authority to ban all U.S. sales and software updates effective September 29, 2024 — the first time the U.S. government has used this authority to ban a foreign software product entirely. Kaspersky denies all of it, which is what you would say whether or not it were true.
Sources:
- Washington Post — “Israel hacked Kaspersky, then tipped the NSA”
- CNBC — “Israeli spies found Russians using Kaspersky”
- Wikipedia (sourced)
- CNN — “Biden administration bans Kaspersky software”
- Lawfare — “Kaspersky finally evicted from the US”
Sophos
Status: Still operating
Sophos’s “Pacific Rim” report, released October 2024, is the company’s own account of a five-year campaign in which Chinese state-sponsored hackers — linked to Volt Typhoon, APT31, and APT41 — systematically exploited Sophos firewall products to penetrate nuclear energy suppliers, military hospitals, airports, and government ministries across South and Southeast Asia, Europe, and the United States. The opening salvo was CVE-2020-12271, a pre-authentication SQL injection in the XG Firewall requiring zero credentials to exploit, used to deploy the Asnarök Trojan; the attack origin traced to Chengdu. This is not a story of rapid detection — Sophos discovered the attackers had developed bootkit malware designed to survive factory resets on its own devices only by planting surveillance code on its own infected equipment. The five-year timeline encompasses multiple vulnerability waves, with attackers graduating from mass exploitation to precision targeting of critical infrastructure. The mockery is not that Sophos got attacked — everyone does — but that the attackers had five years to work before the story became public.
Sources:
- Sophos — “Pacific Rim” report
- Sophos — Pacific Rim timeline
- Bleeping Computer — “Sophos reveals 5-year battle with Chinese hackers”
- Lawfare — “Sophos’s Five-Year-Long Cyber Knife Fight”
Nortel Networks
Status: Bankrupt 2009
Hackers working from China had access to Nortel’s networks from at least 2000 through the company’s bankruptcy in 2009 — nearly a decade of uninterrupted infiltration. Seven passwords were stolen from top executives, including CEO Frank Dunn, whose account was used to download 779 documents in a single seven-hour session from a Shanghai IP address. The Wall Street Journal reported that Nortel “did nothing from a security standpoint” beyond resetting the seven passwords. Management was “mostly disinterested in the investigation” and more focused on annual profits. Once North America’s largest telephone equipment maker with over 32,000 employees, Nortel filed for bankruptcy in January 2009. The specific harm: a telecommunications company responsible for critical infrastructure across North America was comprehensively owned by a foreign state actor for a decade, and management’s response to discovering the intrusion was to change seven passwords and move on. The stolen intellectual property is widely believed to have benefited Chinese competitors including Huawei.
Sources:
- Washington Post — “Report: Chinese hackers breach Nortel networks”
- Global News — “Inside the Chinese military attack on Nortel”
- IEEE Spectrum — “Nortel Penetrated by Hackers Since at Least 2000”
- DataBreachToday — “Nortel Breach Started in 2000”
- Naked Security/Sophos — “Nortel veteran claims Chinese hackers stole its data for nearly 10 years”
- NATO Association of Canada — “Huawei: The Dragon that Caught Nortel off Guard”