Inside Google's 27-person in-house counterespionage team, the Threat Analysis Group, which tracks 200+ hacker groups, many of which are linked to US adversaries
Google likely has 'the most useful data set available to any private company for tracking state adversaries and intelligence services,' an expert says Tweets: @shanehuntley , @wsj , @bobmcmillan , and @alexstamos Tweets: Shane Huntley / @shanehuntley : Profile of my team and their work in WSJ today: http://www.wsj.com/...Currently hiring in Silicon Valley and Zurich, and especially looking for a strong manager/leader for the intel analysis folk in Sunnyvale. DM me. @wsj : Inside the team at Google that battles hackers, using Google's own data to identify and fend off state adversaries and intelligence services http://www.wsj.com/... Robert McMillan / @bobmcmillan : I interviewed Google's @ShaneHuntley and learned about the Threat Analysis Group that he runs there. He was hired just after the Chinese broke into Google and has led company's pushback against nations-state activity. http://www.wsj.com/... Alex Stamos / @alexstamos : Shane's team is excellent, and this story helps highlight the under-discussed challenges with having private companies act as pseudo- governments. In this case, running small intelligence agencies. http://twitter.com/...
Context & Ripple Effects
Google's Threat Analysis Group is the most developed example yet of a private company running counterintelligence at nation-state scale: 27 people tracking 200+ groups off Google's own telemetry, which one expert calls the most useful private-sector data set on state adversaries. It is not alone — Microsoft operates a parallel Threat Intelligence Center with dozens of analysts naming roughly 70 state-sponsored groups, so the WSJ profile lands mid-race between the two platforms.
The team's remit keeps pulling it toward political terrain. Its report on 12+ state-sponsored groups exploiting COVID-19 showed how its findings double as public diplomacy, while its later, undisclosed takedown of an operation run by a US ally raised exactly the accountability questions a corporate spy shop invites — all against a backdrop of internal employee rebellion over Google's military work.
First-order effects
- Google is scaling the unit now — hiring in Silicon Valley and Zurich and recruiting a manager for the Sunnyvale intel-analysis team — meaning headcount and leadership structure change immediately.
- Every named customer of Gmail, Android, and Chrome gets earlier warning against state-linked phishing and espionage campaigns identified from Google's own network data.
Second-order effects
- Microsoft's larger-but-similar unit turns threat-intel publishing into a competitive signal between the two cloud-and-platform rivals, pressuring each to name more groups and disclose faster.
- Government partners gain a de facto early-warning feed they don't control, while adversaries like the Chinese crews profiled in related coverage adapt by leaning harder on private-sector hackers to blur attribution.
Third-order effects
- If the pattern holds, a handful of platform companies become standing intelligence agencies in function if not name — with disclosure decisions (like Google's silence on the ally-run operation) made by corporate policy rather than any public mandate.
- That gap sets up a structural fight over norms: who authorizes a private firm to act against state operations, and whether governments formalize or regulate these units as their intelligence value grows.
The trend: Big-platform security teams are evolving into quasi-state intelligence services whose scale, data advantage, and disclosure choices increasingly shape national-security outcomes faster than governments can.