Google said it shut down a hacking group in January but didn't disclose that it was an active counter-terrorism operation by a US ally, raising ethical concerns
The decision to block an “expert” level cyberattack has caused controversy inside Google after it emerged that the hackers in question were working for a US ally. Tweets: @normative , @howelloneill , @brianfagioli , @josephfcox , @josephfcox , @techreview , @martellemichael , @b_fung , @chicagocyber , @cyberevitas , and @howelloneill Tweets: Julian Sanchez / @normative : Better headline: Google fixed security vulnerabilities, like they're supposed to, inconveniencing government-sponsored hackers. https://www.technologyreview.com/ ... Patrick Howell O'Neill / @howelloneill : New: Google recently spotted a mysterious hacking group rapidly using 11 0-day exploits. Google didn't share who was behind the attacks or who was targeted. In fact, it was a Western democracy actively targeting terrorists. https://www.technologyreview.com/ ... Brian Fagioli / @brianfagioli : @Techmeme @HowellONeill This is quite an interesting conundrum. Ultimately, Google did the right thing. You can't ignore vulnerabilities that impact everyone only because it's being exploited in one instance to fight terror. Joseph Cox / @josephfcox : Google reportedly stopped a hacking operation that was actually a Western democracy targeting terrorist devices, raising alarm bells inside Google and governments https://www.technologyreview.com/ ... Joseph Cox / @josephfcox : According to the report, Google knew who the hackers were (a Western democracy) and knew who the targets were (terrorists) https://www.technologyreview.com/ ... https://twitter.com/... @techreview : Google blocked an “expert” level cyberattack recently... except we have learned that the hackers in question were actually Western government operatives actively conducting a counter-terrorism operation. https://www.technologyreview.com/ ... Michael Martelle / @martellemichael : “How one treats intelligence activity or law enforcement activity driven under democratic oversight within a lawfully elected representative government is very different from that of an authoritarian regime.” https://twitter.com/... Brian Fung / @b_fung : When Google shut down a hacking operation recently, @techreview reports, the company did not disclose that the hackers were linked to a US ally — raising questions about western companies' relationships with governments viewed as “friendly”: https://www.technologyreview.com/ ... Yoshi / @chicagocyber : Well written piece on some of the complex discussions around disclosing “friendly” cyber operations. https://twitter.com/... Jade Parker / @cyberevitas : Rule 1 is a foundational rule for a reason. There are no exceptions. Red, blue, or green, public or private sector, high-end or low-budget tools: don't get caught. https://twitter.com/... Patrick Howell O'Neill / @howelloneill : Google's thinking comes down to this: Even when it's a Western government exploiting vulnerabilities today, they will eventually be used by others, and so the right choice is always to fix the flaws today. https://www.technologyreview.com/ ...
Context & Ripple Effects
Google's 27-person Threat Analysis Group, built to track 200+ hacker groups mostly tied to US adversaries, is designed around a clean assumption: patching what its analysts find serves users and hurts hostile states. This story breaks that assumption — the 'expert' level attack Google blocked in January was running on behalf of a US ally's counter-terrorism operation, and Google disclosed the takedown without saying whose operation it disrupted.
That lands in a company with a documented history of nondisclosure dilemmas: the Google+ bug kept quiet from 2015 to mid-2018 over fear of blowback, and the Project Zero dispute with Apple over how vulnerability disclosures shape public perception. The difference here is direction — this time the ethical question inside Google isn't whether to disclose, but whether disclosing at all was itself a political act against an allied government.
First-order effects
- The US ally loses an active cyber-operation mid-campaign: the vulnerabilities its hackers were exploiting get patched and publicized, burning capability it had invested in.
- Google employees and security leadership now face an internal governance question — whether TAG's mandate should include advance coordination with friendly governments before neutralizing their operations.
Second-order effects
- Allied governments that quietly rely on commercial platforms' infrastructure have fresh reason to distrust unilateral vendor action, pressuring Google toward formal notification channels or deconfliction protocols with intelligence partners.
- The disclosure norms debated since the Apple–Project Zero clash now apply in reverse: vendors must weigh not just user safety but the diplomatic cost of exposing an ally's tradecraft, which rivals like Microsoft will watch closely as they run equivalent threat-intel units.
Third-order effects
- If patching decisions routinely intersect with state-sponsored operations, platform security teams become de facto participants in cyber-geopolitics — and governments will seek standing arrangements with them, formalizing what has so far been ad hoc.
- This points toward codified rules for how platforms handle operations by friendly versus hostile states, echoing the accountability gaps already flagged in coverage of US companies building surveillance tools used for human-rights violations.
The trend: Platform-level security decisions are hardening into instruments of cyber-statecraft, forcing tech firms to choose between user protection and alignment with allied government operations.