An investigation shows the CIA failed to secure its messaging system used by Iranian spies, often hidden within websites, leading to capture, torture, and death
Earlier reporting described how Iranian investigators allegedly used Google searches to uncover a cluster of CIA-linked websites, compromising a broader communications network. The new investigation ties that operational failure to the exposure of individual sources, including Gholamreza Hosseini.
Related reporting of a separate compromise of CIA communications in China makes the Iran account more consequential: the issue was not merely one exposed site, but the resilience of a source-communications model across hostile environments.
First-order effects
Iranian operatives were able to identify CIA-linked sources using the website-hidden messaging system; Hosseini was captured while attempting to leave Iran and was subsequently tortured and killed.
The CIA’s affected Iranian network lost the security that protected its sources’ identities, turning a communications channel into an exposure point.
Second-order effects
The reported wider-network compromise forces the CIA to treat linked web infrastructure as a common vulnerability rather than an isolated failure, increasing the operational cost of maintaining source contact.
Iran gained intelligence and counterintelligence value from captured sources, while the CIA’s ability to recruit and retain Iranian assets was directly damaged by the system’s exposure.
Third-order effects
Taken together with the China reporting, the case points to a structural tradecraft risk: reusable or discoverable digital communications infrastructure can create correlated failures across geographically separate human-intelligence networks.
Intelligence services are likely to place greater weight on compartmentalized, independently auditable communications channels, because a single design weakness can endanger both sources and entire networks.
The trend: Human-intelligence operations are becoming more dependent on digital tradecraft whose shared infrastructure can turn one technical weakness into network-wide exposure.
We interviewed six Iranians who had worked with the CIA as spies and informants and got caught. A Reuters investigation found CIA negligence likely led to their capture. https://www.reuters.com/...
NEW REPORT today from @Reuters @JoelSchectman providing more detail about fatal flaws in the CIA's defunct communications network. Iran and China compromised the network in 2011, and killed dozens of CIA assets https://www.reuters.com/...
The CIA network reportedly consisted of benign looking websites with a hidden communications functionality, used by assets around the world to communicate back and forth with their agency handlers. https://twitter.com/...
The CIA mass-produced “secret messaging” websites — normal-looking websites that foreign assets overseas could use to communicate. But the websites were utter garbage. https://twitter.com/...
NEW: Read statement by director @rondeibert on the fatal flaws found by senior researcher @billmarczak in a defunct CIA covert communications system. We are not publishing the full findings at this time pending responsible disclosure process... https://citizenlab.ca/...
This was one of the websites the CIA used to hide its secret messaging system. (Iran eventually uncovered it and informed China.) It's so sloppily made that the Arabic writing is backwards and disconnected. https://www.reuters.com/... https://twitter.com/...
The CIA “pressures, even deceives, Iranians hoping to secure US visas into providing intel...After an Iranian drops off an application, diplomatic officers are instructed to examine whether their employment history or family ties could make them valuable.” https://www.reuters.com…
Brutal and long time coming deep dive into how Iran rolled up a CIA network due to sheer sloppiness. At same time, Hezbollah was doing same in Beirut as the agency kept meeting sources in the same places aka Pizza Hut in Rouche and ended up losing everyone https://www.reuters.com…
2/ One spy recounted receiving the covert messaging system first reported by @JennaMC_Laugh & @zachsdorfman. We found his soccer news site in an internet archive and asked two cyberanalysts review the system. @bozorgmehr https://twitter.com/...
My Special Report with @joel_schectman shows how the CIA failed its spies in Iran. I explain parts of the story in this thread: https://www.reuters.com/...
WOW: this Reuters investigation reveals incredibly sloppy and incompetent work by the CIA in creating a web comms infrastructure for informants in Iran. Opsec failures like using similar domain names, not obscuring the code, sequential IP addresses 😱🙈 https://www.reuters.com/... …
“Hosseini was the victim of CIA negligence, a year-long Reuters investigation into the agency's handling of its informants found. A faulty CIA covert communications system made it easy for Iranian intelligence to identify and capture him”. https://www.reuters.com/...
3/ @billmarczak & @thezedwards easily discovered the messaging element and links to hundreds of other CIA sites, which had been easy for the Iranians. https://twitter.com/...
What do these 4 websites & hundreds more have in common? 👀They were built by CIA to support encrypted messaging sessions between spies in the field and their U.S. handlers. Reuters is out today with a year-long investigation into the network @ https://www.reuters.com/... 🔊🚨🌩️ ⚖️ …
Another excellent investigation by Reuters, this time on C.I.A. negligence, leaving informants on their own, after setting up a faulty communication - which Reuters was able to locate! - system in the first place. By @joel_schectman and @bozorgmehr https://www.reuters.com/... htt…
“Such aggressive steps by the CIA sometimes put average Iranians in danger with little prospect of gaining critical intelligence. When these men were caught, the agency provided no assistance to the informants or their families, even years later” https://www.reuters.com/...
Wow, this is sloppy stuff - spies were told to visit a website called https://iraniangoals.com/ (a bit on the nose) and type a ‘secret’ password into the search field... which was called ‘password’ in the HTML. https://twitter.com/...