The CIA’s Secret Star Wars Fan Blog
Quick Overview
The CIA operated hundreds of poorly designed, easily discoverable fake websites from 2004 to 2013 to communicate with informants, primarily in Iran, leading to a catastrophic compromise of US intelligence infrastructure and the capture or death of 18-20 agents by hostile governments like Iran and China.
Summary
Key Points: From 2004 to 2013, the CIA used hundreds of fake websites, including a Star Wars fan page and a classic car site, to communicate covertly with informants. These websites were designed with significant security flaws, including easily accessible source code revealing messaging functions and sequential IP addresses. Iran and China successfully compromised the CIA's covert communication system, with Iran reportedly using Google to identify the spy sites. The compromise led to the capture or killing of 18 to 20 CIA sources in China alone, effectively unraveling years of intelligence building. A defense contractor warned the CIA about a "massive intelligence failure" related to these communications as early as 2008, five years before informants began disappearing. The CIA provided minimal training to informants on avoiding detection or covert contact methods, contributing to their exposure.
Context: The United States Central Intelligence Agency (CIA) faced significant challenges in gathering intelligence from hostile territories like Iran, especially after the 1979-1980 hostage crisis severed diplomatic ties. To circumvent these difficulties and monitor Iran's nuclear program, the CIA developed a network of covert websites for secure communication with informants.
Detailed Analysis
From 2004 to 2013, the CIA established a network of nearly 900 fake websites, each assigned to a single informant, to facilitate covert communication, particularly with sources in Iran regarding its nuclear program. These sites, disguised as innocuous fan pages (e.g., Star Wars, Johnny Carson) or niche interest sites (e.g., rug auctions, car news, soccer), allowed informants to pass intelligence via hidden messaging functions. However, the websites were riddled with severe security vulnerabilities. Their source code explicitly named secret functions like "password," "message," and "compose," making them easily identifiable. Furthermore, the CIA purchased IP addresses in sequential blocks, allowing hostile intelligence agencies like Iran and China to discover entire networks of spy sites by simply changing the last digit of a known IP address. This catastrophic design flaw, which a defense contractor warned about as early as 2008, led to the systematic dismantling of US spying operations. By 2013, China alone had killed or imprisoned 18 to 20 CIA sources, effectively crippling the US intelligence network built over years. The CIA's failure to provide adequate counter-detection training to its informants further exacerbated the compromise, highlighting a significant intelligence failure.