Leaked documents reveal plans for extensive Russian influence campaign in Israel

2023 Israeli judicial reform protestsLEAKED INFORMATION PUBLISHED BY leading German media outlets has revealed Russia’s plans for an influence campaign targeting Israel. The information was leaked earlier this month by the German newspaper Süddeutsche Zeitung and German television stations Norddeutscher Rundfunk (NDR) and Westdeutscher Rundfunk (WDR), as well as by Israeli news outlets. It allegedly came from Social Design Agency (SDA), a Moscow-based firm hired by the Kremlin, which operates in Israel and several countries in the West.

Founded in 2017, the SDA is reportedly one of a host of firms and organizations that are collaborating with Russian intelligence in its efforts to influence public opinion worldwide. Earlier this year, the United States imposed sanctions on SDA, “for providing services to the government of Russia in connection with a foreign malign influence campaign”. The SDA’s founder is Ilya Gambashidze, who is said to be in direct contact with Russian President Vladimir Putin and other Kremlin officials.

Israel has been a central target of SDA’s Russian influence campaign. The country’s internal situation, with mass demonstrations against the legal reform is “perfect for launching a campaign to influence public opinion”, an SDA document from 2023 reads. The document accurately describes the political and social situation in Israel and names a number of influential Russian expatriates whose activities should be monitored.

According to the leaked documents, the purpose of the planned campaign was to raise support for Russia in its war against Ukraine, and strengthen the proportion of Israelis who espouse anti-Ukrainian sentiments. Another central goal was to ensure that no party in the Knesset —the IsraeliQ Quote parliament— would support a possible transfer of military aid to Ukraine.

From the documents, it appears that the conclusions formulated by the SDA were infused into around 50 cartoons distributed every month on social networks, around 20 fictitious articles appearing on websites pretending to be legitimate, and many reactions on various social networks. Among other things, the company distributed through paid ads on Facebook cartoons showing Ukrainian President Volodymyr Zelensky burning the Israeli flag, as well as cartoons accusing Israeli leftists of supporting Hamas.

One of the main revelations of the recent leaks is that the Arab community in Israel constitutes a target of the Russian influence campaign. For example, a fake Arabic-language article that was circulated online claimed that Israel did not have in its possession enough precision weapons, because it had given them to Ukraine. The article went on to claim that the lack of such weapons would lead to failures on the battlefield. “The good news should be heard by all believers living under occupation”, the article states. “The policy of the occupation government will soon lead to its defeat. We will wait for a spark to ignite our war of liberation, in which the entire Muslim world will support us”. The purpose of the article appears to be to prompt the Israeli-Arab population to turn against the Israeli government based on Israel’s alleged weakness, and to support Israel’s enemies. Read more of this post

Spy’s release by higher court shows Austria is unable to find its intelligence footing

Egisto OttON JUNE 26, THE longwinded case of Austria’s counter intelligence failure regarding a possible inside threat took yet another —quite surprising— turn: the state court of Vienna (Landesgericht Wien) released from pre-trial detention (Untersuchungshaft) Egisto Ott, a former member of the Federal Office for the Protection of the Constitution and Counterterrorism (BVT) —Austria’s now-dissolved domestic intelligence agency. Ott, who was accused of spying against Austria, had been arrested (again) at the end of March on suspicion of obtaining classified information for which he could provide no reason, as well as for presumably selling it. Among the suspected recipients of the classified information were Russian assets and —more or less directly— Russian intelligence.

However, the three-judge panel called to decide on the detention complaint came to the conclusion that, while there remains a strong suspicion (dringender Tatverdacht) against Ott, the reasons for his further detention were not sufficiently given. In the judges’ view, all activities that could carry a pre-trial detention were committed before Ott was arrested and released for the first time in 2021. Back then, Ott had also been released after a short detention, following a decision by the same court. Briefly summarized, in 2021 the Landesgericht concluded that Ott could no longer spy against Austria as he did not have access to classified information, having been removed from the domestic intelligence agency years earlier. Additionally, since the BVT was in the process of reorganization and reformation at that point, the judges deemed the possibility of further criminal behavior by Ott to be unrealistic.

The recent assessment that Ott did not conduct additional punishable offences following his first release is surprising, since the prosecutor alleged —with a certain undertone directed against the initial decision to release Ott, which can be noted in the arrest warrant— that Ott had resumed his information-gathering and handling activities immediately upon being set free in 2021. Specifically, Ott is accused of having unlawfully retrieved data from the Central Register of Residents (Zentrales Melderegister) on March 24 of that year and then passing it on. The information accessed by Ott concerned the Bulgarian investigative journalist Christo Grozev, who was living in Austria at the time. Consequently, Grozev had to leave Vienna, since his life was deemed to be in severe danger. Today, whenever Grozev returns to Austria to visit members of his family who remain there, he has to do so under heavy protection by the Austrian authorities.

Between June and November 2022, when Ott had been released from his first pre-trial detention, there was also an alleged transfer to Russia of three mobile phones, or their data, as well as a highly-encrypted SINA-workstation laptop. However, the judges of the Landesgericht concluded that, while information or intelligence provided to foreign services does not have to be secret to constitute criminal espionage against Austria, “concrete and vital interests of Austria” have to be violated by such a transfer. The judges did not deem that the evidence furnished by the prosecutor met their criteria. Die Presse, Austria’s ‘newspaper of record’, published a detailed explanation of the court decision. Read more of this post

Profile of Tang Yuanjun, alleged asset for Chinese intelligence 2018-2023

Yuanjun TangTANG YUANJUN WAS ARRESTED by the United States Federal Bureau of Investigation (FBI) in August 2024. He allegedly worked as a Chinese Ministry of State Security (MSS) asset between 2018 and 2023. He reported on the following categories of information that were of interest to the MSS:

  • Prominent U.S.-based Chinese democracy activists and dissidents.
  • US Chinese-American Member of Congress Xiong Yan, from New York.
  • Immigration claims from dissidents wanting to leave China for the US.

According to the US Department of Justice (DoJ), Tang expressed his desire to see his aging family in China. A prominent dissident such as Tang would not be able to travel to China without being arrested, unless his travel had been approved by authorities. An acquaintance helped him establish secure online contact with the MSS. After being recruited, Tang reported to the MSS using an email account, encrypted chats, text messages and audio and video calls. Tang helped the MSS infiltrate a group chat on WhatsApp; used by numerous People’s Republic of China (PRC) dissidents and pro-democracy activists to communicate about pro-democracy issues and express criticism of the PRC government. In fact, this was what users called a “super group”. It is a group that consists of many other groups. Members could not even identify who was the sponsor of the group chats [1].

In addition, Tang reportedly video-recorded a June 2020 Zoom discussion commemorating the anniversary of the Tiananmen Square massacre in the PRC. The Zoom online discussion was led by Zhou Fengsuo, Director of the June 4th Memorial Museum in New York City and a leading advocate for democracy in China. The Ministry of Public Security also infiltrated these discussions with the assistance of Zoom China and US based employees [2].

Tang was Secretary General of the overseas headquarters of the China Democratic Party United Headquarters in New York City. This non-profit organization assists mainland Chinese dissidents in immigration and asylum applications for the US. Tang allegedly provided information on these individuals to the MSS [3]. Tang also allegedly identified ten immigration attorneys to support MSS efforts to place assets in the US. Other dissident organizations in New York and Los Angeles provide similar visa application services to generate income.

In 2022, reportedly Tang met with the MSS in Changchun City, Jilin Province, China, where an officer installed a software on Tang’s phone which Tang believed to be a “bug” that caused all photographs and videos captured on the phone to be transmitted to the MSS. In his role as leading democracy advocate Tang encouraged dissidents to attend protests in Manhattan and Washington DC. He used the compromised phone to take photographs of the events. The Chinese Communist Party (CCP) then used the photographs as evidence against overseas dissidents. Read more of this post

Is Israel preparing to carry out intelligence operations on US soil?

Amichai ChikliSEVERAL WEEKS AGO, ISRAEL’S Minister of Diaspora Affairs, Amichai Chikli, reportedly met with the chief executive officer (CEO) of Israeli private intelligence company Black Cube. According to Israeli newspaper The Marker, the purpose of the alleged meeting was to propose an intelligence operation to be carried out on American soil by Black Cube, on behalf of the Israeli government. The intelligence operation would allegedly target a United States-based organization that stands at the forefront of demonstrations against Israel on university campuses in the United States —demonstrations that the state of Israel views as anti-Semitic.

According to The Marker report, the alleged meeting between Minister Chikli and the CEO of Black Cube, Dan Zorla, took place in a private residence in Herzliya near Tel Aviv. Minister Chikli was personally involved in the discussions with Black Cube, with the understanding that intelligence operations carried out by the firm on American soil would not be officially attributed to the State of Israel. However, it is unclear whether such intelligence operations were indeed authorized to proceed.

The organization against which Chikli reportedly asked Black Cube to target is “Students for Justice in Palestine”. The group has staged numerous demonstrations on university campuses across the United States since the outbreak of the Israel-Hamas war last October.

The alleged use of a private intelligence company against an American-based organization, whose leaders are primarily American citizens, may be perceived as a violation of American sovereignty. Such an activity could further-damage the relationship between Israel and the American government and stigmatize Israel’s image among the American public.

Following the publication of The Marker report, the Ministry of Diaspora Affairs claimed the proposal for the intelligence operation had been initiated by Black Cube and that Ministry officials ultimately rejected it. Still, at least three different sources appear to confirm the exact opposite —namely, that the spying initiative was prompted by the Ministry. Black Cube reportedly rejected it based on concerns that such a high-risk operation could damage the company’s standing with the United States government and harm its ability to do business on American soil in the future.

An official statement issued by the Ministry of Diaspora Affairs said: “Since the beginning of the war, the ministry has held meetings with dozens of organizations seeking to assist the efforts of the State of Israel in various fields. At the company’s [Black Cube’s] request, a meeting was held with the ministry’s professional echelon, and at the end of it, it was decided not to proceed with any engagement”. Read more of this post

Israel releases findings of internal probe into October 7 intelligence disaster

Hamas GazaTHE OFFICIAL INTERNAL INVESTIGATION into the performance of Israel’s Military Intelligence Directorate (MID) during the run-up to the Hamas attack of October 7, 2023, has been released. Known as The Road to War, the report addresses the central question of: how did the MID –the main military intelligence body of the Israel Defense Forces, or IDF– miss all the signs of the pending Hamas attack, and how did all the available warnings go unheeded?

To compline the report, the Intelligence Directorate of the IDF investigated how the most significant intelligence failure in the history of the State of Israel occurred, as well as how the MID analysts and other members of the intelligence community failed to notice the attack that Hamas had been planning.

According to the findings of the investigation, Hamas began planning its attack between seven and eight years ago, which means that Israeli intelligence should have been able to observe the relevant warnings as early as 2016. However, the IDF’s intelligence division missed the early signs.

It appears that the MID assumed Hamas had been deterred by Israel. There was also a prevailing assumption that the group’s military wing, led by Yahya Sinwar, had settled on improving the economic situation of Gaza Strip residents while securing its internal sovereign status in the Gaza Strip. The MID intelligence analysts were uniformly immersed in the concept that Hamas “did not want to and could not” go to war against Israel.

The main findings of the investigation are as follows: Read more of this post

South Korea’s top HUMINT agency probes potentially catastrophic data breach

North South KoreaIN A HIGHLY UNUSUAL move, authorities in Seoul have publicly acknowledged a data leak that may have resulted in the outing of a number of South Korean undercover human intelligence (HUMINT) operatives abroad. The South Korean Ministry of National Defense said on Sunday it was investigating an alleged link of highly sensitive data belonging to the Korea Defense Intelligence Command (KDIC).

Formed under American tutelage in 1946, KDIC is today considered South Korea’s most secretive intelligence agency. It operates under the Defense Intelligence Agency (DIA), which makes it part of the Ministry of National Defense’s chain of command. Unlike DIA’s civilian counterpart, the National Intelligence Service, KDIC rarely surfaces in unclassified news reporting, and it almost never issues press releases. Its operations primarily involve HUMINT activities, thus making it South Korea’s most active HUMINT-focused agency.

Predictably, KDIC’s primary intelligence target is North Korea. The agency gathers much of its intelligence on the North through an extensive network of undercover officers operating with diplomatic credentials. KDIC also handles non-official cover (NOC) operatives, who are located mostly in Asia. There have been periodic claims in the unclassified literature that some KDIC NOCs have operated inside North Korea at times –though such claims remain speculative.

On Saturday, the Seoul-headquartered Yonhap News Agency alleged that classified information relating to KDIC had been “leaked”. According to Yonhap, the leak included personally identifiable information about KDIC official and non-official cover personnel stationed abroad. The report claimed that the leak was discovered by South Korean authorities a month ago, and that the discovery had resulted in the recall of several KDIC undercover operatives serving overseas “due to concerns over their identities being exposed”.

The Yonhap report claimed that, according to an ongoing probe, the leak may have originated from a personal laptop computer belonging to a civilian KDIC employee. The employee has since claimed that the laptop had been hacked, but some investigators believe the suspect may have “intentionally left the laptop vulnerable to hacking by North Koreans”.

According to an official statement released on Sunday by the Ministry of National Defense, the case is “currently under investigation by military authorities”.

Author: Joseph Fitsanakis | Date: 29 July 2024 | Permalink

Analysis: Secret Service failed Trump because it can’t keep up with the growing threat

Trump 2016THE UNITED STATES SECRET Service is among the world’s most prestigious law enforcement agencies. Its institutional experience in protecting US presidents and presidential candidates dates to 1901. Given its high-stakes protective mission —safeguarding the executive leadership of the world’s most powerful nation— the agency has historically placed emphasis on flawlessness: it simply can’t afford to fail.

Yet it did just that on Saturday in Butler, Pennsylvania. Presidential candidate Donald Trump did not survive the attempted assassination because his Secret Service detail neutralized the threat to his safety in time. Instead he survived because the shooter, 20-year-old Thomas Matthew Crooks, from the small suburb of Bethel Park in Pittsburgh, missed. How are we to explain this abject failure by one of the world’s most venerated law enforcement agencies?

POLICING IN A DEMOCRACY

Unlike tyrannical regimes, where law enforcement is nearly omnipresent, policing functions in democratic societies are relatively limited. They rely on what can be essentially described as a numbers game. Under this model, the effectiveness of policing functions inherently rests on the assumption that the vast majority of the population will comply with legal norms voluntarily, and that it will do so most of the time.

Thus, the sustainability of law and order in democratic societies hinges, not just on the capabilities of the enforcement agencies, but significantly on the general populace’s commitment to uphold the rule of law. This tacit social contract allows law enforcement agencies to operate with a relatively small logistical footprint. It also allows police forces to focus their efforts on a relatively small number of individuals, or groups, who do not adhere to the law.

WIDESPREAD BREAKDOWN

The US has relied on this model of policing since the Civil War. However, this model tends to falter once a substantial segment of the population refuses to voluntarily adhere to legal conventions. In such a scenario, the sheer number of non-compliant individuals can overwhelm the policing system, leading to a widespread breakdown in law and order.

The US has witnessed such incidents with alarming intensity in recent years. Examples include the 2014 Bundy standoff and the 2016 occupation of the Malheur National Wildlife Refuge by armed groups of anti-government extremists. It also witnessed the —often gratuitously violent— George Floyd protests, as well as the armed occupation of the Capitol Hill neighborhood of Seattle, Washington, in 2020.

Most notably, America witnessed widespread civil disobedience on January 6, 2021, when thousands of frenzied Trump supporters stormed the US Capitol and attempted to bring an end to the Constitutional order in one of the world’s oldest democracies. In addition to exposing the fragility of American democracy, the January 6 attack drew attention to the ineffectiveness of the state’s policing functions, thus further-eroding public trust and compliance.

AMERICANS ARE EMBRACING VIOLENCE

There is no denying that Americans are viewing violence as an element of national politics with an alarming rate. Last summer, a survey conducted by the University of Chicago’s Project on Security and Threats revealed that 4.4 percent of the adult population of the US —12 million Americans— believed that violence was justified to restore Donald Trump to power. Granted, very few of those survey responders would actually be willing to act on such extreme beliefs. But even a mere 1 percent of those 12 million people who appear to endorse violence in support of Trump amounts to 120,000 individuals. That’s an enormously large number of radicalized Americans. Read more of this post

German intelligence agencies discuss ongoing espionage and hybrid challenges

Conference AgendaTHE 5TH SYMPOSIUM ON the Law of Intelligence Services (Symposium zum Recht der Nachrichtendienste) took place in Berlin, Germany, on March 21-22. In view of the public criticism that German intelligence agencies have faced in recent times, it was probably a relief for their officials to be able to talk more-or-less among themselves for once.

The event (see agenda in .pdf) was organized by the Federal Ministry of the Interior and the Federal Chancellery Office. This year’s topic was: “Intelligence Agencies and Armed Conflicts”. It included the tried and tested mix of academics —predominantly legal scholars—, practitioners and heads of various government authorities. The majority of the external experts discussed the complicated and, in Germany, arduous parliamentary procedures that would arise in the event of a war.

In view of the controls increasingly being placed on German intelligence agencies by various bodies and authorities —which were also represented at the symposium— a certain discrepancy became apparent repeatedly in the presentations: How can the German intelligence agencies react adequately and quickly to hybrid threats when these types of threat do not concern themselves with administrative-legal subtleties and parliamentary procedures? Although the concept of hybrid threats was generally taken for granted and therefore hardly discussed in terms of content, those present agreed at a minimum that disinformation is part of it. All the more worrying was the statement by one speaker who explained that there was no official definition of disinformation within the German security authorities’ legal codes.

In the discussion, the panel moderated by Center for Intelligence Service Training and Further Education (ZNAF), the common training and study location of the Federal Intelligence Service (BND) and the Federal Office for the Protection of the Constitution (BfV), clearly stood out and underscored that this relatively new institution has made a name for itself in the academic intelligence landscape since its establishment in 2019.

However, the symposium also showed that the German security bureaucracy tends to reach its limits when it comes to current developments in the unconventional domain. This was demonstrated, for example, by a speaker’s demand that hybrid risks ought to be assigned to a “state area of responsibility”. The problem, however, lies precisely in the statelessness of hybrid risks. The existing regulations are also proving to be counterproductive, in view of the challenges: there would simply be highly heterogeneous participants in the so-called Cyber Defense Centre, which would also include police authorities. However, due to the strict separation in the legal domain, personal data cannot simply be passed on from the BND to the Federal Police, for example. Read more of this post

Tradecraft observations on the Reichenbach/Fischer espionage case

Germany ReichstagSEVERAL CASES OF CHINESE espionage have been announced recently in Europe. Thomas Reichenbach and Herwig and Ina Fischer —a married couple— were arrested on April 22, 2024, for illegal exports of dual use technology with military (naval) applications.

Reichenbach lists himself as a contract marketing manager for the Hong Kong Trade Development Council. He studied at Peking University in the mid-1980s. He worked in China, speaks Mandarin, and has a Chinese wife.

Herwig and Ina Fischer own a small engineering consulting company named Innovative Dragon in Duesseldorf. Both have travelled extensively in China. Innovative Dragon contracts for technical research with universities. Herwig studied mechanical engineering and aircraft and spacecraft construction at the Rhine-Westphalia Higher Technical School, focusing on guidance technology and composite fiber materials. The company headquarters are in London and there are offices in Duesseldorf and Shanghai (Donghua University Science and Technology Park). The London office does not appear to have a functioning telephone number.

Reichenbach is suspected of having been recruited by the Ministry of State Security (MSS) in China. The German government has accused the trio of having illegally exported dual use technology since at least 2022. At the time of the arrests, the suspects were in negotiations on additional research projects useful for expanding the combat strength of the Chinese People’s Liberation Army Navy.

Status: Alleged

Tradecraft observations:

  1. Use of a potential front company in London to facilitate allegedly illegal exports.
  2. Use of third countries to facilitate allegedly illegal exports.
  3. Reichenbach allegedly recruited Herwig and Ina Fischer and handled them as in-country assets.
  4. It is alleged that the MSS probably recruited Reichenbach in China.
  5. An MSS officer allegedly handled Reichenbach from China (linear control).
  6. The MSS allegedly funded the operation through front companies.

Author: Nicholas Eftimiades* | Date: 03 May 2024 | Permalink

* Nicholas Eftimiades is a Senior Fellow at the Atlantic Council. He retired from a 34-year government career that included employment in the United States Central Intelligence Agency, the Department of State, and the Defense Intelligence Agency. He held appointments on the Department of Defense’s Defense Science Board and the Economic Security Subcommittee of the Department of Homeland Security’s Homeland Security Advisory Council. He is an advisor to the United States Intelligence Community. Eftimiades authored numerous works on China’s espionage methods. His books, Chinese Intelligence Operations (1994) and Chinese Espionage: Operations and Tactics (2020) are examinations of the structure, operations, and methodology of China’s intelligence services. They are widely regarded as seminal works in the field.

Notes on the assassination of Iranian IRGC Commander Hassan Mahdawi

IRGC - ABTHE TARGETED KILLING OF Hassan Mahdawi, a high-ranking member of Iran’s Islamic Revolutionary Guards Corps (IRGC) and the commander of the Quds Force in Syria and Lebanon, was carried out by Israel on April 1, 2024. The actual assassination was based on precise operational intelligence, while Israel’s assessment of Iran’s response was wrong.

On the day of the attack, a building adjacent to the Iranian Embassy in the Syrian capital of Damascus was attacked with rockets. The attack killed seven IRGC members: General Muhammad Reza Zahedi, also known as Hassan Mahdawi, his deputy, and five additional officers. Mahdawi is the most senior Iranian commander to be killed since the assassination of IRGC Quds Force Commander Qasem Soleimani by the United States in 2020.

Mahdawi had close ties with Hezbollah. He maintained a close relationship with Hezbollah Secretary-General Hassan Nasrallah and was perceived by Israel to be directly coordinating the military attacks on Israel from Lebanon and Syria. In Tehran’s collective memory, Israel’s history of attacks against it includes numerous strikes on Iranian nuclear sites, assassinations of scientists within Iran, and actions against Iranian proxies in Syria, Lebanon, Iraq, and Yemen. Traditionally, these attacks have been invariably met with attacks by Iran’s proxies in the region.

This time, it was different. Iran recognized Mahdawi’s assassination as a direct attack on Iran that it could not tolerate, and had to respond to differently. Just days following Mahdawi’s assassination, Iran attacked Israel. According to the Israel Defense Forces, 99 percent of the more than 330 weapons fired at Israel (including at least 185 drones and 110 surface-to-surface missiles) were intercepted, mostly over the territory of countries adjacent to Israel. Iran’s attack on Israel was unprecedented. It was launched directly from Iranian territory in contrast to prior cases, when Iran has used its proxies, supposedly leaving its hands clean.

Israel could not tolerate such a blatant infringement on its sovereignty. After Israeli officials vowed a response to the Iranian attack, the Jewish State counter-attacked, causing minor damage to the Eighth Shekari Air Base in northwest Esfahan, a dozen kilometers from the Natanz nuclear facility. It was a calculated response designed to deliver a message to Iran that Israel could and would respond to an attack. Following Israel’s counterattack, the tensions between Iran and Israel have subsided for the time being.

While the attack on General Mahdawi was based on excellent operational intelligence, it became evident that the Israeli assessment regarding a possible Iranian response was erroneous. The Israeli assessment was that the Iranian response would be similar to what occurred in the past —namely limited attacks by Hezbollah on northern Israel and attacks on the Golan heights by Iranian proxies in Syria. Israel simply did not anticipate a direct Iranian attack on Israel from Iranian territory.

It seems that Israeli senior analysts were entangled in a conception of Iran’s past behavior and anticipated that Tehran’s response would be similar to prior cases, namely utilizing Iran’s proxies. Israel did not pay enough attention to the difference between Mahdawi’s assassination and previous attacks against Iran. This time, the attack targeted the Iranian embassy in Damascus and the target was a very senior official, who was close to Iran’s Supreme Leader Ali Khamenei.

It appears that Israel’s assessment of the Iranian response to Mahdawi’s assassination was a strategic failure. It appears more likely that the Israeli War Cabinet was provided with an incorrect assessment by the nation’s intelligence community, and less likely that it was provided with an incorrect assessment, which it then decided to ignore. There is concern in Israel that the intelligence assessment was once again wrong, after the colossal failure to anticipate the October 7 attack on Israel by Hamas.

Author: Avner Barnea | Date: 26 April 2024 | Permalink

Dr. Avner Barnea is research fellow at the National Security Studies Center of the University of Haifa in Israel. He served as a senior officer in the Israel Security Agency (ISA). He is the author of We Never Expected That: A Comparative Study of Failures in National and Business Intelligence (Lexington Books, 2021).

Austria: Arrest raises broader questions about counterintelligence capabilities

BVT AustriaON GOOD FRIDAY, MARCH 29, Egisto Ott, a former member of Austria’s now-dissolved domestic intelligence agency, the Federal Office for the Protection of the Constitution and Counterterrorism (BVT), was arrested in his house in Carinthia, Austria’s southernmost state. Ott had frequently been at the center of media attention in the past year, in connection with the network surrounding the fugitive financier and alleged spy Jan Maršálek, as well as alleged misconduct relating to carrying out illegal investigations of persons. Ott also seems to have been involved in an alleged attempt to create an intelligence unit, or even an entire shadow intelligence service, embedded inside Austria’s foreign ministry. Now the veteran police and intelligence officer stands accused by the state attorney of abusing his authority and of being part of an “intelligence activity to the disadvantage of Austria” —the only form of spying that is illegal under § 256 of the Austrian criminal code.

Ott’s arrest came several years after intelligence was first shared with Austria by Western partner services —allegedly the Central Intelligence Agency— that reportedly date from as early as November 2017. Back then, Ott allegedly received classified material from his service’s email address to his personal Gmail account. However, Peter Gridling, director of the BVT from 2008 until its dissolution in 2021, stated in a recent interview that the ensuing investigations did not yield actionable results that could be used in criminal proceedings. This statement is highly interesting, as Gridling filed accusations about Ott with the State Prosecutor’s Office himself, and would hardly have done unless he had access to hard evidence. Ott was consequently removed from the BVT and placed in Police Academy Austria (SIAK), which is responsible for training police officers and conducts research related to police and domestic security.

Nevertheless, according to media reporting, Ott seems to have kept and illegally used certain forms of identification that presented him as a police officer. He is also alleged to have maintained access to several police databases and to have retained his network of trusted informants that provided him with intelligence. These included contacts in friendly foreign police services, whom Ott knew from his time as a liaison officer in Italy and Turkey. According to Gridling, these contacts were unaware that Ott had been removed from the BVT under suspicion of being unreliable and potentially even working for Russia. They therefore continued to help him when asked. Ott allegedly deceived his contacts by claiming that he needed information on cases relating to different kinds of extremism. As it turned out, according to the leaked arrest warrant, several of the individuals referred to by Ott as “suspects” in terrorism investigations were in fact Russian dissidents or intelligence defectors who were living as protected persons in Austria and elsewhere outside Russia.

It appears highly probable that Ott also had people inside the Austrian bureaucracy, including former colleagues in the BVT, who continued to provide him with information and assistance, even after the first allegations against him arose in 2017. As of now, at least one other officer from LVT Vienna (the state unit of the BVT) has been found to have illegally provided Ott with Information. It is likely, given the publicly available descriptions of Ott’s activities, that other individuals may be implicated. It also remains to be seen whether individuals involved in this case were able to join the BVT’s successor agency, the new Directorate of State Protection and Intelligence (DSN). Read more of this post

Interview reveals state of mind of Israeli intelligence prior to October 7 attack

Israeli General Staff MilitaryON MARCH 23, CHANNEL 12 of Israeli television aired a remarkable interview with Sassi Elya, the former director of technology at the Israel Security Agency (ISA). Better known by the acronyms Shin Bet or Shabak, the ISA is Israel’s domestic security service. The interview had initially been scheduled for broadcast as part of the evening news on October 7, 2023. However, its airing was canceled due to the attack on Israel by Hamas, which occurred that morning.

But on March 23, after about 5 months, Channel 12 aired the original interview with Elya. The retired official spoke with glee about the advanced technological capabilities developed by the ISA in order to prevent terrorist attacks against Israel. Elya said Israeli intelligence had built a unique system, known as “the Tool”, which allegedly provided intimate knowledge about the life of every Palestinian living in the West Bank and Gaza. This technologically advanced surveillance system allegedly monitored every move of its targets, all for the purpose of preventing potential terrorist attacks against the Jewish state. Elya claimed that, as a result of this advanced technological system, there was no chance that Israel would be surprised by Palestinian militants. This system was so advanced, he said, that intelligence agencies from all over the world were coming to Israel to learn about it.

Thanks to Channel 12, we can now examine Elya’s interview retrospectively, and especially in light of the ISA’s poor performance on October 7, as well as its failure to warn Israeli authorities about Hamas’ preparations for the attack. Notably, Elya was interviewed again for the same television program. Predictably, he admitted that his prior assessment had been wrong and regretted being so overly confident about the technology.

This case demonstrates the overestimation by Israeli intelligence of its own capabilities, because of arrogance and over-confidence. This approach refutes the basic premise of intelligence work: be skeptical and be modest. Furthermore, this case highlights that Israeli intelligence agencies overly relied on technology (SIGINT) in the lead-up to October 7, while seemingly neglecting the low-tech activity of gathering information through human intelligence (HUMINT).

The system that Elya described in his initial interview as the ultimate counterintelligence tool was reportedly criticized internally by some in the ISA for gathering huge amounts of information without offering sufficient analytical capability. This imbalance between collection and analysis can render an entire surveillance system practically useless. The bottom line is that, almost by accident, we are now aware of the state of mind that the ISA was in before the sudden attack by Hamas on October 7, which cost so many lives as a result of the ISA’s complacency.

► Author: Avner Barnea | Date: 01 April 2024 | Permalink

Dr. Avner Barnea is research fellow at the National Security Studies Center of the University of Haifa in Israel. He served as a senior officer in the Israel Security Agency (ISA). He is the author of We Never Expected That: A Comparative Study of Failures in National and Business Intelligence (Lexington Books, 2021).

Opinion: Five months into the war, Israeli intelligence failure looks even worse

Israel Hamas warSINCE OCTOBER 7, 2024, when Israel was caught off guard by a sudden and highly damaging attack from Hamas, more information has surfaced regarding why there was no prior warning about the attack and the failures of Israeli intelligence in this regard.

It has become clear that Israeli intelligence miscalculated Hamas’s intentions. The Israeli security concept, spearheaded by the Israel Military Intelligence (IMI) and the Israel Security Agency (ISA), was that: (a) Hamas had been deterred from launching large-scale attacks; and (b) Hamas was focused on carrying out terrorist attacks against Israelis in the West Bank and not on Israel proper. This flawed security concept, which had been fully adopted by the Israeli cabinet and the Israel Defense Forces (IDF) was proven to be groundless. In fact, Hamas successfully exploited it in order to develop and accelerate its attack strategy.

One significant reason for the failure of the IDF, both in the area of intelligence collection and operationally, was its underestimation of the capabilities of Hamas and the intentions of its leader, Yahya Sinwar. There was also an overestimation by many in Israel, including the security establishment, of Israel’s own intelligence Q Quotecapabilities. Another important insight is that the counterintelligence structures inside Hamas were successful in preventing Israeli intelligence from recruiting agents who were close enough to Sinwar to be able to alert Israel about the impending attack. Furthermore, Israel’s collection and analysis of signals intelligence was unproductive, possibly because Hamas was successful in countering Israel’s ability to produce effective intelligence from signals intercepts.

As the IDF moved deeper into Gaza, and as more information was collected from Hamas facilities, it became clear that there were significant gaps in information regarding the preparations for the attack by Hamas inside Gaza. These preparations lasted for a long time and involved numerous operatives who remained undetected by Israeli intelligence. It looks like the compartmentation system inside Hamas, based on a need-to-know only model, was highly effective.

The IDF attacked the Gaza Strip in 2014 in Operation Protective Edge. Its mission was to destroy Hamas’s ability to carry out assaults against Israel through tunnels dug deep inside Gaza and crossing the border into Israel. Indeed, about 20 such tunnels were destroyed during that operation. Later, Hamas built 250 miles of new tunnels in Gaza that were aimed at defense and to hide combatants when Israel attacked. It has been suggested that this construction project was funded by cash sent to Gaza by Qatar, with Israel’s approval —though Qatar denies this claim. Read more of this post

Russian intelligence services intensify efforts to ‘liquidate’ defectors: report

Maksim KuzminovTHE RUSSIAN INTELLIGENCE SERVICES have been “bolstering the[ir] architecture” aimed at stopping potential defectors and “liquidating” those who have already defected and are living in exile, according to a new report. In a leading article published on Sunday, The Wall Street Journal said that the list of “unsolved deaths” of the Kremlin’s Russian critics is “lengthening” and may have surpassed 50, according to some accounts.

Since the current phase of the invasion of Ukraine, which began in February 2022, Russian defectors and other critics of Russia’s ongoing war have “died in unusual circumstances on three continents”, according to the New York-based newspaper. Most deaths have occurred inside Russia, but several have occurred in countries such as India, France, and Spain. In the most recent case, Maksim Kuzminov, a Russian helicopter pilot, who defected to Ukraine in August 2023, was gunned down in Villajoyosa, Spain, last month, in what The Journal described as a “mafia-style assassination”.

The paper notes that very few of these killings or suspicious deaths can be directly attributed to the Kremlin. It adds, however, that the Russian government has ordered a redoubling of coordinated anti-defector operations by the country’s three main intelligence agencies —the Federal Security Service (FSB), the Foreign Intelligence Service (SVR), and the Main Intelligence Directorate of the General Staff of the Russian Armed Forces (GRU). In their effort to prevent defections and punish defectors, these agencies have blurred their operational boundaries,  “making it more difficult to know which is responsible” for anti-defector operations, says The Journal.

Russian anti-defector operations are also increasingly involving third-country nationals —operatives who have no official connection with Russia, or with the country in which they are operating on behalf of Russian intelligence. In one recent example from last August, authorities in Britain arrested three Bulgarian citizens with spying for Russia. According to British government prosecutors, the suspects possessed forged passports and identity cards for Spain, France, the United Kingdom, Croatia, Italy, Greece, Bulgaria, the Czech Republic, and Slovenia.

Author: Joseph Fitsanakis | Date: 04 March 2024 | Permalink

Netanyahu ignored calls to disrupt Hamas finances, claims ex-Mossad official

Udi LevyA RETIRED SENIOR MOSSAD official has alleged that Israeli Prime Minister Benjamin Netanyahu repeatedly ignored, and even frustrated, efforts to stop the flow of hundreds of millions of dollars to Hamas. This inaction may have enabled the Palestinian militant group to plan, organize and execute Operation Al-Aqsa Flood, which killed over 1400 Israelis on October 7, 2023, and sparked the current war between Israel and Hamas.

The allegation was made by Udi Levy, a 30-year veteran of the Israeli intelligence community, who served as an intelligence officer in the Israel Defense Forces before being appointed to head the Economic Warfare Division of the Mossad, Israel’s external intelligence agency. During his tenure in the Mossad, which ended with his retirement in 2016, Levy was a member of Task Force Harpoon, which aimed to disrupt the flow of funds to militant Palestinian groups, including Hamas.

Last week, Levy told the BBC’s flagship investigative television program Panorama that Task Force Harpoon had identified around 40 companies in the Middle East and North Africa, which were part of Hamas’ investment portfolio. These companies, based in countries such as Sudan, Algeria, Turkey, Saudi Arabia, and Qatar, were active in the areas of real estate, mining, construction, and tourism, among others. Some of the companies were even directly controlled by Hamas, said Levy.

The income from these financial investments allowed Hamas to use “billions, not millions” of dollars to build its military infrastructure in the Gaza Strip, according to the former Mossad official. That investment income was supplemented with direct cash infusions from Iran and Qatar, which in some cases arrived monthly through special envoys, according to Levy. He added that Turkey was “a critical focal point” in Hamas’ money network, as it served as a financial hub for the militant group’s holdings.

Levy told the BBC that he personally advised Netanyahu to “target Hamas’ finances” and explained to him that “Israel had the means to crush Hamas by using only financial tools”. However, Levy claims that, not only did the Israeli prime minister ignore Levy’s advice, but he proceeded to shut down the Mossad’s Task Force Harpoon. This is not the first time that Levy has made these claims. In December 2023, he told The New York Times that Task Force Harpoon analysts were so frustrated with the Israeli government’s inertia, that they resorted to “uploading some documents to Facebook” in hopes that the Israeli authorities would be forced to take action once details about Hamas’ finances were disclosed.

Author: Joseph Fitsanakis | Date: 26 February 2024 | Permalink