<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ozan Akyol &#8211; Digital Intelligence</title>
	<atom:link href="https://www.digitalintelligence.at/author/ozan/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.digitalintelligence.at</link>
	<description>Analysis &#38; Consulting</description>
	<lastBuildDate>Sun, 16 Aug 2026 16:58:55 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://www.digitalintelligence.at/wp-content/uploads/2025/11/android-chrome-512x512-1-60x60.png</url>
	<title>Ozan Akyol &#8211; Digital Intelligence</title>
	<link>https://www.digitalintelligence.at</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Seven Years of Deliveries, One Arrest</title>
		<link>https://www.digitalintelligence.at/seven-years-of-deliveries-one-arrest/</link>
					<comments>https://www.digitalintelligence.at/seven-years-of-deliveries-one-arrest/#respond</comments>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Sun, 16 Aug 2026 16:57:48 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4506</guid>

					<description><![CDATA[On Monday, 10 August, the Interior Ministry put out a press release announcing a success. The DSN had dismantled an international network of companies that moved sanctioned industrial goods to Russia through a firm registered in Vienna. Machine tools and special metalworking equipment, the kind you need to mill engine parts. According to the DSN&#8217;s own assessment, the goods ended up in the production of engines for cruise missiles and combat aircraft. State Secretary Leichtfried called it unacceptable and congratulated the investigators. Fine. It is unacceptable. But read the press release a second time and pay attention to the dates,]]></description>
										<content:encoded><![CDATA[<p>On Monday, 10 August, the Interior Ministry put out a press release announcing a success. The DSN had dismantled an international network of companies that moved sanctioned industrial goods to Russia through a firm registered in Vienna. Machine tools and special metalworking equipment, the kind you need to mill engine parts. According to the DSN&#8217;s own assessment, the goods ended up in the production of engines for cruise missiles and combat aircraft. State Secretary Leichtfried called it unacceptable and congratulated the investigators.</p>
<p>Fine. It is unacceptable. But read the press release a second time and pay attention to the dates, because the dates are the actual story.</p>
<p>The company had been supplying Russian military end users since 2019. Not since the full-scale invasion. Since 2019, five years after Crimea, in the middle of a sanctions regime that every exporter of dual-use goods in this country was legally obliged to understand. When the EU tightened sanctions after February 2022, the company did not stop. It rerouted. The goods travelled through firms in Turkey, the UAE, Hong Kong, Belarus, Kyrgyzstan, South Korea, Poland and Lithuania. European manufacturers were shown forged end-user certificates promising the equipment would stay in third countries. The real customers, per the investigation, were companies attributable to Rostec, the conglomerate at the heart of the Russian defence industry.</p>
<p>The first search warrants came in August 2025. Four properties, searched simultaneously, roughly forty data storage devices seized. In mid-May of this year the managing director and co-owner, a 28-year-old Belarusian citizen, was arrested. He has been sitting in pre-trial detention since. Total deliveries: more than 3.3 million euros.</p>
<p>Count it out. Seven years of deliveries. Three of them under the hardest sanctions regime Europe has ever imposed. Then somebody knocked on the door.</p>
<p>The press release celebrates the ending. Nobody in it explains the beginning or the middle.</p>
<h2>The pattern, again</h2>
<p>If you have been reading this site for a while, you already know where this is going. I have spent the better part of a year writing about the same underlying condition from different angles. A capital full of accredited intelligence officers. An espionage law that until recently did not care unless Austria itself was the target. A counterintelligence apparatus that needed six and a half years to attribute a cyberattack on its own Foreign Ministry.</p>
<p>Sanctions evasion is the trade version of the same disease. Espionage needs residency and cover. Sanctions evasion needs a jurisdiction and clean paperwork. Austria offers both, and cheaply. A GmbH costs almost nothing to set up, the banking works, and the customs and licensing apparatus that is supposed to catch this was never built for adversarial trade, for counterparties who forge documents professionally and route consignments through five countries as a matter of routine.</p>
<p>To be fair, this is not an Austrian invention. The Kyiv Independent showed in June, with customs records, how EU-made machinery keeps reaching Russian missile plants through third-country intermediaries. C4ADS has mapped the broker geography in detail: China and Hong Kong, Turkey, the UAE. Moscow&#8217;s procurement people treat European export controls as a delay, not an obstacle.</p>
<p>But this case is ours, and it raises a question nobody at Monday&#8217;s announcement wanted to touch: how many companies like this are operating in Vienna right now, and who exactly is looking for them?</p>
<h2>Note what solved this case</h2>
<p>There is a second point, and it connects to something this site has covered at length this year.</p>
<p>Nobody read anyone&#8217;s Signal messages to crack this network. It was cracked with the oldest tools in the trade: corporate records, customs data, a paper trail, coordinated house searches, forty seized hard drives, and prosecutors willing to hold a suspect while the analysis ran. Financial and trade forensics. The boring end of intelligence work.</p>
<p>I find that worth saying out loud in the same year the DSN&#8217;s flagship legislative project, the surveillance of encrypted messengers, sits before the Constitutional Court, sold to the public as indispensable against exactly this category of threat. Terrorism, extremism, espionage. Here is arguably the most consequential hostile-state operation uncovered in Austria this year, one that fed the engines of Russian cruise missiles, and it was taken apart with powers the state has had for decades.</p>
<p>The lesson is not that new powers are never justified. The lesson is that the binding constraint in Austrian counterintelligence has rarely been legal authority. It has been attention, staffing, and the willingness to sit with boring documents for a very long time. No trojan fixes that.</p>
<h2>Brussels has the tool and will not use it</h2>
<p>One more layer. In June 2023 the EU&#8217;s 11th sanctions package created a mechanism to ban exports of sensitive goods to third countries that systematically re-export them to Russia. It took until the 20th package for Brussels to activate it, and when it finally did, it applied the ban to one product category and one country: CNC machine tools to Kyrgyzstan. By the Kyiv School of Economics&#8217; numbers, Kyrgyzstan supplied about one percent of Russia&#8217;s battlefield goods. China and Hong Kong supplied the overwhelming majority.</p>
<p>Kyrgyzstan appears in the Vienna network&#8217;s country list. So do Hong Kong, Turkey and the UAE. None of those three face the mechanism, because they are trading partners with leverage, and Brussels knows it. Which means enforcement falls back on the member states, on national services finding the Vienna node of a network whose other nodes will simply reconstitute somewhere else next quarter.</p>
<h2>What should be asked at trial</h2>
<p>The proceedings are ongoing and the presumption of innocence applies to everyone involved. But the questions are already on the table, and they should be asked in court and in parliament.</p>
<p>Which European manufacturers shipped against those forged certificates, and what did their due diligence actually consist of? Criminal liability under EU law generally requires knowledge, but &#8220;we saw a stamp and stopped asking&#8221; is a compliance posture, not a defence of the system. When did Austrian authorities receive the first indication, from customs data, from a partner service, from anyone, and what happened to it between 2019 and August 2025? And is sanctions enforcement at the DSN a unit with a headcount, or a project with a press release?</p>
<p>The ministry says it will continue to act consistently against anyone supporting the Russian armaments apparatus. Good. The measure of that sentence will not be the next announcement. It will be how many years the next network gets to run before anyone notices.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.digitalintelligence.at/seven-years-of-deliveries-one-arrest/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Six and a Half Years to Say the Obvious: What the Turla Attribution Tells Us About Austria</title>
		<link>https://www.digitalintelligence.at/six-and-a-half-years-to-say-the-obvious-what-the-turla-attribution-tells-us-about-austria/</link>
					<comments>https://www.digitalintelligence.at/six-and-a-half-years-to-say-the-obvious-what-the-turla-attribution-tells-us-about-austria/#respond</comments>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 10:18:16 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4503</guid>

					<description><![CDATA[On 14 July 2026 the Russian ambassador was summoned to the Foreign Ministry at Minoritenplatz. The reason goes back six and a half years: the cyberattack on the ministry around New Year 2019/2020, an incident that kept the Austrian federal administration busy for weeks. Only now, in a joint declaration by all 27 EU member states, has it been officially confirmed what people in this field have known for years. The attack was carried out by Turla, a group run by Center 16 of the Russian domestic intelligence service FSB. I have watched enough attribution processes from close range to]]></description>
										<content:encoded><![CDATA[<p>On 14 July 2026 the Russian ambassador was summoned to the Foreign Ministry at Minoritenplatz. The reason goes back six and a half years: the cyberattack on the ministry around New Year 2019/2020, an incident that kept the Austrian federal administration busy for weeks. Only now, in a joint declaration by all 27 EU member states, has it been officially confirmed what people in this field have known for years. The attack was carried out by Turla, a group run by Center 16 of the Russian domestic intelligence service FSB.</p>
<p>I have watched enough attribution processes from close range to know one thing. Six and a half years is not a forensic requirement. It is a political choice.</p>
<h2>What happened back then</h2>
<p>A short reminder. In early January 2020 the Foreign Ministry announced it was the target of a serious attack. The wording at the time was unusually open, officials spoke of a state actor almost immediately. Then silence. The systems were cleaned over several weeks, and in February 2020 the attack was declared over. Who was behind it remained officially unanswered, even though the handwriting was readable from day one.</p>
<p>Today we know from the EU declaration that internal information related to Russia was exfiltrated. That is the sentence worth stopping at. Moscow did not want just anything. Moscow wanted to know what Vienna knows about Russia. What assessments Austrian diplomacy makes about Russian activities, who it shares them with, and how much this republic actually sees. That is classic intelligence collection against a country that likes to present itself as a neutral bridge.</p>
<h2>Who Turla is</h2>
<p>Turla is not an ordinary crew. Documented for well over a decade under names like Snake, Uroburos and Venomous Bear, it belongs to the most capable actors ever tied to a state apparatus. Its specialty is long, quiet espionage operations against foreign ministries, embassies and defense structures. The group&#8217;s Snake malware was considered one of the most sophisticated espionage tools ever built, until the FBI dismantled its infrastructure in a coordinated operation in 2023. Western services publicly attributed it to Center 16 of the FSB back then.</p>
<p>The EU now states that this same FSB unit has been running attacks on government networks and critical infrastructure across the Union for years. Alongside Austria, the declaration names Germany, Finland, France, the Netherlands, Poland, Romania, Slovakia and Cyprus. Austria is not a special case, it is one target among many. With one difference. Hardly any other affected country needed this long to say it out loud.</p>
<h2>Why only now</h2>
<p>The technical attribution was finished long ago. The signatures, the infrastructure, the tooling, all of it was on the table. What was missing was the political will to name Russia in public. Austria hid behind its neutrality and behind Vienna as a location, with its international organizations and roughly 13,000 accredited diplomats, of whom, by common assessment, more than a fifth are intelligence officers in the case of certain states. Nobody wanted to endanger the hub. So everyone stayed quiet.</p>
<p>The fact that the attribution comes now has less to do with Vienna than with Brussels. The joint declaration of all 27 member states is part of a broader European line of systematically naming and sanctioning Russian cyber operations. Austria is riding on that train, it did not push it. Foreign Minister Meinl-Reisinger said the ambassador was told that cyberattacks on Austria are unacceptable. That is a correct sentence. It would have been more correct in 2020.</p>
<h2>What summoning an ambassador is worth</h2>
<p>Let us be honest. Summoning an ambassador is the mildest instrument diplomacy has. It costs nothing, it changes nothing, and in Moscow it gets noted and filed. Pro Russian channels are already playing the predictable counter melody: why now, why so harsh, Russia offered dialogue after all. Anyone who knows the disinformation economy recognizes the pattern instantly. And it is the delay itself that hands this narrative its opening. An attribution made promptly, backed technically and issued together with partners is hard to delegitimize. One that takes six and a half years looks arbitrary, even when it is correct.</p>
<p>And it is correct. I have no doubt about that. The evidence Western services have compiled on Center 16 over the years is overwhelming.</p>
<h2>The uncomfortable question</h2>
<p>The real question is not addressed to Moscow but to Vienna. What has this republic learned since 2020? The attack on the Foreign Ministry hit at a moment when Austria&#8217;s domestic intelligence apparatus was internationally isolated after the BVT affair. Since then the DSN has been rebuilt, the Egisto Ott case has shown how deep Russian networks reached into Austrian security structures, and with the NISG 2026 the national implementation of NIS2 finally enters into force this October, years behind schedule.</p>
<p>The pattern is always the same. Austria reacts late, quietly, and only when the outside pressure grows large enough. The Turla attribution is a textbook example. Six and a half years between attack and naming is not a sign of diligence. It is a sign that this republic has treated espionage against itself as a location advantage for too long, instead of calling it what it is: an attack on its sovereignty.</p>
<p>Anyone who believes Center 16 has been on pause since 2020 has not understood the business. The question is not whether Austrian networks are compromised again today. The question is how long we will need this time to say so.</p>
<p><em>Sources: Joint declaration of the 27 EU member states on Russian cyberattacks (July 2026), confirmation by the Austrian Foreign Ministry to APA, reporting by Die Presse and ORF on 14 and 15 July 2026.</em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.digitalintelligence.at/six-and-a-half-years-to-say-the-obvious-what-the-turla-attribution-tells-us-about-austria/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Vienna Buys the Bidstream</title>
		<link>https://www.digitalintelligence.at/vienna-buys-the-bidstream/</link>
					<comments>https://www.digitalintelligence.at/vienna-buys-the-bidstream/#respond</comments>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Mon, 27 Jul 2026 18:22:41 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[OSINT]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[European security]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4499</guid>

					<description><![CDATA[Austria has renewed a licence for a surveillance system built on advertising data. Nobody in government will say under what legal authority, and the data protection regulator was never asked. A procurement notice on Austria&#8217;s public tender portal records the extension of a licence agreement between the Interior Ministry and the US vendor Penlink, worth roughly 1.85 million euros over two years. The package covers Penlink products including Webloc. Der Standard reported the deal first; netzpolitik.org followed with the ministry&#8217;s response, which was that no public information can be given about specific software solutions, and that anything the ministry uses,]]></description>
										<content:encoded><![CDATA[<p><strong>Austria has renewed a licence for a surveillance system built on advertising data. Nobody in government will say under what legal authority, and the data protection regulator was never asked.</strong></p>
<hr />
<p>A procurement notice on Austria&#8217;s public tender portal records the extension of a licence agreement between the Interior Ministry and the US vendor Penlink, worth roughly 1.85 million euros over two years. The package covers Penlink products including Webloc. Der Standard reported the deal first; netzpolitik.org followed with the ministry&#8217;s response, which was that no public information can be given about specific software solutions, and that anything the ministry uses, it uses within its legal powers.</p>
<p>The first half of that answer is a choice rather than a constraint. The second half cannot be verified, because the first half prevents anyone from checking it.</p>
<p>What makes this worth more than a paragraph of outrage is what Webloc actually is, and why the standard categories used in Austrian surveillance debate do not fit it.</p>
<h2>What Webloc does</h2>
<p>Webloc was built by the Israeli firm Cobwebs Technologies, acquired by Spire Capital in 2023 and merged into Penlink. It is sold as an add-on to Tangles, Cobwebs&#8217; web and social media intelligence platform, and it is not a wiretap, not an interception system, and not spyware in the conventional sense. It never touches the target&#8217;s device.</p>
<p>Instead it ingests the exhaust of the mobile advertising industry. Every time a phone opens an app that shows ads, an auction runs in under a second and the user&#8217;s data is broadcast to a large number of bidding parties. Separately, tracking SDKs embedded in apps collect and sell data directly. Both streams carry a Mobile Advertising ID, a persistent identifier tied to a specific handset, alongside GPS coordinates, Wi-Fi access point names, IP address, device model, operating system, language, and in many cases the ad targeting segments used to classify the person behind the phone.</p>
<p>Citizen Lab&#8217;s April 2026 analysis, based on leaked contract documents from El Salvador, technical specifications from Vietnam, US Navy procurement records and Penlink material from 2025, describes a system with access to a continuously updated stream from up to 500 million devices worldwide, refreshed every four to twenty-four hours, with three years of history available for query.</p>
<p>The interface is what matters. An analyst can draw a polygon on a map and retrieve every device observed inside it during a time window. They can intersect two polygons to find devices present in both, which surfaces people who travelled between two places. They can set alerts for new devices entering a monitored area. They can run a heat map on a single identifier to infer home address and workplace, which the vendor documentation treats as the expected workflow rather than an edge case. One example screen in the leaked material tracks a person moving from Germany through Austria into Hungary. Another resolves a single device to a specific building, rendered in Street View.</p>
<p>Note what this means structurally. Even when the target is one person, the query runs against everyone. A geofence around an address returns the neighbours. A geofence around a mosque, a clinic, a union hall or a newsroom returns whoever was there. The distinction between targeted and mass surveillance, which does most of the load-bearing work in Austrian legal argument about the SNG and the Constitutional Court proceedings on messenger surveillance, does not survive contact with this architecture. The Vienna-based tracking researcher Wolfie Christl put it plainly: even used against individuals, the system collects and analyses data on millions of uninvolved people every day.</p>
<h2>Two legal questions, neither answered</h2>
<p>There are two separate lawfulness problems here and they are routinely collapsed into one.</p>
<p>The first concerns the supply chain. Location data harvested from consumer apps under a consent banner about advertising, then sold onward through data brokers to a surveillance vendor, then sold to a state intelligence service, is being processed for a purpose no user ever agreed to. Christl&#8217;s position is that consent is effectively the only conceivable GDPR basis for such a transfer, and that no party in the chain holds valid consent for state surveillance. Germany&#8217;s consumer protection ministry took a comparable line in 2024, arguing that transferring personal data as a commodity in itself is incompatible with data protection law. The claim in Penlink&#8217;s older documentation that collection is GDPR compliant and consent-based rests on the same fiction the entire ad-tech sector rests on.</p>
<p>The second concerns the buyer. Even assuming the data existed lawfully, the Interior Ministry would need a domestic legal basis to acquire and query it. Purchasing commercially available data is a well-known route around the warrant requirement precisely because it does not look like a search. Nothing is intercepted, no device is compromised, no court is asked. In the United States, seventy-two members of Congress called in March 2026 for an investigation into warrantless location data purchases by ICE and other agencies, and an internal DHS review in 2023 already found that several DHS components had broken federal law through such purchases.</p>
<p>Austria has answered neither question. The ministry&#8217;s response to netzpolitik.org gestured at extremist and terrorist offences and indicated the Directorate for State Protection and Intelligence Service as the responsible body, which tells us the intended use case without telling us the authority for it.</p>
<h2>The oversight gap is the actual scandal</h2>
<p>The Austrian data protection authority told netzpolitik.org that it has no closer knowledge of the ministry&#8217;s planned use of the software and was not consulted. Under the GDPR, prior consultation with the supervisory authority is required where a data protection impact assessment identifies a high residual risk.</p>
<p>Work through the possibilities. Either the ministry conducted an impact assessment on a system that queries commercial location data covering hundreds of millions of people and concluded there was no high risk, or it did not conduct one. Both are difficult to defend. The regulator has kept the door open, noting it can examine compliance at any time through a complaint or an own-initiative review. It has not said it will.</p>
<p>Meanwhile the transparency record is instructive. Citizen Lab sent ninety-six freedom of information requests across fourteen European countries and six EU bodies. Austrian ministries, alongside Dutch and Romanian ones, declined to say whether they use Webloc. Europol confirmed holding relevant information and refused to release it. Not a single European agency confirmed use. Austria&#8217;s participation only became known because a procurement document sat in a public tender portal. Green MP Süleyman Zorba, who had previously been told that any disclosure would endanger national security, has made the obvious point that the deployment is now documented in public award records.</p>
<p>Austria is, on current evidence, the second confirmed ad-based surveillance customer in the EU after Hungary, where domestic intelligence has been using Webloc since at least 2022 and bought a fresh licence round in March 2026.</p>
<h2>Mission creep is not hypothetical</h2>
<p>The reassurance offered in these debates is always that the tool is reserved for terrorism, extremism and organised crime. There is now a documented answer to that.</p>
<p>Tucson police in Arizona acquired Tangles and Webloc for sex trafficking investigations, funded from a state border security programme. An internal report obtained by journalists describes the department using the system to investigate burglary, robbery and the theft of several thousand dollars of cigarettes, running advertising ID queries across crime scene areas to locate a suspect&#8217;s workplace, his former girlfriend and the apartment the identifiers kept returning to. The same system was used to monitor protests during campaign visits by presidential and vice-presidential candidates.</p>
<p>That is the empirical trajectory of a capability that is fast, cheap, warrantless and sitting on an analyst&#8217;s desk. Nothing about Austrian institutional culture makes it immune, and the current absence of any published control regime makes it less protected than the American departments where at least the procurement records are litigated.</p>
<h2>The counterintelligence problem nobody is discussing</h2>
<p>There is a dimension to this that civil liberties framing misses, and it should concern Austrian security professionals more than it currently does.</p>
<p>If the Interior Ministry can buy access to a stream covering hundreds of millions of devices, so can anyone else with a budget and a front company. The data does not become available only to lawful buyers. It is a commercial product moving through an opaque broker layer, and the same bidstream that produces Webloc produces competitor systems from other vendors, some of them in jurisdictions with no meaningful export control on this category.</p>
<p>Vienna hosts the IAEA, UNODC, the OSCE, OPEC and a large diplomatic corps. It is one of the densest concentrations of intelligence-relevant personnel in Europe. Every one of those people carries a phone running apps with embedded tracking SDKs. A geofence around the Vienna International Centre, a ministry, an embassy or a safe house is a commercially purchasable product. Pattern of life on a named official requires only linking one identifier, and advertising IDs are routinely matched to names, addresses and phone numbers by the same industry that insists they are anonymous. The US Federal Trade Commission has stated directly that these identifiers provide no anonymity in the marketplace.</p>
<p>A state that normalises the purchase of this data for its own investigations has a weaker position from which to argue that the market should not exist. That is a counterintelligence cost, not just a privacy cost, and it is being incurred without public debate.</p>
<h2>What should happen next</h2>
<p>Three things are reasonable to demand, and none of them require accepting or rejecting the underlying capability.</p>
<p>Publish the legal basis. Not the operational detail, not the target selection, just the statutory provision under which commercially sourced location data may be acquired and queried, and which oversight body approves individual queries.</p>
<p>Have the data protection authority open an own-initiative review. The question of whether the underlying processing is lawful is squarely within its mandate and does not depend on the ministry&#8217;s cooperation.</p>
<p>Treat ad-based tracking as a defensive problem. For anyone in Austria handling sensitive material, the mitigation is unglamorous and available today: reset advertising identifiers regularly or disable them entirely, deny location permission to any app that does not require it for its core function, and remove ad-supported apps from devices used for sensitive travel. This is not a substitute for regulation. It is what can be done while regulation does not exist.</p>
<hr />
<p><strong>Sources</strong></p>
<ul>
<li>Wolfie Christl, Astrid Perry, Luis Fernando Garcia, Siena Anstis and Ron Deibert, &#8220;Uncovering Webloc: An Analysis of Penlink&#8217;s Ad-based Geolocation Surveillance Tech,&#8221; Citizen Lab Report No. 191, University of Toronto, 9 April 2026</li>
<li>Sebastian Meineck, netzpolitik.org, 30 June 2026</li>
<li>Der Standard, reporting on the Interior Ministry procurement record</li>
<li>VSquare, Szabolcs Panyi, on Hungarian intelligence use of Webloc, April 2026</li>
<li>Austrian federal procurement portal, tender award documentation</li>
</ul>
]]></content:encoded>
					
					<wfw:commentRss>https://www.digitalintelligence.at/vienna-buys-the-bidstream/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Austria&#8217;s Spyware Law Goes Before the Judges. The Real Question Is Who Sells the Exploit.</title>
		<link>https://www.digitalintelligence.at/austrias-spyware-law-goes-before-the-judges-the-real-question-is-who-sells-the-exploit/</link>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Fri, 12 Jun 2026 08:21:25 +0000</pubDate>
				<category><![CDATA[Europe]]></category>
		<category><![CDATA[Intelligence]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4477</guid>

					<description><![CDATA[On June 22 the Austrian Constitutional Court will sit in public session and hear arguments about whether the state may read your Signal messages. The hearing starts at 9:30 in the morning. I expect the courtroom to be full and the answers to be thin. The law under review is the amendment to the Staatsschutz- und Nachrichtendienst-Gesetz that the Nationalrat passed on July 9 last year. It gives the DSN, Austria&#8217;s domestic intelligence service, the power to monitor messages on services like WhatsApp and Signal, encrypted or not. The trigger conditions are terrorism, activities that endanger the constitutional order, and]]></description>
										<content:encoded><![CDATA[<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="3:1-3:251;93-343">On June 22 the Austrian Constitutional Court will sit in public session and hear arguments about whether the state may read your Signal messages. The hearing starts at 9:30 in the morning. I expect the courtroom to be full and the answers to be thin.</p>
<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="5:1-5:590;345-934">The law under review is the amendment to the Staatsschutz- und Nachrichtendienst-Gesetz that the Nationalrat passed on July 9 last year. It gives the DSN, Austria&#8217;s domestic intelligence service, the power to monitor messages on services like WhatsApp and Signal, encrypted or not. The trigger conditions are terrorism, activities that endanger the constitutional order, and espionage. Orders run for three months and can be extended. Before anything happens, the Rechtsschutzbeauftragter in the Interior Ministry reviews the request and the Federal Administrative Court has to approve it.</p>
<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="7:1-7:211;936-1146">On paper that is a layered system. In practice I have yet to meet anyone in Vienna&#8217;s security community who can explain how a court is supposed to meaningfully review a surveillance technique it cannot inspect.</p>
<h2 class="text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold" data-sourcepos="9:1-9:19;1148-1166">How we got here</h2>
<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="11:1-11:479;1168-1646">The vote last July was ugly. ÖVP and SPÖ carried it, FPÖ and the Greens voted against, and even inside the coalition the NEOS deputies Krisper and Scherak broke ranks. That fracture mattered. In January, FPÖ and the Greens filed a Drittelbeschwerde, a constitutional challenge that requires one third of the Nationalrat. Sixty-two deputies signed. When the parliamentary far right and the Greens agree that a law goes too far, the Constitutional Court tends to listen carefully.</p>
<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="13:1-13:477;1648-2124">There is also precedent, and it is not on the government&#8217;s side. In 2019 the same court struck down Austria&#8217;s first attempt at a Bundestrojaner. The judges called covert surveillance of computer systems a grave intrusion into private life under the European Convention on Human Rights, permissible only within extremely narrow limits. The Interior Ministry&#8217;s lawyers have spent the years since trying to draft around that ruling. June 22 is the test of whether they succeeded.</p>
<h2 class="text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold" data-sourcepos="15:1-15:41;2126-2166">The part nobody wants to say out loud</h2>
<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="17:1-17:388;2168-2555">Here is the technical reality the political debate keeps avoiding. You cannot wiretap Signal. End-to-end encryption means there is nothing useful on the wire. There are only two ways in. Either the provider hands over the messages, which Signal will not and structurally cannot do, or the state installs spyware on the target device by exploiting a vulnerability in the operating system.</p>
<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="19:1-19:599;2557-3155">The second option is what this law actually authorizes, whatever the legislative language says. And the budget figures confirm it. The impact assessment attached to the reform set aside ten million euros from 2026, followed by roughly two million per year in license fees through 2029. License fees. Nobody pays recurring license fees for a tool they built themselves. Austria is shopping at an international spyware vendor, and the shortlist of companies selling state-grade mobile exploitation is not long. The same paperwork mentions an IMSI catcher for location data, almost as an afterthought.</p>
<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="21:1-21:423;3157-3579">So the state becomes a customer in the exploit market. That has consequences the law does not address. Every zero-day a government buys and keeps alive is a vulnerability deliberately left open in phones carried by everyone else, including ministers, judges and the DSN&#8217;s own officers. People in allied services have been blunt with me about this trade-off for years. You do not get a Trojan that only works on terrorists.</p>
<h2 class="text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold" data-sourcepos="23:1-23:42;3581-3622">Why the timing is awkward for everyone</h2>
<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="25:1-25:576;3624-4199">The government will argue necessity, and it has material. Sylvia Mayer, running the DSN since January, says openly that Russia is the largest espionage threat and that among Vienna&#8217;s thirteen thousand accredited diplomats, some delegations are more than one fifth intelligence officers. The Egisto Ott verdict in May, four years and one month for spying for Moscow from inside the old BVT, gave Austria its first major espionage conviction of the new era. The services finally have political momentum after a decade of being the embarrassment of European counterintelligence.</p>
<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="27:1-27:362;4201-4562">The opposition will argue proportionality, and it also has material. The 2019 ruling. The technical impossibility of limiting spyware once deployed. The fact that the agency asking for this capability is the institutional successor of the office Ott worked for. Trust is the currency here, and Austrian domestic intelligence has been printing very little of it.</p>
<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="29:1-29:593;4564-5156">The court has said it intends to announce its decision in the days after the hearing. Whichever way it falls, the law is supposed to enter into force in 2027, which means the procurement process is presumably already moving. That is the thread I find more interesting than the constitutional question. If the judges uphold the law, Austria signs a contract with a spyware vendor within months. The name on that contract, and the export jurisdiction behind it, will tell us more about the future of Austrian surveillance than anything said in court on June 22. I intend to find out what it is.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Vienna&#8217;s Antenna Forest and Austria&#8217;s Quiet Course Change</title>
		<link>https://www.digitalintelligence.at/viennas-antenna-forest-and-austrias-quiet-course-change/</link>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Sat, 30 May 2026 12:38:14 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[Intelligence]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4473</guid>

					<description><![CDATA[There is a stretch of road in Vienna&#8217;s 22nd district, just off the U1 metro line, where you can stand on one side of a small park and see the Russian diplomatic compound on the left and the UN City complex on the right. The distance between them, on a clear day, is about what a decent rooftop antenna would have for line of sight on satellite uplinks from the IAEA. Anyone in Vienna&#8217;s intelligence ecosystem has thought about this geometry at some point. The staff at the IAEA Communications Office have thought about it more. On 4 May, the]]></description>
										<content:encoded><![CDATA[<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">There is a stretch of road in Vienna&#8217;s 22nd district, just off the U1 metro line, where you can stand on one side of a small park and see the Russian diplomatic compound on the left and the UN City complex on the right. The distance between them, on a clear day, is about what a decent rooftop antenna would have for line of sight on satellite uplinks from the IAEA. Anyone in Vienna&#8217;s intelligence ecosystem has thought about this geometry at some point. The staff at the IAEA Communications Office have thought about it more.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">On 4 May, the Austrian Foreign Ministry confirmed an ORF report from the previous evening. Three Russian diplomats had been declared persona non grata over the antennas on the roof of the embassy on Reisnerstrasse in the 3rd district and on the Donaustadt compound described above. The installations, according to ORF&#8217;s sources, were used to intercept data transmitted by international organisations based in Vienna over satellite internet. The three have already left.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">This is the largest single Russian expulsion in Austria&#8217;s post-2022 period and brings the cumulative total to 14 since the full-scale invasion. The 14 figure, set against the seven-thousand-or-so hostile officers operating in this city and the dozens of accredited Russian personnel still in Vienna, is small. The story matters less for the numerical impact than for what it signals about how the new coalition is actually treating the espionage portfolio.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Foreign Minister Beate Meinl-Reisinger framed it in unusually direct language for an Austrian foreign minister: &#8220;Espionage is a security problem for Austria. In this government, we have initiated a change of course and are taking consistent action against it.&#8221; Then, more pointedly: &#8220;It is unacceptable for diplomatic immunity to be used to conduct espionage.&#8221;</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Both sentences should be read in the context of what the Austrian government did before reaching the expulsion decision.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The Russian ambassador was summoned to the Foreign Ministry in April. Vienna asked Moscow to waive the immunity of the three officers so that the prosecutor&#8217;s office could open a case. Russia refused, which is the answer everyone in the building expected. Once that refusal was on the record, the only remaining instrument was a PNG declaration. That sequence, asking for immunity to be lifted before going to expulsion, is itself meaningful. It tells you the Justice Ministry would have preferred to prosecute, not deport. That is the institutional logic of the §319a draft I wrote about last month coming into view. The government is signalling that it wants foreign espionage on Austrian soil treated as a criminal matter rather than a diplomatic one.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The technical layer matters, and I will be brief about it because there are people in this city who know more than I do about exactly what those antennas were doing. The basics are these. When an international organisation in Vienna sends and receives traffic over satellite, the uplink and downlink are not magic. They are radio waves with side lobes that bleed off the main beam, and they pass over rooftops in defined geometric patterns. Anyone with the right antenna at the right altitude in the right place can pick up that traffic. Decrypting it is harder, but the volume of communications moving through the IAEA, UNOV, the OSCE and the EU Agency for Fundamental Rights, accumulated over years, gives serious cryptanalytic teams plenty to work with. Embassy rooftops are uniquely valuable platforms for this work because of immunity. Nobody, including DSN, can come up and look at the equipment.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The Donaustadt compound is what makes this case sharper than the standard embassy SIGINT story. The site sits within walking distance of the UN City complex. The line of sight is, to put it generously, ideal. Anyone who has walked along Wagramer Strasse on a clear afternoon understands the geometry instinctively. The question that has been quietly asked in Vienna&#8217;s diplomatic circles for years is why nobody acted on this earlier.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Part of the answer is that DSN until recently was not in shape to act. Sylvia Mayer took over on 1 January as the first female director of the agency. The Russian ambassador was summoned in April. The expulsions were announced on 4 May. That is the operational rhythm of a service that has decided to spend its first major political capital on this file. Mayer herself was on the podium at the press conference. Asked why these installations were a particular threat, she limited herself to saying it had to do with their size and nature, and declined to comment on the timing. The decline to discuss the timing is the whole story. The timing is a political choice, not an intelligence one. The antennas have been there for years.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">There are limits to what I will read into a single expulsion. Austria has now expelled 14 Russian diplomats in four years, which compared to other European countries is still on the low side. The bulk of accredited Russian personnel are still here, doing whatever they do, with the same immunities. The Donaustadt compound is still in operation. The antennas, as a class of equipment, are not going anywhere, and Russia will rotate in new staff under different cover within months. The structural facts of Vienna&#8217;s exposure have not changed.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">What has changed, possibly, is the political ceiling on what can be done about that exposure. For most of the past decade, the standard official Austrian position was that Vienna&#8217;s hosting role required a particular kind of equidistance, and that expulsions complicated relationships with international organisations that depended on diplomatic stability. That position has been quietly retired by the current government. Meinl-Reisinger&#8217;s &#8220;change of course&#8221; line is not rhetorical. It maps onto a sequence of concrete decisions: the §319a draft, the summoning of the ambassador, the public request for immunity waiver, the public expulsion. These are not the actions of a government still committed to the bridge.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The next move belongs to Moscow. The Russian embassy called the expulsions &#8220;outrageous&#8221; and &#8220;politically motivated,&#8221; and warned of a &#8220;harsh&#8221; response, calling the bilateral relationship &#8220;at a historical low.&#8221; In recent pattern, &#8220;harsh response&#8221; usually means a reciprocal expulsion of Austrian diplomats, often more than the original number, and visa frictions for Austrian citizens. The relationship will degrade further. That is also part of the price of the course change, and the government appears to be prepared to pay it.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The piece I wrote last month argued that the §319a draft was real progress but that the Ott verdict would tell us more than the law itself. The expulsions on 4 May added a third data point to that picture. Taken with the verdict that landed on 20 May, the bill, the expulsions and the conviction are starting to look less like isolated events and more like a deliberate sequence. Vienna, for the first time in a long time, is acting like a country that takes its espionage problem seriously.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Whether that lasts beyond the next election cycle is a question I will not answer today. It depends on which parties are at the table after the next vote and what they decide to do with the institutional momentum the current government has built. The political risks are real. The operational improvements are also real. Both things can be true.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The &#8220;Between Peace and War&#8221; Doctrine Has an Austrian Problem</title>
		<link>https://www.digitalintelligence.at/the-between-peace-and-war-doctrine-has-an-austrian-problem/</link>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Mon, 11 May 2026 12:04:30 +0000</pubDate>
				<category><![CDATA[Europe]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4449</guid>

					<description><![CDATA[The day the White House announced it was withdrawing the United States from the European Centre of Excellence for Countering Hybrid Threats, I happened to be in a meeting with a contact at the Federal Police in Vienna. He glanced at the news on my phone, made a dry remark in Viennese German that I will not bother to translate, and went back to whatever case we were on. That reaction is, I think, the entire problem in miniature. The European conversation about the gray zone is happening at full volume. White papers, conferences in Brussels and Helsinki, ECFR reports,]]></description>
										<content:encoded><![CDATA[


<p class="wp-block-paragraph">The day the White House announced it was withdrawing the United States from the European Centre of Excellence for Countering Hybrid Threats, I happened to be in a meeting with a contact at the Federal Police in Vienna. He glanced at the news on my phone, made a dry remark in Viennese German that I will not bother to translate, and went back to whatever case we were on. That reaction is, I think, the entire problem in miniature.</p>



<p class="wp-block-paragraph">The European conversation about the gray zone is happening at full volume. White papers, conferences in Brussels and Helsinki, ECFR reports, Council conclusions in March, a CSIS analysis that finally puts numbers on the sabotage. The actual operational people who would have to do something about it, at least in this country, are still treating it as somebody else&#8217;s file.</p>



<p class="wp-block-paragraph">There is a doctrine emerging inside European intelligence services that finally, openly, names what has been happening for the past several years. Blaise Metreweli, the new chief of MI6, set it out in her first public speech on 15 December. &#8220;We are now operating in a space between peace and war,&#8221; she said. &#8220;This is not a temporary state or a gradual evolution.&#8221; Then she listed what that space contains: arson, sabotage, cyberattacks on critical infrastructure, drones over airports and military bases, aggressive undersea activity, and what she called the deliberate creation of fractures inside societies.</p>



<p class="wp-block-paragraph">That speech was, by the careful reading of a few people I trust in London, a doctrinal moment. Metreweli spent very little time on China and almost none on terrorism, the two priorities that have dominated British intelligence work for two decades. She did not really mention the United States at all, which is itself a signal. The framing was entirely about Russia and about a Europe that has to start acting on the gray zone rather than just documenting it.</p>



<p class="wp-block-paragraph">Joseph Fitsanakis sharpened the argument in a 5 May intelNews piece. His point, distilled, is that European intelligence services were built for a strategic environment in which they complemented American primacy. Their job was to support NATO, fill in regional gaps, provide national-level warning, and feed the larger US machine. That model is operationally insufficient now. Trump&#8217;s pivot, including the January withdrawal from the Helsinki-based Hybrid CoE, was the formal closure of the old arrangement. What Europe needs instead is autonomous intelligence structures capable of supporting an actual independent strategy. Most European services are not there yet, and the gap is widening.</p>



<p class="wp-block-paragraph">The case for the doctrine, if you want it in numbers, is overwhelming. CSIS counted 219 suspected Russian hybrid warfare incidents in Europe between 2014 and 2025, with 46 percent of them occurring in 2024 alone. German media revealed in February that the Bundeskriminalamt counted 321 sabotage cases inside Germany during 2025. In September 2025, between 19 and 21 Russian-launched drones crossed into Polish airspace, forcing NATO Article 4 consultations and the closure of several airports. Drone sightings shut down operations at Munich Airport. Lithuania declared a state of emergency over repeated Belarusian balloon incursions. At the February Munich Security Conference, BND president Martin Jäger put the global Russian intelligence officer count at 60,000, not including informants. Whatever the precision on that figure, the scale is unmistakable.</p>



<p class="wp-block-paragraph">This is the strategic backdrop. Now the part that actually matters from where I sit.</p>



<p class="wp-block-paragraph">Austrian neutrality, as written into the Constitution in 1955, was designed for a different kind of conflict. The architects had in mind blocs, armies, formal alliances. The neutrality law commits Austria not to join military alliances, not to host foreign military bases, and not to participate in aggressive war. None of those conditions are triggered by the activity Metreweli described. A drone over Vienna&#8217;s airport does not require Austria to declare its alliance status. A cyberattack on the IAEA does not engage the army. A sabotage operation against a logistics hub in Lower Austria does not breach any of the formal conditions of neutrality. So Austria sits, technically neutral, while operations against its partners, its institutions, and increasingly its own infrastructure are run through its territory.</p>



<p class="wp-block-paragraph">This is the part of the doctrine that nobody in Vienna wants to address out loud. Neutrality, as a legal category, is operationally meaningless in a gray-zone conflict. The conflict does not generate the moments that neutrality is built to manage. There is no declaration of war, no troop movement, no formal alliance request. There is only constant, low-grade, deniable pressure. And in a country that hosts the IAEA, UNOV, the OSCE, OPEC, the EU Agency for Fundamental Rights, several thousand accredited foreign personnel, and the seven-thousand-or-so hostile intelligence officers I have written about before, the absence of a formal war does not mean the absence of strategic stakes. It just means Austria is currently choosing not to act on them.</p>



<p class="wp-block-paragraph">The §319a bill I covered last month is the dim reflection of this realization inside the Justice Ministry. The drafters know, even if they cannot put it in the explanatory memorandum, that the current legal framework is calibrated for a world that no longer exists. Closing the espionage loophole is the easy half. The harder half is asking whether a country can credibly call itself neutral when its capital is the operational backyard for at least one belligerent in an ongoing European conflict.</p>



<p class="wp-block-paragraph">I do not see the DSN reaching that question on its current trajectory. Sylvia Mayer took over as director on 1 January. The service is still rebuilding from the BVT collapse, and the allied agencies I speak with regularly describe DSN as analytically respectable and operationally thin, which is the wrong shape for &#8220;between peace and war&#8221; work. The doctrine Metreweli outlined assumes a service capable of running disruption operations against hostile networks on its own initiative. That is not what DSN does, and it is not what DSN, given Austrian political reality, will be doing any time soon.</p>



<p class="wp-block-paragraph">The political reality is the second-order problem. The FPÖ leads the polls. The party has spent the past decade building its base on a soft-Russia, hard-neutrality position, and there is no electoral incentive for them to revisit it. If they form the next government, or play kingmaker in the next coalition, the most likely outcome is that Austria stays inside the EU institutional framework on paper while drifting operationally outside the European gray-zone response architecture. Other European services will adjust by routing around Vienna. I have already heard variations of that sentence in a couple of allied capitals over the past year.</p>



<p class="wp-block-paragraph">So what does Metreweli&#8217;s doctrine actually mean for this country.</p>



<p class="wp-block-paragraph">It means the choice is becoming explicit. Either Austria modernizes its understanding of neutrality to allow active counter-hybrid work, including offensive cyber, disruption of hostile networks on its own territory, and meaningful operational sharing on hybrid campaigns against partners. Or it accepts that its strategic position will erode quietly, year by year, until the city is treated by allied services as a permissive environment to be worked around rather than worked with.</p>



<p class="wp-block-paragraph">The Constitution does not actually prevent the first option. The Constitution prevents joining a military alliance. It does not prevent treating sabotage, cyberattacks, drone incursions and hybrid operations against European partners as serious matters that Austria acts on. That is a political choice presented as a legal constraint. Most Austrian politicians find the legal framing convenient because it spares them the conversation.</p>



<p class="wp-block-paragraph">Metreweli&#8217;s speech, read carefully, was an invitation. She was telling other European services that the UK is moving from documenting to acting. She was telling Moscow that the cost calculus is about to change. She was telling Washington, very politely, that London no longer believes the transatlantic intelligence relationship is what it once was. And she was telling neutral countries that the gray zone does not respect their preferred categories.</p>



<p class="wp-block-paragraph">Vienna has not yet had this conversation with itself. It will. The only question is whether it happens because Austrian politicians chose to have it, or because allied services stopped waiting.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Austria Finally Drafts a Real Espionage Law. The Ott Trial Will Decide Whether It Matters.</title>
		<link>https://www.digitalintelligence.at/austria-finally-drafts-a-real-espionage-law-the-ott-trial-will-decide-whether-it-matters/</link>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Sun, 26 Apr 2026 16:13:51 +0000</pubDate>
				<category><![CDATA[Europe]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4445</guid>

					<description><![CDATA[Austria has spent the better part of half a century letting foreign intelligence officers run operations from its capital, because the law, quite literally, does not care as long as the target is somebody else. Section 256 of the Criminal Code criminalises espionage only when it is directed against the Austrian state. So if a Russian, Chinese or Iranian officer sits in a Viennese café and tasks a contact to collect on the IAEA, surveil a dissident who fled here precisely because she thought the Republic would protect her, or lift material from an OSCE delegation, none of that is]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Austria has spent the better part of half a century letting foreign intelligence officers run operations from its capital, because the law, quite literally, does not care as long as the target is somebody else.</p>



<p class="wp-block-paragraph">Section 256 of the Criminal Code criminalises espionage only when it is directed against the Austrian state. So if a Russian, Chinese or Iranian officer sits in a Viennese café and tasks a contact to collect on the IAEA, surveil a dissident who fled here precisely because she thought the Republic would protect her, or lift material from an OSCE delegation, none of that is a crime under Austrian law. The targeted state can complain. The targeted institution can withdraw cooperation. Austria itself has nothing to charge.</p>



<p class="wp-block-paragraph">This is what produces the &#8220;spy capital&#8221; cliché. The figure people quote is 7,000 hostile officers operating in this city. It comes from the Austrian Center for Intelligence and Security Studies and is several years old. I have my doubts about that level of precision, since counting people whose entire job is not being counted is a strange exercise. But the structural fact the number gestures at is real, and any allied service will tell you the same thing about Vienna without much prompting.</p>



<p class="wp-block-paragraph">On 9 March, the Justice Ministry circulated a draft bill that finally moves to close §256. Falter obtained the text and reported on 3 April. Bloomberg followed the same morning. The draft is now sitting with the ÖVP-NEOS coalition partners.</p>



<p class="wp-block-paragraph">The headline change is a new §319a, criminalising espionage against international organisations headquartered in Austria, with prison terms of six months to five years. The IAEA, UNOV, the OSCE, the EU Agency for Fundamental Rights, all of them become protected. Operating against them from Austrian soil becomes a domestic offence rather than a diplomatic embarrassment that the Foreign Ministry has to manage privately.</p>



<p class="wp-block-paragraph">That is the part everyone is writing about. The two changes underneath it are more interesting.</p>



<p class="wp-block-paragraph">The first widens the legal concept of <em>Nachteil der Republik</em>, detriment to the Republic. Under the draft, the conduct does not have to actually harm Austria. It is enough that it is capable of endangering the country&#8217;s reputation, security or prosperity. So espionage against another EU member state, conducted from here, becomes prosecutable on the theory that hosting it could damage Austria&#8217;s relations with the partner. This shifts the offence from a results-based crime toward something closer to abstract endangerment. The Constitutional Court has historically not been comfortable with that kind of construction, and the provision will end up there sooner or later.</p>



<p class="wp-block-paragraph">The second targets what the trade calls disposable agents. These are the low-skilled people, often very young, recruited through Telegram or Signal to do small, discrete tasks. Photograph a building. Drop a package. Walk behind a target for an afternoon. The Bulgarian cell that worked through Jan Marsalek and was convicted in London last year relied heavily on this model, including in Vienna. Under current law, prosecuting them was awkward, because their individual contribution was small and their knowledge of the wider operation was usually genuine ignorance. The draft makes participation itself the offence, including for volunteers.</p>



<p class="wp-block-paragraph">The political pressure behind all of this is coming, very specifically, from one courtroom on Landesgerichtsstrasse.</p>



<h2 class="wp-block-heading">The Ott trial</h2>



<p class="wp-block-paragraph">The trial of Egisto Ott opened on 22 January. Ott is a former officer of the BVT, the domestic intelligence service that was dissolved after the 2018 raid that, more than anything else, destroyed Austria&#8217;s standing inside the European intelligence community for most of the next decade. The indictment runs to 172 pages. The headline charge, which is what makes this politically explosive rather than just embarrassing, is supporting a foreign intelligence service to the detriment of Austria.</p>



<p class="wp-block-paragraph">Prosecutors say Ott pulled large volumes of personal and operational data from national and international police databases between 2015 and 2021, kept some of it in a private Gmail account, and passed it through Marsalek, the fugitive Wirecard COO who has been in Russia since 2020. The list of alleged products is bad. Addresses of Russian dissidents living in Austria. Phone metadata of senior interior ministry staff. At one point in 2022, a laptop containing classified EU electronic security hardware that ended up with Russian intelligence.</p>



<p class="wp-block-paragraph">The allegation that should make any journalist in this region uncomfortable is that Ott provided Marsalek with the Vienna address of Christo Grozev, the Bellingcat investigator who has spent years exposing GRU operations from Salisbury to Berlin. Marsalek arranged for the apartment to be broken into. Grozev eventually left Austria after being told the threat to him was credible. Anna Thalhammer at Profil, who has been writing on Ott and Marsalek for years, is a witness in the trial and has described being a target of disinformation and physical surveillance in this city.</p>



<p class="wp-block-paragraph">The personal details are not the point. The point is that the same investigation that produced Ott&#8217;s arrest also surfaced what the Bulgarian cell had been doing in Vienna for months, and almost none of it was prosecutable here. That is the political fact that finally moved the bill.</p>



<h2 class="wp-block-heading">Two things missing from the conversation</h2>



<p class="wp-block-paragraph">The first is operational capacity. Writing §319a into the Criminal Code is one parliamentary vote. Building the kind of counter-intelligence service that can actually make a §319a case against a foreign professional working under official or commercial cover in Vienna is several budget cycles, at minimum.</p>



<p class="wp-block-paragraph">The DSN took over from the BVT in late 2021 and is still rebuilding. Sylvia Mayer started as the first female DSN director on 1 January. Allied services I have spoken to over the past two years tend to describe the DSN as analytically competent and operationally thin, and the gap between those two things is exactly where §319a cases live. I am not saying nothing will happen. I am saying that for the first two or three years after this passes, the cases that get charged will probably look like the Bulgarian one, meaning they will fall into Austria&#8217;s lap because someone else made the original arrests.</p>



<p class="wp-block-paragraph">The second is press freedom. The widened <em>Nachteil der Republik</em> language is broad enough that I can already see a future prosecutor reaching for it against a journalist who publishes material the government finds awkward, particularly anything connected to allied state operations on Austrian soil. I want a clear source-protection carve-out in the final text. Falter&#8217;s reporting did not mention one. The Justice Ministry will presumably say existing media protections apply. In practice they do not always apply, especially when the story embarrasses a partner government.</p>



<h2 class="wp-block-heading">What this actually changes</h2>



<p class="wp-block-paragraph">It changes what the prosecutor can charge once a case has been built. That is a real change.</p>



<p class="wp-block-paragraph">It does not change the geographic and institutional facts that make Vienna useful in the first place. It does not change the diplomatic immunities attached to the several thousand accredited foreign personnel in this city. It does not change the political reality that the FPÖ, currently leading in the polls, has spent the better part of a decade benefiting from the absence of pressure on this question and has every interest in the new law being enforced as gently as possible if and when they are in government.</p>



<p class="wp-block-paragraph">The Ott verdict is the test, not the law. If a jury sitting through 172 pages of evidence and ninety witnesses cannot bring itself to convict a former officer on the espionage count, the new statute will not matter, because no prosecutor will want to be the one to bring the next case. If they do convict, the Republic will have signalled, for the first time in a long time, that it is prepared to treat espionage on its territory as the serious matter it has always been.</p>



<p class="wp-block-paragraph">&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Open Source, Ignored: Why Europe Must Get Serious About Social Media Threat Monitoring Before the Next School Attack</title>
		<link>https://www.digitalintelligence.at/open-source-ignored-why-europe-must-get-serious-about-social-media-threat-monitoring-before-the-next-school-attack/</link>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Thu, 16 Apr 2026 10:43:33 +0000</pubDate>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[OSINT]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4434</guid>

					<description><![CDATA[On April 15, 2026, a 14-year-old student walked into Ayser Çalık Middle School in Kahramanmaraş, Turkey, carrying five firearms and seven magazines. By the time it was over, nine people were dead. One of them was a math teacher named Ayla Kara, who died trying to shield her students. The attacker, İsa Aras Mersinli, also died. He turned the gun on himself. In the hours that followed, investigators began working through his digital life. What they found was not a mystery. It was a map, drawn in plain sight, that nobody had thought to read. A Profile Picture as a]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">On April 15, 2026, a 14-year-old student walked into Ayser Çalık Middle School in Kahramanmaraş, Turkey, carrying five firearms and seven magazines. By the time it was over, nine people were dead. One of them was a math teacher named Ayla Kara, who died trying to shield her students.</p>



<p class="wp-block-paragraph">The attacker, İsa Aras Mersinli, also died. He turned the gun on himself.</p>



<p class="wp-block-paragraph">In the hours that followed, investigators began working through his digital life. What they found was not a mystery. It was a map, drawn in plain sight, that nobody had thought to read.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">A Profile Picture as a Manifesto</h2>



<p class="wp-block-paragraph">Mersinli&#8217;s WhatsApp profile picture was a photo of Elliot Rodger.</p>



<p class="wp-block-paragraph">For those unfamiliar with the name: Rodger was a 22-year-old who, in May 2014, killed six people in Isla Vista, California before taking his own life. Before the attack, he uploaded videos explaining his motivations and left behind a 137-page document he called his manifesto. He had become, in the years since, an icon in online communities built around male grievance, rejection, and the glorification of mass violence. He is arguably the most influential figure in the so-called &#8220;incel&#8221; subculture that has since been linked to multiple attacks across North America and Europe.</p>



<p class="wp-block-paragraph">A teenager in southern Turkey had put this man&#8217;s face as his public-facing identity. He had done it voluntarily. He had done it where anyone who knew him could see it.</p>



<p class="wp-block-paragraph">His computer also contained a document, dated April 11, 2026, four days before the attack, describing what he was planning to do.</p>



<p class="wp-block-paragraph">The Turkish Prosecution&#8217;s Office confirmed the attack was premeditated. There was no spontaneity here. There was a timeline, a target, and a model.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">The Telegram Layer</h2>



<p class="wp-block-paragraph">The attack in Kahramanmaraş did not happen in isolation. The same week, another school in Şanlıurfa was targeted. And in the immediate aftermath, a Telegram group called &#8220;C31K,&#8221; with approximately 100,000 members, began circulating messages celebrating the attackers and posting specific schools, dates, and locations as the next targets.</p>



<p class="wp-block-paragraph">Turkish authorities identified 591 social media accounts spreading what they described as disinformation and provocation. Cybercrime units opened investigations. The group had previously been connected to two separate murder cases in Turkey.</p>



<p class="wp-block-paragraph">This is a pattern that European security analysts should be paying very close attention to.</p>



<p class="wp-block-paragraph">What we are seeing is not just copycat violence driven by media coverage. It is something more structured: online communities that actively cultivate the mythology of mass attackers, offer belonging to isolated and radicalized young people, and then, after an attack, use it as recruitment material and operational inspiration for the next one. The digital infrastructure of this ecosystem runs primarily through encrypted messaging platforms, gaming communities, and fringe imageboards, most of which operate with minimal oversight.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">The Incel Pipeline and Its European Reach</h2>



<p class="wp-block-paragraph">The incel phenomenon is not a Turkish story. It is not an American one either. Since Rodger&#8217;s 2014 attack, the ideological framework he helped define has been cited in mass casualty events in Canada, the United Kingdom, Germany, and Finland. In 2018, a van attack in Toronto killed ten people. In 2021, a man in Plymouth, England killed five. In both cases, investigators found significant engagement with incel forums and, in particular, with content venerating Elliot Rodger specifically.</p>



<p class="wp-block-paragraph">What connects Kahramanmaraş to Plymouth to Toronto is not geography. It is an online ecosystem that operates without borders and targets young men who feel, for whatever reason, invisible and powerless.</p>



<p class="wp-block-paragraph">In Mersinli&#8217;s case, the behavioral indicators were present. Teachers described him as withdrawn and increasingly isolated. He was reportedly spending large amounts of time online. His social media profile displayed an open tribute to a foreign mass killer. His computer contained a pre-attack document. None of this triggered a formal intervention.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">What Monitoring Actually Means</h2>



<p class="wp-block-paragraph">There is a legitimate debate in Europe about the limits of social media surveillance, and it is a debate worth having. The GDPR framework, fundamental rights law, and democratic principles all impose real constraints on how states can monitor private communications. Those constraints exist for good reason.</p>



<p class="wp-block-paragraph">But what happened in Kahramanmaraş was not a question of encrypted messages or private channels. Mersinli&#8217;s profile picture was visible to anyone who had his contact. His behavioral isolation was observable to teachers and classmates. The warning signs were not hidden. They were unread.</p>



<p class="wp-block-paragraph">This is where the conversation about monitoring needs to be more precise. The choice is not between mass surveillance and willful blindness. There is a middle space that involves:</p>



<p class="wp-block-paragraph"><strong>Training educators and school counselors</strong> to recognize the specific behavioral and digital markers associated with radicalization toward mass violence. A student who idolizes a foreign school shooter is not simply &#8220;troubled.&#8221; That is a specific and documented warning sign with its own established literature.</p>



<p class="wp-block-paragraph"><strong>Building structured reporting pathways</strong> between schools and threat assessment teams. Several European countries, including Germany and the Netherlands, have developed multi-agency behavioral threat assessment programs modeled on the US Secret Service&#8217;s work in this area. These programs work when they are actually resourced and integrated into school environments.</p>



<p class="wp-block-paragraph"><strong>Monitoring open-source digital signals</strong> without requiring access to private communications. What Mersinli displayed on his profile was open-source. A school or a social worker or a platform flagging system could theoretically have caught it. The question is whether any of those systems were in place or whether anyone was looking.</p>



<p class="wp-block-paragraph"><strong>Engaging platform providers on incel content specifically.</strong> The Telegram group that celebrated the Kahramanmaraş attack had 100,000 members and had already been linked to two previous murders. That it continued to operate until this moment is a failure of platform governance, not an intelligence gap.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">The Copycat Problem Is Structural</h2>



<p class="wp-block-paragraph">One of the more uncomfortable findings in mass violence research is that extensive media coverage of attackers, particularly sympathetic or fascinated coverage that focuses on the attacker&#8217;s psychology and background, demonstrably increases the probability of subsequent attacks. The so-called &#8220;contagion effect&#8221; has been documented in peer-reviewed research for decades.</p>



<p class="wp-block-paragraph">Online communities have essentially weaponized this effect. They do not just report on attacks. They archive them, analyze them, build personas around the perpetrators, and actively market them as role models to young men who are already vulnerable. Elliot Rodger has been dead for twelve years. He has, in that time, inspired more violence than he carried out himself.</p>



<p class="wp-block-paragraph">Mersinli did not invent his frame of reference. Someone, or more likely some community, handed it to him. That community is still operating. It has 100,000 members in a single Telegram group in Turkey alone.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">What Europe Should Be Doing Differently</h2>



<p class="wp-block-paragraph">The EU&#8217;s Digital Services Act, fully in force since 2024, creates obligations for very large online platforms to assess and mitigate systemic risks, including risks to public security. Mass violence glorification communities of 100,000 members on major messaging platforms are, by any reasonable reading, a systemic risk. Whether the DSA&#8217;s enforcement mechanisms are being applied to this specific category of content with any seriousness is an open question.</p>



<p class="wp-block-paragraph">At the national level, the more practical gap is in threat assessment capacity at the local level. National intelligence services are not positioned to monitor every isolated teenager in every European school. But schools, social services, and local police can be. They need better tools, better training, and better coordination structures to do it.</p>



<p class="wp-block-paragraph">The UK&#8217;s Channel program, Germany&#8217;s VERA-2 radicalization assessment tool, and the Netherlands&#8217; integrated approach to neighborhood-level threat assessment all represent the kind of infrastructure that can catch individuals before they cross a threshold. The precondition is that people in daily contact with at-risk youth know what they are looking for.</p>



<p class="wp-block-paragraph">A boy who puts Elliot Rodger on his profile picture is telling you something. The question is whether anyone in his environment had been taught to hear it.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">A Note on What This Is Not</h2>



<p class="wp-block-paragraph">This is not a case where better surveillance technology would have made the difference. It is not a case for reading teenagers&#8217; private messages or expanding state access to encrypted communications. The signals that Mersinli sent were not encrypted. They were in plain view on a platform billions of people use every day.</p>



<p class="wp-block-paragraph">What failed was human awareness, institutional training, and platform responsibility. Those are solvable problems, and solving them does not require trading privacy for security. It requires investment, coordination, and a clearer-eyed understanding of how radicalization toward mass violence actually works in 2026.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AI Broke the Criminal Profile. Now What?</title>
		<link>https://www.digitalintelligence.at/ai-broke-the-criminal-profile-now-what/</link>
					<comments>https://www.digitalintelligence.at/ai-broke-the-criminal-profile-now-what/#respond</comments>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Thu, 26 Mar 2026 21:36:48 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Intelligence]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4428</guid>

					<description><![CDATA[How artificial intelligence is rewriting the rules of criminal behavior, and why the profiler&#8217;s playbook needs a fundamental reset. Criminal profiling has always rested on one core assumption: criminals are creatures of habit. They leave behavioral signatures. They escalate predictably. Their psychology leaks through their methods. For decades, this held up well enough. The FBI&#8217;s Behavioral Analysis Unit built an entire discipline around reading crime scenes like psychological fingerprints, classifying offenders as organized or disorganized, mapping modus operandi against personality types, and predicting the next move based on the last one. Then AI entered the equation. Not as a tool]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">How artificial intelligence is rewriting the rules of criminal behavior, and why the profiler&#8217;s playbook needs a fundamental reset.</p>



<p class="wp-block-paragraph">Criminal profiling has always rested on one core assumption: criminals are creatures of habit. They leave behavioral signatures. They escalate predictably. Their psychology leaks through their methods. For decades, this held up well enough. The FBI&#8217;s Behavioral Analysis Unit built an entire discipline around reading crime scenes like psychological fingerprints, classifying offenders as organized or disorganized, mapping modus operandi against personality types, and predicting the next move based on the last one.</p>



<p class="wp-block-paragraph">Then AI entered the equation. Not as a tool for investigators, but as a tool for criminals. And it didn&#8217;t just make crime easier. It fundamentally altered who commits crime, how they behave while doing it, and what traces they leave behind. That shift is quietly dismantling the foundations of classical profiling.</p>



<h2 class="wp-block-heading">The Old Rules</h2>



<p class="wp-block-paragraph">Traditional profiling works on a set of behavioral axioms. Behavior reflects personality. Crime scenes tell stories about the offender&#8217;s psychology. Signature behaviors, those acts unnecessary for completing the crime but driven by deep psychological needs, remain consistent across offenses. Modus operandi evolves as the offender learns, but the core emotional drivers stay stable.</p>



<p class="wp-block-paragraph">These principles gave investigators a framework: analyze the scene, read the behavior, build a psychological sketch, narrow the suspect pool. It was never perfect. FBI internal data suggested profiling contributed to solving roughly 17% of cases where it was applied. Academic reviews have been even less generous. But as a supplementary tool alongside forensic evidence and traditional detective work, it had value.</p>



<p class="wp-block-paragraph">The problem is that every one of these axioms assumes the offender is acting from their own psychology, with their own skills, under their own operational limitations. AI has removed those constraints.</p>



<h2 class="wp-block-heading">The New Criminal Doesn&#8217;t Fit the Old Mold</h2>



<p class="wp-block-paragraph">Consider what AI has done to the barrier of entry for sophisticated crime. Voice cloning now requires 20 to 30 seconds of audio. Convincing deepfake video can be produced in under an hour using freely available tools. Dark LLMs and jailbreak-as-a-service platforms generate phishing campaigns, social engineering scripts, and even malware with minimal technical knowledge required from the operator.</p>



<p class="wp-block-paragraph">This is the first major break from classical profiling logic. The old model assumed a correlation between crime sophistication and offender capability. An organized crime scene implied an intelligent, socially competent, methodical individual. A well-crafted social engineering attack suggested experience, psychological insight, and confidence. AI has severed that link entirely. A teenager with a laptop can now execute attacks that would have previously required a team of experienced operatives.</p>



<p class="wp-block-paragraph">The Trend Micro research team documented this shift in their 2025 criminal AI report: the underground ecosystem has moved from experimentation to industrialization. Criminals no longer build their own tools. They rent them. The barrier has collapsed, the tooling has professionalized, and the attack surface has expanded across every domain. Telegram channels now recruit &#8220;AI video actors&#8221; and &#8220;deepfake presenters&#8221; as a service category.</p>



<p class="wp-block-paragraph">What does this mean for profiling? It means the behavioral signature, the profiler&#8217;s primary analytical unit, is increasingly a product of the tool rather than the person behind it. When a deepfake CEO orders a wire transfer on a video call, the behavioral cues that investigators would normally analyze (speech patterns, confidence level, emotional state, decision-making style) belong to the AI model, not the attacker. The criminal becomes invisible behind the synthetic layer.</p>



<h2 class="wp-block-heading">AI Doesn&#8217;t Just Enable Crime. It Redirects It.</h2>



<p class="wp-block-paragraph">Here is the less obvious but more consequential effect. AI isn&#8217;t simply making existing criminal patterns more efficient. It is creating entirely new behavioral categories that classical profiling has no framework to address.</p>



<p class="wp-block-paragraph">Take synthetic identity fraud. Criminals now build complete fake identities using a mix of real and fabricated data, pass automated KYC checks with AI-generated documents, and operate accounts that leave behind a perfectly normal behavioral footprint. There is no psychological signature to read because the &#8220;person&#8221; never existed. The behavior was designed by algorithm to look average.</p>



<p class="wp-block-paragraph">Or consider AI-powered behavioral mimicry. Trend Micro and Group-IB both documented cases where AI studied institutional behavior patterns (transaction timing, approval workflows, communication styles) and then replicated them precisely to avoid triggering fraud detection. The criminal isn&#8217;t acting like themselves anymore. They are acting like the system expects a legitimate user to act. This is the opposite of what profiling relies on: instead of behavior revealing identity, behavior is engineered to conceal it.</p>



<p class="wp-block-paragraph">The 2025 AI Incident Database recorded 346 AI-related incidents in a single year. Of those, 179 involved deepfake impersonation. The targets ranged from CEOs to private individuals. In one case, a British widow lost half a million pounds in a romance scam powered by deepfake video of a celebrity. A Florida couple lost $45,000 to a fabricated Elon Musk giveaway. These are not sophisticated adversaries with complex psychological profiles. These are operators running playbooks, sometimes literally purchased as step-by-step tutorials from underground forums.</p>



<h2 class="wp-block-heading">The Profiling Crisis</h2>



<p class="wp-block-paragraph">Classical profiling depends on three things that AI is systematically eroding:</p>



<p class="wp-block-paragraph"><strong>Behavioral consistency.</strong> AI allows criminals to switch personas, communication styles, and operational methods between attacks with zero psychological cost. There is no escalation pattern to track because each attack can be calibrated independently by the tool.</p>



<p class="wp-block-paragraph"><strong>Skill-behavior correlation.</strong> The assumption that crime complexity reflects offender sophistication is broken. AI democratizes capability. The profile of &#8220;who could do this&#8221; expands from a narrow suspect pool to essentially anyone with internet access and basic prompt engineering skills.</p>



<p class="wp-block-paragraph"><strong>Psychological leakage.</strong> Crime scenes and communications used to leak the offender&#8217;s personality involuntarily. When AI generates the phishing email, conducts the video call, or crafts the social engineering script, the psychological content belongs to the model&#8217;s training data, not the operator&#8217;s mind.</p>



<p class="wp-block-paragraph">This doesn&#8217;t mean profiling is dead. But it means the discipline needs to shift its unit of analysis. Instead of asking &#8220;what kind of person did this,&#8221; investigators increasingly need to ask &#8220;what kind of toolchain produced this behavior.&#8221; The profiling target is migrating from psychology to infrastructure.</p>



<h2 class="wp-block-heading">Where Profiling Still Works, and Where It Can&#8217;t</h2>



<p class="wp-block-paragraph">Profiling retains value in crimes that remain fundamentally physical and personal: serial violent offenses, sexual crimes, stalking, arson. These still carry strong behavioral signatures because the offender&#8217;s psychological needs drive the act directly, not through a technological intermediary.</p>



<p class="wp-block-paragraph">But for the fastest-growing categories of crime (fraud, identity theft, business email compromise, financial manipulation, extortion through synthetic media), classical profiling is increasingly irrelevant. The offender&#8217;s psychology matters less than their toolkit. Their behavioral patterns are shaped more by the AI model they are using than by their own personality.</p>



<p class="wp-block-paragraph">The intelligence community and law enforcement agencies that recognize this shift will adapt. Those that keep trying to build psychological profiles of operators who are essentially invisible behind AI-generated behavior will waste time and resources chasing ghosts.</p>



<p class="wp-block-paragraph">The profiler&#8217;s question used to be: <em>Who is this person?</em></p>



<p class="wp-block-paragraph">Now it needs to be: <em>What system is this person hiding behind, and where does that system leak?</em></p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.digitalintelligence.at/ai-broke-the-criminal-profile-now-what/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The First Cyber War: How Digital Intelligence Shaped Operation Epic Fury</title>
		<link>https://www.digitalintelligence.at/the-first-cyber-war-how-digital-intelligence-shaped-operation-epic-fury/</link>
					<comments>https://www.digitalintelligence.at/the-first-cyber-war-how-digital-intelligence-shaped-operation-epic-fury/#respond</comments>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Mon, 16 Mar 2026 02:30:49 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Worldwide]]></category>
		<category><![CDATA[hybrid threats]]></category>
		<category><![CDATA[intelligence analysis]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4422</guid>

					<description><![CDATA[I&#8217;ve been covering cyber threats for years now, and I&#8217;ve sat through countless conference panels where retired generals talk about &#8220;the coming cyber war.&#8221; Always in the future tense. Always hypothetical. That era is over. On February 28, the US and Israel hit Iran. But the shooting started in cyberspace. Hours before any jet crossed Iranian airspace, US Cyber Command had already gutted Tehran&#8217;s communications and sensor networks. General Dan Caine confirmed it publicly: space and cyber operations came first, leaving Iran unable to &#8220;see, coordinate, or respond effectively.&#8221; Think about what that means. By the time the bombs dropped,]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">I&#8217;ve been covering cyber threats for years now, and I&#8217;ve sat through countless conference panels where retired generals talk about &#8220;the coming cyber war.&#8221; Always in the future tense. Always hypothetical. That era is over.</p>



<p class="wp-block-paragraph">On February 28, the US and Israel hit Iran. But the shooting started in cyberspace. Hours before any jet crossed Iranian airspace, US Cyber Command had already gutted Tehran&#8217;s communications and sensor networks. General Dan Caine confirmed it publicly: space and cyber operations came first, leaving Iran unable to &#8220;see, coordinate, or respond effectively.&#8221; Think about what that means. By the time the bombs dropped, the Iranian military was already operating blind.</p>



<p class="wp-block-paragraph">And it only got stranger from there.</p>



<h2 class="wp-block-heading">Tehran&#8217;s traffic cameras killed the Supreme Leader</h2>



<p class="wp-block-paragraph">This is the part that reads like fiction but isn&#8217;t. Israeli intelligence had been inside Tehran&#8217;s traffic camera network for what appears to be months, possibly longer. Not just watching. Feeding the footage into a machine alongside CIA human intelligence, signals intercepts, satellite imagery, communications metadata. The Financial Times was first to report the scope of it. One Israeli source called the whole setup an AI-powered &#8220;target production machine.&#8221; You pour data in, you get a 14-digit grid coordinate out.</p>



<p class="wp-block-paragraph">They built what they called a &#8220;life pattern&#8221; for Khamenei. His routes. His schedules. Which aides traveled with him. When his security detail was thinnest. The Jerusalem Post reported that Israeli analysts mapped these patterns over an extended period, cross-referencing traffic camera data with other intelligence streams.</p>



<p class="wp-block-paragraph">Then the CIA confirmed Khamenei would attend a senior military meeting on the morning of the 28th. The entire operation timeline shifted around that single piece of intelligence. The result: Khamenei dead, along with the IRGC commander, the defense minister, the chief of staff, the head of the National Defense Council. More than a dozen top officials, gone before lunch.</p>



<p class="wp-block-paragraph">I keep coming back to what RUSI wrote about this. They pointed out something that gets lost in the spectacle: cyber&#8217;s biggest contribution here wasn&#8217;t disruption. It was reconnaissance. Years of quiet network access, pre-positioned in Iranian infrastructure, activated at the decisive moment. That&#8217;s not a hack. That&#8217;s a long-term intelligence operation that happened to run through fiber optic cables instead of dead drops.</p>



<h2 class="wp-block-heading">Israel doesn&#8217;t want to depend on Silicon Valley for its kill chain</h2>



<p class="wp-block-paragraph">Here&#8217;s something that should concern anyone in the AI policy space. Haaretz reporter Omer Benjakob told NPR that Israel is building its own military AI systems specifically because it can&#8217;t afford to rely on American commercial platforms. His quote was memorable: &#8220;One day someone will discover we also use Claude, and then there&#8217;ll be a protest in San Francisco, and then they&#8217;ll take Claude away from us.&#8221;</p>



<p class="wp-block-paragraph">He said this on the record.</p>



<p class="wp-block-paragraph">The Anthropic dispute with the Trump administration over military use of Claude is well documented at this point. But the strategic implications go deeper than one company&#8217;s ethical stance. If your precision targeting pipeline depends on a model whose provider can revoke access based on a policy change or public pressure campaign, you have a serious sovereignty problem. Israel clearly sees it that way. Others will too.</p>



<p class="wp-block-paragraph">None of this means AI targeting is ready for primetime, though. The March 8 strike on the Shajareh Tayyebeh school in Minab killed 165 people. 110 of them were schoolgirls. The building used to be a military base. Whether AI targeting systems worked off stale data is still under investigation, but a UCL computer scientist put the core issue bluntly: &#8220;This stuff is only two or three years old.&#8221;</p>



<p class="wp-block-paragraph">Speed and precision are not the same thing. This war is proving that every day.</p>



<h2 class="wp-block-heading">60 hacktivist groups, one internet blackout, and a paradox</h2>



<p class="wp-block-paragraph">Iran&#8217;s internet dropped to somewhere between 1% and 4% connectivity on February 28. That&#8217;s barely functional. You&#8217;d think that would cripple the regime&#8217;s cyber response. And for the state-run APT groups operating inside Iran, it probably did, at least initially.</p>



<p class="wp-block-paragraph">But that&#8217;s not how Iran&#8217;s cyber infrastructure actually works. Tehran has spent years building out proxy networks. Hacktivist groups, some loosely affiliated, some directly run by MOIS or the IRGC, operating from outside Iran&#8217;s borders. When the internet went dark domestically, these external nodes lit up.</p>



<p class="wp-block-paragraph">Unit 42 counted around 60 groups active in the first week alone. Handala Hack, which has documented ties to the Ministry of Intelligence, ran wiper and exfiltration campaigns against Israeli defense targets. On March 12, they hit Stryker, one of the largest medical technology companies in the US. MuddyWater, an IRGC-linked group, turned out to have pre-planted backdoors in Israeli-adjacent defense and financial networks. They didn&#8217;t need to break in after the war started. They were already inside.</p>



<p class="wp-block-paragraph">March 2 was when things escalated beyond the Middle East. Pro-Russian hacktivist group NoName057(16) formally joined the Iranian coalition. Since then, the combined front has been hitting targets in Cyprus, Romania, across the Gulf states. Government websites, airports, telecom providers. The Russia-Iran cyber axis is no longer theoretical. It&#8217;s operational.</p>



<p class="wp-block-paragraph">Now, the OT and SCADA claims. Groups have been posting screenshots alleging access to Israeli water systems, Jordanian grain storage controls, various industrial systems. John Hultquist at Google Threat Intelligence has been saying for years that Iran exaggerates its cyber successes for psychological effect, and he&#8217;s right. A lot of these claims don&#8217;t hold up under scrutiny.</p>



<p class="wp-block-paragraph">But I&#8217;d be careful about dismissing all of it. CyberAv3ngers compromised real US water systems in 2023 using nothing more sophisticated than default passwords on Unitronics PLCs. The capability is proven. What we don&#8217;t know is how much coordination these proxy groups can maintain while their state sponsors are dealing with an actual shooting war.</p>



<h2 class="wp-block-heading">The information battlefield is now indistinguishable from the physical one</h2>



<p class="wp-block-paragraph">Before the first airstrike, Israel had already compromised BadeSaba, a popular Iranian prayer app with over five million users. They pushed messages to regime supporters urging military defection. They hijacked state news websites to publish anti-regime content. Later, they sent AI-equipped drone swarms over Tehran to hit Basij militia checkpoints.</p>



<p class="wp-block-paragraph">Iran&#8217;s been playing the same game in reverse for years. Dozens of Israeli nationals recruited through Telegram, paid to commit low-level sabotage: starting fires, spraying antigovernment graffiti, sowing social discord. A Clemson University researcher called Israel&#8217;s approach &#8220;psychological operations integrated with military operations in one clean campaign with a single goal: toppling the Iranian regime.&#8221;</p>



<p class="wp-block-paragraph">Both sides have turned every digital platform into a weapon. Messaging apps, news sites, social media, traffic infrastructure. There&#8217;s no longer a meaningful line between &#8220;cyber operation&#8221; and &#8220;influence operation.&#8221; It&#8217;s all one battlefield.</p>



<h2 class="wp-block-heading">CISA is running on fumes at the worst possible time</h2>



<p class="wp-block-paragraph">I can&#8217;t write about this conflict&#8217;s cyber dimension without mentioning what&#8217;s happening at CISA. The agency has lost roughly a third of its staff. The temporary director got reassigned to another corner of DHS right as the war kicked off. FBI and NSA have put out joint warnings about Iranian targeting of US defense contractors and financial firms. Jamie Dimon at JPMorgan went on CNBC and said banks are bracing for a wave of cyber and terrorist attacks.</p>



<p class="wp-block-paragraph">So at the exact moment when motivated, state-aligned Iranian cyber actors are looking for American targets, the primary agency that&#8217;s supposed to coordinate civilian cyber defense is hollowed out. That should worry people far more than it seems to.</p>



<h2 class="wp-block-heading">European organizations need to pay attention</h2>



<p class="wp-block-paragraph">The NCSC in the UK puts Iran in the same threat tier as Russia and North Korea. That was true before February 28. It&#8217;s more true now, because the Russian hacktivist groups that joined the Iranian coalition have broadened the targeting aperture into Europe.</p>



<p class="wp-block-paragraph">Organizations in Austria and the DACH region might feel geographically removed from this conflict. They&#8217;re not. If your supply chain touches Israeli technology, if your cloud provider hosts workloads for companies in targeted sectors, if you run Israeli-manufactured OT equipment, you&#8217;re in scope. CyberAv3ngers targeted Unitronics PLCs in 2023 specifically because they were Israeli-made. That logic doesn&#8217;t stop at borders.</p>



<p class="wp-block-paragraph">Trellix published research showing that Iranian threat groups have expanded from targeting a handful of countries to more than twenty since the conflict started. Western Europe is on that list. The tactics are familiar: spear-phishing, unpatched edge devices, ransomware that looks criminal but serves state interests, data leaks timed for maximum embarrassment.</p>



<h2 class="wp-block-heading">This doesn&#8217;t end when the bombing stops</h2>



<p class="wp-block-paragraph">Iranian APT groups like APT42, APT34 and MuddyWater have a well-documented habit of running campaigns for years after the initial trigger. The proxy networks are activated. Russia and Iran have found operational common ground in cyberspace. The infrastructure built for this conflict will be repurposed, not dismantled.</p>



<p class="wp-block-paragraph">Two decades of defense policy debates about whether cyber is a &#8220;real&#8221; domain of warfare just got their answer. In this conflict, cyber was the opening move, the intelligence backbone, the targeting enabler, the psychological weapon, and the retaliatory instrument of choice for a regime that lost its conventional military options in a matter of hours.</p>



<p class="wp-block-paragraph">We&#8217;re not waiting for the first cyber war anymore. We&#8217;re in it.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>
]]></content:encoded>
					
					<wfw:commentRss>https://www.digitalintelligence.at/the-first-cyber-war-how-digital-intelligence-shaped-operation-epic-fury/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
