<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Analysis &#8211; Digital Intelligence</title>
	<atom:link href="https://www.digitalintelligence.at/category/analysis/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.digitalintelligence.at</link>
	<description>Analysis &#38; Consulting</description>
	<lastBuildDate>Sun, 16 Aug 2026 16:58:55 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://www.digitalintelligence.at/wp-content/uploads/2025/11/android-chrome-512x512-1-60x60.png</url>
	<title>Analysis &#8211; Digital Intelligence</title>
	<link>https://www.digitalintelligence.at</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Seven Years of Deliveries, One Arrest</title>
		<link>https://www.digitalintelligence.at/seven-years-of-deliveries-one-arrest/</link>
					<comments>https://www.digitalintelligence.at/seven-years-of-deliveries-one-arrest/#respond</comments>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Sun, 16 Aug 2026 16:57:48 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4506</guid>

					<description><![CDATA[On Monday, 10 August, the Interior Ministry put out a press release announcing a success. The DSN had dismantled an international network of companies that moved sanctioned industrial goods to Russia through a firm registered in Vienna. Machine tools and special metalworking equipment, the kind you need to mill engine parts. According to the DSN&#8217;s own assessment, the goods ended up in the production of engines for cruise missiles and combat aircraft. State Secretary Leichtfried called it unacceptable and congratulated the investigators. Fine. It is unacceptable. But read the press release a second time and pay attention to the dates,]]></description>
										<content:encoded><![CDATA[<p>On Monday, 10 August, the Interior Ministry put out a press release announcing a success. The DSN had dismantled an international network of companies that moved sanctioned industrial goods to Russia through a firm registered in Vienna. Machine tools and special metalworking equipment, the kind you need to mill engine parts. According to the DSN&#8217;s own assessment, the goods ended up in the production of engines for cruise missiles and combat aircraft. State Secretary Leichtfried called it unacceptable and congratulated the investigators.</p>
<p>Fine. It is unacceptable. But read the press release a second time and pay attention to the dates, because the dates are the actual story.</p>
<p>The company had been supplying Russian military end users since 2019. Not since the full-scale invasion. Since 2019, five years after Crimea, in the middle of a sanctions regime that every exporter of dual-use goods in this country was legally obliged to understand. When the EU tightened sanctions after February 2022, the company did not stop. It rerouted. The goods travelled through firms in Turkey, the UAE, Hong Kong, Belarus, Kyrgyzstan, South Korea, Poland and Lithuania. European manufacturers were shown forged end-user certificates promising the equipment would stay in third countries. The real customers, per the investigation, were companies attributable to Rostec, the conglomerate at the heart of the Russian defence industry.</p>
<p>The first search warrants came in August 2025. Four properties, searched simultaneously, roughly forty data storage devices seized. In mid-May of this year the managing director and co-owner, a 28-year-old Belarusian citizen, was arrested. He has been sitting in pre-trial detention since. Total deliveries: more than 3.3 million euros.</p>
<p>Count it out. Seven years of deliveries. Three of them under the hardest sanctions regime Europe has ever imposed. Then somebody knocked on the door.</p>
<p>The press release celebrates the ending. Nobody in it explains the beginning or the middle.</p>
<h2>The pattern, again</h2>
<p>If you have been reading this site for a while, you already know where this is going. I have spent the better part of a year writing about the same underlying condition from different angles. A capital full of accredited intelligence officers. An espionage law that until recently did not care unless Austria itself was the target. A counterintelligence apparatus that needed six and a half years to attribute a cyberattack on its own Foreign Ministry.</p>
<p>Sanctions evasion is the trade version of the same disease. Espionage needs residency and cover. Sanctions evasion needs a jurisdiction and clean paperwork. Austria offers both, and cheaply. A GmbH costs almost nothing to set up, the banking works, and the customs and licensing apparatus that is supposed to catch this was never built for adversarial trade, for counterparties who forge documents professionally and route consignments through five countries as a matter of routine.</p>
<p>To be fair, this is not an Austrian invention. The Kyiv Independent showed in June, with customs records, how EU-made machinery keeps reaching Russian missile plants through third-country intermediaries. C4ADS has mapped the broker geography in detail: China and Hong Kong, Turkey, the UAE. Moscow&#8217;s procurement people treat European export controls as a delay, not an obstacle.</p>
<p>But this case is ours, and it raises a question nobody at Monday&#8217;s announcement wanted to touch: how many companies like this are operating in Vienna right now, and who exactly is looking for them?</p>
<h2>Note what solved this case</h2>
<p>There is a second point, and it connects to something this site has covered at length this year.</p>
<p>Nobody read anyone&#8217;s Signal messages to crack this network. It was cracked with the oldest tools in the trade: corporate records, customs data, a paper trail, coordinated house searches, forty seized hard drives, and prosecutors willing to hold a suspect while the analysis ran. Financial and trade forensics. The boring end of intelligence work.</p>
<p>I find that worth saying out loud in the same year the DSN&#8217;s flagship legislative project, the surveillance of encrypted messengers, sits before the Constitutional Court, sold to the public as indispensable against exactly this category of threat. Terrorism, extremism, espionage. Here is arguably the most consequential hostile-state operation uncovered in Austria this year, one that fed the engines of Russian cruise missiles, and it was taken apart with powers the state has had for decades.</p>
<p>The lesson is not that new powers are never justified. The lesson is that the binding constraint in Austrian counterintelligence has rarely been legal authority. It has been attention, staffing, and the willingness to sit with boring documents for a very long time. No trojan fixes that.</p>
<h2>Brussels has the tool and will not use it</h2>
<p>One more layer. In June 2023 the EU&#8217;s 11th sanctions package created a mechanism to ban exports of sensitive goods to third countries that systematically re-export them to Russia. It took until the 20th package for Brussels to activate it, and when it finally did, it applied the ban to one product category and one country: CNC machine tools to Kyrgyzstan. By the Kyiv School of Economics&#8217; numbers, Kyrgyzstan supplied about one percent of Russia&#8217;s battlefield goods. China and Hong Kong supplied the overwhelming majority.</p>
<p>Kyrgyzstan appears in the Vienna network&#8217;s country list. So do Hong Kong, Turkey and the UAE. None of those three face the mechanism, because they are trading partners with leverage, and Brussels knows it. Which means enforcement falls back on the member states, on national services finding the Vienna node of a network whose other nodes will simply reconstitute somewhere else next quarter.</p>
<h2>What should be asked at trial</h2>
<p>The proceedings are ongoing and the presumption of innocence applies to everyone involved. But the questions are already on the table, and they should be asked in court and in parliament.</p>
<p>Which European manufacturers shipped against those forged certificates, and what did their due diligence actually consist of? Criminal liability under EU law generally requires knowledge, but &#8220;we saw a stamp and stopped asking&#8221; is a compliance posture, not a defence of the system. When did Austrian authorities receive the first indication, from customs data, from a partner service, from anyone, and what happened to it between 2019 and August 2025? And is sanctions enforcement at the DSN a unit with a headcount, or a project with a press release?</p>
<p>The ministry says it will continue to act consistently against anyone supporting the Russian armaments apparatus. Good. The measure of that sentence will not be the next announcement. It will be how many years the next network gets to run before anyone notices.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.digitalintelligence.at/seven-years-of-deliveries-one-arrest/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Vienna Buys the Bidstream</title>
		<link>https://www.digitalintelligence.at/vienna-buys-the-bidstream/</link>
					<comments>https://www.digitalintelligence.at/vienna-buys-the-bidstream/#respond</comments>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Mon, 27 Jul 2026 18:22:41 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[OSINT]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[European security]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4499</guid>

					<description><![CDATA[Austria has renewed a licence for a surveillance system built on advertising data. Nobody in government will say under what legal authority, and the data protection regulator was never asked. A procurement notice on Austria&#8217;s public tender portal records the extension of a licence agreement between the Interior Ministry and the US vendor Penlink, worth roughly 1.85 million euros over two years. The package covers Penlink products including Webloc. Der Standard reported the deal first; netzpolitik.org followed with the ministry&#8217;s response, which was that no public information can be given about specific software solutions, and that anything the ministry uses,]]></description>
										<content:encoded><![CDATA[<p><strong>Austria has renewed a licence for a surveillance system built on advertising data. Nobody in government will say under what legal authority, and the data protection regulator was never asked.</strong></p>
<hr />
<p>A procurement notice on Austria&#8217;s public tender portal records the extension of a licence agreement between the Interior Ministry and the US vendor Penlink, worth roughly 1.85 million euros over two years. The package covers Penlink products including Webloc. Der Standard reported the deal first; netzpolitik.org followed with the ministry&#8217;s response, which was that no public information can be given about specific software solutions, and that anything the ministry uses, it uses within its legal powers.</p>
<p>The first half of that answer is a choice rather than a constraint. The second half cannot be verified, because the first half prevents anyone from checking it.</p>
<p>What makes this worth more than a paragraph of outrage is what Webloc actually is, and why the standard categories used in Austrian surveillance debate do not fit it.</p>
<h2>What Webloc does</h2>
<p>Webloc was built by the Israeli firm Cobwebs Technologies, acquired by Spire Capital in 2023 and merged into Penlink. It is sold as an add-on to Tangles, Cobwebs&#8217; web and social media intelligence platform, and it is not a wiretap, not an interception system, and not spyware in the conventional sense. It never touches the target&#8217;s device.</p>
<p>Instead it ingests the exhaust of the mobile advertising industry. Every time a phone opens an app that shows ads, an auction runs in under a second and the user&#8217;s data is broadcast to a large number of bidding parties. Separately, tracking SDKs embedded in apps collect and sell data directly. Both streams carry a Mobile Advertising ID, a persistent identifier tied to a specific handset, alongside GPS coordinates, Wi-Fi access point names, IP address, device model, operating system, language, and in many cases the ad targeting segments used to classify the person behind the phone.</p>
<p>Citizen Lab&#8217;s April 2026 analysis, based on leaked contract documents from El Salvador, technical specifications from Vietnam, US Navy procurement records and Penlink material from 2025, describes a system with access to a continuously updated stream from up to 500 million devices worldwide, refreshed every four to twenty-four hours, with three years of history available for query.</p>
<p>The interface is what matters. An analyst can draw a polygon on a map and retrieve every device observed inside it during a time window. They can intersect two polygons to find devices present in both, which surfaces people who travelled between two places. They can set alerts for new devices entering a monitored area. They can run a heat map on a single identifier to infer home address and workplace, which the vendor documentation treats as the expected workflow rather than an edge case. One example screen in the leaked material tracks a person moving from Germany through Austria into Hungary. Another resolves a single device to a specific building, rendered in Street View.</p>
<p>Note what this means structurally. Even when the target is one person, the query runs against everyone. A geofence around an address returns the neighbours. A geofence around a mosque, a clinic, a union hall or a newsroom returns whoever was there. The distinction between targeted and mass surveillance, which does most of the load-bearing work in Austrian legal argument about the SNG and the Constitutional Court proceedings on messenger surveillance, does not survive contact with this architecture. The Vienna-based tracking researcher Wolfie Christl put it plainly: even used against individuals, the system collects and analyses data on millions of uninvolved people every day.</p>
<h2>Two legal questions, neither answered</h2>
<p>There are two separate lawfulness problems here and they are routinely collapsed into one.</p>
<p>The first concerns the supply chain. Location data harvested from consumer apps under a consent banner about advertising, then sold onward through data brokers to a surveillance vendor, then sold to a state intelligence service, is being processed for a purpose no user ever agreed to. Christl&#8217;s position is that consent is effectively the only conceivable GDPR basis for such a transfer, and that no party in the chain holds valid consent for state surveillance. Germany&#8217;s consumer protection ministry took a comparable line in 2024, arguing that transferring personal data as a commodity in itself is incompatible with data protection law. The claim in Penlink&#8217;s older documentation that collection is GDPR compliant and consent-based rests on the same fiction the entire ad-tech sector rests on.</p>
<p>The second concerns the buyer. Even assuming the data existed lawfully, the Interior Ministry would need a domestic legal basis to acquire and query it. Purchasing commercially available data is a well-known route around the warrant requirement precisely because it does not look like a search. Nothing is intercepted, no device is compromised, no court is asked. In the United States, seventy-two members of Congress called in March 2026 for an investigation into warrantless location data purchases by ICE and other agencies, and an internal DHS review in 2023 already found that several DHS components had broken federal law through such purchases.</p>
<p>Austria has answered neither question. The ministry&#8217;s response to netzpolitik.org gestured at extremist and terrorist offences and indicated the Directorate for State Protection and Intelligence Service as the responsible body, which tells us the intended use case without telling us the authority for it.</p>
<h2>The oversight gap is the actual scandal</h2>
<p>The Austrian data protection authority told netzpolitik.org that it has no closer knowledge of the ministry&#8217;s planned use of the software and was not consulted. Under the GDPR, prior consultation with the supervisory authority is required where a data protection impact assessment identifies a high residual risk.</p>
<p>Work through the possibilities. Either the ministry conducted an impact assessment on a system that queries commercial location data covering hundreds of millions of people and concluded there was no high risk, or it did not conduct one. Both are difficult to defend. The regulator has kept the door open, noting it can examine compliance at any time through a complaint or an own-initiative review. It has not said it will.</p>
<p>Meanwhile the transparency record is instructive. Citizen Lab sent ninety-six freedom of information requests across fourteen European countries and six EU bodies. Austrian ministries, alongside Dutch and Romanian ones, declined to say whether they use Webloc. Europol confirmed holding relevant information and refused to release it. Not a single European agency confirmed use. Austria&#8217;s participation only became known because a procurement document sat in a public tender portal. Green MP Süleyman Zorba, who had previously been told that any disclosure would endanger national security, has made the obvious point that the deployment is now documented in public award records.</p>
<p>Austria is, on current evidence, the second confirmed ad-based surveillance customer in the EU after Hungary, where domestic intelligence has been using Webloc since at least 2022 and bought a fresh licence round in March 2026.</p>
<h2>Mission creep is not hypothetical</h2>
<p>The reassurance offered in these debates is always that the tool is reserved for terrorism, extremism and organised crime. There is now a documented answer to that.</p>
<p>Tucson police in Arizona acquired Tangles and Webloc for sex trafficking investigations, funded from a state border security programme. An internal report obtained by journalists describes the department using the system to investigate burglary, robbery and the theft of several thousand dollars of cigarettes, running advertising ID queries across crime scene areas to locate a suspect&#8217;s workplace, his former girlfriend and the apartment the identifiers kept returning to. The same system was used to monitor protests during campaign visits by presidential and vice-presidential candidates.</p>
<p>That is the empirical trajectory of a capability that is fast, cheap, warrantless and sitting on an analyst&#8217;s desk. Nothing about Austrian institutional culture makes it immune, and the current absence of any published control regime makes it less protected than the American departments where at least the procurement records are litigated.</p>
<h2>The counterintelligence problem nobody is discussing</h2>
<p>There is a dimension to this that civil liberties framing misses, and it should concern Austrian security professionals more than it currently does.</p>
<p>If the Interior Ministry can buy access to a stream covering hundreds of millions of devices, so can anyone else with a budget and a front company. The data does not become available only to lawful buyers. It is a commercial product moving through an opaque broker layer, and the same bidstream that produces Webloc produces competitor systems from other vendors, some of them in jurisdictions with no meaningful export control on this category.</p>
<p>Vienna hosts the IAEA, UNODC, the OSCE, OPEC and a large diplomatic corps. It is one of the densest concentrations of intelligence-relevant personnel in Europe. Every one of those people carries a phone running apps with embedded tracking SDKs. A geofence around the Vienna International Centre, a ministry, an embassy or a safe house is a commercially purchasable product. Pattern of life on a named official requires only linking one identifier, and advertising IDs are routinely matched to names, addresses and phone numbers by the same industry that insists they are anonymous. The US Federal Trade Commission has stated directly that these identifiers provide no anonymity in the marketplace.</p>
<p>A state that normalises the purchase of this data for its own investigations has a weaker position from which to argue that the market should not exist. That is a counterintelligence cost, not just a privacy cost, and it is being incurred without public debate.</p>
<h2>What should happen next</h2>
<p>Three things are reasonable to demand, and none of them require accepting or rejecting the underlying capability.</p>
<p>Publish the legal basis. Not the operational detail, not the target selection, just the statutory provision under which commercially sourced location data may be acquired and queried, and which oversight body approves individual queries.</p>
<p>Have the data protection authority open an own-initiative review. The question of whether the underlying processing is lawful is squarely within its mandate and does not depend on the ministry&#8217;s cooperation.</p>
<p>Treat ad-based tracking as a defensive problem. For anyone in Austria handling sensitive material, the mitigation is unglamorous and available today: reset advertising identifiers regularly or disable them entirely, deny location permission to any app that does not require it for its core function, and remove ad-supported apps from devices used for sensitive travel. This is not a substitute for regulation. It is what can be done while regulation does not exist.</p>
<hr />
<p><strong>Sources</strong></p>
<ul>
<li>Wolfie Christl, Astrid Perry, Luis Fernando Garcia, Siena Anstis and Ron Deibert, &#8220;Uncovering Webloc: An Analysis of Penlink&#8217;s Ad-based Geolocation Surveillance Tech,&#8221; Citizen Lab Report No. 191, University of Toronto, 9 April 2026</li>
<li>Sebastian Meineck, netzpolitik.org, 30 June 2026</li>
<li>Der Standard, reporting on the Interior Ministry procurement record</li>
<li>VSquare, Szabolcs Panyi, on Hungarian intelligence use of Webloc, April 2026</li>
<li>Austrian federal procurement portal, tender award documentation</li>
</ul>
]]></content:encoded>
					
					<wfw:commentRss>https://www.digitalintelligence.at/vienna-buys-the-bidstream/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Vienna&#8217;s Antenna Forest and Austria&#8217;s Quiet Course Change</title>
		<link>https://www.digitalintelligence.at/viennas-antenna-forest-and-austrias-quiet-course-change/</link>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Sat, 30 May 2026 12:38:14 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[Intelligence]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4473</guid>

					<description><![CDATA[There is a stretch of road in Vienna&#8217;s 22nd district, just off the U1 metro line, where you can stand on one side of a small park and see the Russian diplomatic compound on the left and the UN City complex on the right. The distance between them, on a clear day, is about what a decent rooftop antenna would have for line of sight on satellite uplinks from the IAEA. Anyone in Vienna&#8217;s intelligence ecosystem has thought about this geometry at some point. The staff at the IAEA Communications Office have thought about it more. On 4 May, the]]></description>
										<content:encoded><![CDATA[<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">There is a stretch of road in Vienna&#8217;s 22nd district, just off the U1 metro line, where you can stand on one side of a small park and see the Russian diplomatic compound on the left and the UN City complex on the right. The distance between them, on a clear day, is about what a decent rooftop antenna would have for line of sight on satellite uplinks from the IAEA. Anyone in Vienna&#8217;s intelligence ecosystem has thought about this geometry at some point. The staff at the IAEA Communications Office have thought about it more.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">On 4 May, the Austrian Foreign Ministry confirmed an ORF report from the previous evening. Three Russian diplomats had been declared persona non grata over the antennas on the roof of the embassy on Reisnerstrasse in the 3rd district and on the Donaustadt compound described above. The installations, according to ORF&#8217;s sources, were used to intercept data transmitted by international organisations based in Vienna over satellite internet. The three have already left.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">This is the largest single Russian expulsion in Austria&#8217;s post-2022 period and brings the cumulative total to 14 since the full-scale invasion. The 14 figure, set against the seven-thousand-or-so hostile officers operating in this city and the dozens of accredited Russian personnel still in Vienna, is small. The story matters less for the numerical impact than for what it signals about how the new coalition is actually treating the espionage portfolio.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Foreign Minister Beate Meinl-Reisinger framed it in unusually direct language for an Austrian foreign minister: &#8220;Espionage is a security problem for Austria. In this government, we have initiated a change of course and are taking consistent action against it.&#8221; Then, more pointedly: &#8220;It is unacceptable for diplomatic immunity to be used to conduct espionage.&#8221;</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Both sentences should be read in the context of what the Austrian government did before reaching the expulsion decision.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The Russian ambassador was summoned to the Foreign Ministry in April. Vienna asked Moscow to waive the immunity of the three officers so that the prosecutor&#8217;s office could open a case. Russia refused, which is the answer everyone in the building expected. Once that refusal was on the record, the only remaining instrument was a PNG declaration. That sequence, asking for immunity to be lifted before going to expulsion, is itself meaningful. It tells you the Justice Ministry would have preferred to prosecute, not deport. That is the institutional logic of the §319a draft I wrote about last month coming into view. The government is signalling that it wants foreign espionage on Austrian soil treated as a criminal matter rather than a diplomatic one.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The technical layer matters, and I will be brief about it because there are people in this city who know more than I do about exactly what those antennas were doing. The basics are these. When an international organisation in Vienna sends and receives traffic over satellite, the uplink and downlink are not magic. They are radio waves with side lobes that bleed off the main beam, and they pass over rooftops in defined geometric patterns. Anyone with the right antenna at the right altitude in the right place can pick up that traffic. Decrypting it is harder, but the volume of communications moving through the IAEA, UNOV, the OSCE and the EU Agency for Fundamental Rights, accumulated over years, gives serious cryptanalytic teams plenty to work with. Embassy rooftops are uniquely valuable platforms for this work because of immunity. Nobody, including DSN, can come up and look at the equipment.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The Donaustadt compound is what makes this case sharper than the standard embassy SIGINT story. The site sits within walking distance of the UN City complex. The line of sight is, to put it generously, ideal. Anyone who has walked along Wagramer Strasse on a clear afternoon understands the geometry instinctively. The question that has been quietly asked in Vienna&#8217;s diplomatic circles for years is why nobody acted on this earlier.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Part of the answer is that DSN until recently was not in shape to act. Sylvia Mayer took over on 1 January as the first female director of the agency. The Russian ambassador was summoned in April. The expulsions were announced on 4 May. That is the operational rhythm of a service that has decided to spend its first major political capital on this file. Mayer herself was on the podium at the press conference. Asked why these installations were a particular threat, she limited herself to saying it had to do with their size and nature, and declined to comment on the timing. The decline to discuss the timing is the whole story. The timing is a political choice, not an intelligence one. The antennas have been there for years.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">There are limits to what I will read into a single expulsion. Austria has now expelled 14 Russian diplomats in four years, which compared to other European countries is still on the low side. The bulk of accredited Russian personnel are still here, doing whatever they do, with the same immunities. The Donaustadt compound is still in operation. The antennas, as a class of equipment, are not going anywhere, and Russia will rotate in new staff under different cover within months. The structural facts of Vienna&#8217;s exposure have not changed.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">What has changed, possibly, is the political ceiling on what can be done about that exposure. For most of the past decade, the standard official Austrian position was that Vienna&#8217;s hosting role required a particular kind of equidistance, and that expulsions complicated relationships with international organisations that depended on diplomatic stability. That position has been quietly retired by the current government. Meinl-Reisinger&#8217;s &#8220;change of course&#8221; line is not rhetorical. It maps onto a sequence of concrete decisions: the §319a draft, the summoning of the ambassador, the public request for immunity waiver, the public expulsion. These are not the actions of a government still committed to the bridge.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The next move belongs to Moscow. The Russian embassy called the expulsions &#8220;outrageous&#8221; and &#8220;politically motivated,&#8221; and warned of a &#8220;harsh&#8221; response, calling the bilateral relationship &#8220;at a historical low.&#8221; In recent pattern, &#8220;harsh response&#8221; usually means a reciprocal expulsion of Austrian diplomats, often more than the original number, and visa frictions for Austrian citizens. The relationship will degrade further. That is also part of the price of the course change, and the government appears to be prepared to pay it.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The piece I wrote last month argued that the §319a draft was real progress but that the Ott verdict would tell us more than the law itself. The expulsions on 4 May added a third data point to that picture. Taken with the verdict that landed on 20 May, the bill, the expulsions and the conviction are starting to look less like isolated events and more like a deliberate sequence. Vienna, for the first time in a long time, is acting like a country that takes its espionage problem seriously.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Whether that lasts beyond the next election cycle is a question I will not answer today. It depends on which parties are at the table after the next vote and what they decide to do with the institutional momentum the current government has built. The political risks are real. The operational improvements are also real. Both things can be true.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AI Broke the Criminal Profile. Now What?</title>
		<link>https://www.digitalintelligence.at/ai-broke-the-criminal-profile-now-what/</link>
					<comments>https://www.digitalintelligence.at/ai-broke-the-criminal-profile-now-what/#respond</comments>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Thu, 26 Mar 2026 21:36:48 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Intelligence]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4428</guid>

					<description><![CDATA[How artificial intelligence is rewriting the rules of criminal behavior, and why the profiler&#8217;s playbook needs a fundamental reset. Criminal profiling has always rested on one core assumption: criminals are creatures of habit. They leave behavioral signatures. They escalate predictably. Their psychology leaks through their methods. For decades, this held up well enough. The FBI&#8217;s Behavioral Analysis Unit built an entire discipline around reading crime scenes like psychological fingerprints, classifying offenders as organized or disorganized, mapping modus operandi against personality types, and predicting the next move based on the last one. Then AI entered the equation. Not as a tool]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">How artificial intelligence is rewriting the rules of criminal behavior, and why the profiler&#8217;s playbook needs a fundamental reset.</p>



<p class="wp-block-paragraph">Criminal profiling has always rested on one core assumption: criminals are creatures of habit. They leave behavioral signatures. They escalate predictably. Their psychology leaks through their methods. For decades, this held up well enough. The FBI&#8217;s Behavioral Analysis Unit built an entire discipline around reading crime scenes like psychological fingerprints, classifying offenders as organized or disorganized, mapping modus operandi against personality types, and predicting the next move based on the last one.</p>



<p class="wp-block-paragraph">Then AI entered the equation. Not as a tool for investigators, but as a tool for criminals. And it didn&#8217;t just make crime easier. It fundamentally altered who commits crime, how they behave while doing it, and what traces they leave behind. That shift is quietly dismantling the foundations of classical profiling.</p>



<h2 class="wp-block-heading">The Old Rules</h2>



<p class="wp-block-paragraph">Traditional profiling works on a set of behavioral axioms. Behavior reflects personality. Crime scenes tell stories about the offender&#8217;s psychology. Signature behaviors, those acts unnecessary for completing the crime but driven by deep psychological needs, remain consistent across offenses. Modus operandi evolves as the offender learns, but the core emotional drivers stay stable.</p>



<p class="wp-block-paragraph">These principles gave investigators a framework: analyze the scene, read the behavior, build a psychological sketch, narrow the suspect pool. It was never perfect. FBI internal data suggested profiling contributed to solving roughly 17% of cases where it was applied. Academic reviews have been even less generous. But as a supplementary tool alongside forensic evidence and traditional detective work, it had value.</p>



<p class="wp-block-paragraph">The problem is that every one of these axioms assumes the offender is acting from their own psychology, with their own skills, under their own operational limitations. AI has removed those constraints.</p>



<h2 class="wp-block-heading">The New Criminal Doesn&#8217;t Fit the Old Mold</h2>



<p class="wp-block-paragraph">Consider what AI has done to the barrier of entry for sophisticated crime. Voice cloning now requires 20 to 30 seconds of audio. Convincing deepfake video can be produced in under an hour using freely available tools. Dark LLMs and jailbreak-as-a-service platforms generate phishing campaigns, social engineering scripts, and even malware with minimal technical knowledge required from the operator.</p>



<p class="wp-block-paragraph">This is the first major break from classical profiling logic. The old model assumed a correlation between crime sophistication and offender capability. An organized crime scene implied an intelligent, socially competent, methodical individual. A well-crafted social engineering attack suggested experience, psychological insight, and confidence. AI has severed that link entirely. A teenager with a laptop can now execute attacks that would have previously required a team of experienced operatives.</p>



<p class="wp-block-paragraph">The Trend Micro research team documented this shift in their 2025 criminal AI report: the underground ecosystem has moved from experimentation to industrialization. Criminals no longer build their own tools. They rent them. The barrier has collapsed, the tooling has professionalized, and the attack surface has expanded across every domain. Telegram channels now recruit &#8220;AI video actors&#8221; and &#8220;deepfake presenters&#8221; as a service category.</p>



<p class="wp-block-paragraph">What does this mean for profiling? It means the behavioral signature, the profiler&#8217;s primary analytical unit, is increasingly a product of the tool rather than the person behind it. When a deepfake CEO orders a wire transfer on a video call, the behavioral cues that investigators would normally analyze (speech patterns, confidence level, emotional state, decision-making style) belong to the AI model, not the attacker. The criminal becomes invisible behind the synthetic layer.</p>



<h2 class="wp-block-heading">AI Doesn&#8217;t Just Enable Crime. It Redirects It.</h2>



<p class="wp-block-paragraph">Here is the less obvious but more consequential effect. AI isn&#8217;t simply making existing criminal patterns more efficient. It is creating entirely new behavioral categories that classical profiling has no framework to address.</p>



<p class="wp-block-paragraph">Take synthetic identity fraud. Criminals now build complete fake identities using a mix of real and fabricated data, pass automated KYC checks with AI-generated documents, and operate accounts that leave behind a perfectly normal behavioral footprint. There is no psychological signature to read because the &#8220;person&#8221; never existed. The behavior was designed by algorithm to look average.</p>



<p class="wp-block-paragraph">Or consider AI-powered behavioral mimicry. Trend Micro and Group-IB both documented cases where AI studied institutional behavior patterns (transaction timing, approval workflows, communication styles) and then replicated them precisely to avoid triggering fraud detection. The criminal isn&#8217;t acting like themselves anymore. They are acting like the system expects a legitimate user to act. This is the opposite of what profiling relies on: instead of behavior revealing identity, behavior is engineered to conceal it.</p>



<p class="wp-block-paragraph">The 2025 AI Incident Database recorded 346 AI-related incidents in a single year. Of those, 179 involved deepfake impersonation. The targets ranged from CEOs to private individuals. In one case, a British widow lost half a million pounds in a romance scam powered by deepfake video of a celebrity. A Florida couple lost $45,000 to a fabricated Elon Musk giveaway. These are not sophisticated adversaries with complex psychological profiles. These are operators running playbooks, sometimes literally purchased as step-by-step tutorials from underground forums.</p>



<h2 class="wp-block-heading">The Profiling Crisis</h2>



<p class="wp-block-paragraph">Classical profiling depends on three things that AI is systematically eroding:</p>



<p class="wp-block-paragraph"><strong>Behavioral consistency.</strong> AI allows criminals to switch personas, communication styles, and operational methods between attacks with zero psychological cost. There is no escalation pattern to track because each attack can be calibrated independently by the tool.</p>



<p class="wp-block-paragraph"><strong>Skill-behavior correlation.</strong> The assumption that crime complexity reflects offender sophistication is broken. AI democratizes capability. The profile of &#8220;who could do this&#8221; expands from a narrow suspect pool to essentially anyone with internet access and basic prompt engineering skills.</p>



<p class="wp-block-paragraph"><strong>Psychological leakage.</strong> Crime scenes and communications used to leak the offender&#8217;s personality involuntarily. When AI generates the phishing email, conducts the video call, or crafts the social engineering script, the psychological content belongs to the model&#8217;s training data, not the operator&#8217;s mind.</p>



<p class="wp-block-paragraph">This doesn&#8217;t mean profiling is dead. But it means the discipline needs to shift its unit of analysis. Instead of asking &#8220;what kind of person did this,&#8221; investigators increasingly need to ask &#8220;what kind of toolchain produced this behavior.&#8221; The profiling target is migrating from psychology to infrastructure.</p>



<h2 class="wp-block-heading">Where Profiling Still Works, and Where It Can&#8217;t</h2>



<p class="wp-block-paragraph">Profiling retains value in crimes that remain fundamentally physical and personal: serial violent offenses, sexual crimes, stalking, arson. These still carry strong behavioral signatures because the offender&#8217;s psychological needs drive the act directly, not through a technological intermediary.</p>



<p class="wp-block-paragraph">But for the fastest-growing categories of crime (fraud, identity theft, business email compromise, financial manipulation, extortion through synthetic media), classical profiling is increasingly irrelevant. The offender&#8217;s psychology matters less than their toolkit. Their behavioral patterns are shaped more by the AI model they are using than by their own personality.</p>



<p class="wp-block-paragraph">The intelligence community and law enforcement agencies that recognize this shift will adapt. Those that keep trying to build psychological profiles of operators who are essentially invisible behind AI-generated behavior will waste time and resources chasing ghosts.</p>



<p class="wp-block-paragraph">The profiler&#8217;s question used to be: <em>Who is this person?</em></p>



<p class="wp-block-paragraph">Now it needs to be: <em>What system is this person hiding behind, and where does that system leak?</em></p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.digitalintelligence.at/ai-broke-the-criminal-profile-now-what/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The First Cyber War: How Digital Intelligence Shaped Operation Epic Fury</title>
		<link>https://www.digitalintelligence.at/the-first-cyber-war-how-digital-intelligence-shaped-operation-epic-fury/</link>
					<comments>https://www.digitalintelligence.at/the-first-cyber-war-how-digital-intelligence-shaped-operation-epic-fury/#respond</comments>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Mon, 16 Mar 2026 02:30:49 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Worldwide]]></category>
		<category><![CDATA[hybrid threats]]></category>
		<category><![CDATA[intelligence analysis]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4422</guid>

					<description><![CDATA[I&#8217;ve been covering cyber threats for years now, and I&#8217;ve sat through countless conference panels where retired generals talk about &#8220;the coming cyber war.&#8221; Always in the future tense. Always hypothetical. That era is over. On February 28, the US and Israel hit Iran. But the shooting started in cyberspace. Hours before any jet crossed Iranian airspace, US Cyber Command had already gutted Tehran&#8217;s communications and sensor networks. General Dan Caine confirmed it publicly: space and cyber operations came first, leaving Iran unable to &#8220;see, coordinate, or respond effectively.&#8221; Think about what that means. By the time the bombs dropped,]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">I&#8217;ve been covering cyber threats for years now, and I&#8217;ve sat through countless conference panels where retired generals talk about &#8220;the coming cyber war.&#8221; Always in the future tense. Always hypothetical. That era is over.</p>



<p class="wp-block-paragraph">On February 28, the US and Israel hit Iran. But the shooting started in cyberspace. Hours before any jet crossed Iranian airspace, US Cyber Command had already gutted Tehran&#8217;s communications and sensor networks. General Dan Caine confirmed it publicly: space and cyber operations came first, leaving Iran unable to &#8220;see, coordinate, or respond effectively.&#8221; Think about what that means. By the time the bombs dropped, the Iranian military was already operating blind.</p>



<p class="wp-block-paragraph">And it only got stranger from there.</p>



<h2 class="wp-block-heading">Tehran&#8217;s traffic cameras killed the Supreme Leader</h2>



<p class="wp-block-paragraph">This is the part that reads like fiction but isn&#8217;t. Israeli intelligence had been inside Tehran&#8217;s traffic camera network for what appears to be months, possibly longer. Not just watching. Feeding the footage into a machine alongside CIA human intelligence, signals intercepts, satellite imagery, communications metadata. The Financial Times was first to report the scope of it. One Israeli source called the whole setup an AI-powered &#8220;target production machine.&#8221; You pour data in, you get a 14-digit grid coordinate out.</p>



<p class="wp-block-paragraph">They built what they called a &#8220;life pattern&#8221; for Khamenei. His routes. His schedules. Which aides traveled with him. When his security detail was thinnest. The Jerusalem Post reported that Israeli analysts mapped these patterns over an extended period, cross-referencing traffic camera data with other intelligence streams.</p>



<p class="wp-block-paragraph">Then the CIA confirmed Khamenei would attend a senior military meeting on the morning of the 28th. The entire operation timeline shifted around that single piece of intelligence. The result: Khamenei dead, along with the IRGC commander, the defense minister, the chief of staff, the head of the National Defense Council. More than a dozen top officials, gone before lunch.</p>



<p class="wp-block-paragraph">I keep coming back to what RUSI wrote about this. They pointed out something that gets lost in the spectacle: cyber&#8217;s biggest contribution here wasn&#8217;t disruption. It was reconnaissance. Years of quiet network access, pre-positioned in Iranian infrastructure, activated at the decisive moment. That&#8217;s not a hack. That&#8217;s a long-term intelligence operation that happened to run through fiber optic cables instead of dead drops.</p>



<h2 class="wp-block-heading">Israel doesn&#8217;t want to depend on Silicon Valley for its kill chain</h2>



<p class="wp-block-paragraph">Here&#8217;s something that should concern anyone in the AI policy space. Haaretz reporter Omer Benjakob told NPR that Israel is building its own military AI systems specifically because it can&#8217;t afford to rely on American commercial platforms. His quote was memorable: &#8220;One day someone will discover we also use Claude, and then there&#8217;ll be a protest in San Francisco, and then they&#8217;ll take Claude away from us.&#8221;</p>



<p class="wp-block-paragraph">He said this on the record.</p>



<p class="wp-block-paragraph">The Anthropic dispute with the Trump administration over military use of Claude is well documented at this point. But the strategic implications go deeper than one company&#8217;s ethical stance. If your precision targeting pipeline depends on a model whose provider can revoke access based on a policy change or public pressure campaign, you have a serious sovereignty problem. Israel clearly sees it that way. Others will too.</p>



<p class="wp-block-paragraph">None of this means AI targeting is ready for primetime, though. The March 8 strike on the Shajareh Tayyebeh school in Minab killed 165 people. 110 of them were schoolgirls. The building used to be a military base. Whether AI targeting systems worked off stale data is still under investigation, but a UCL computer scientist put the core issue bluntly: &#8220;This stuff is only two or three years old.&#8221;</p>



<p class="wp-block-paragraph">Speed and precision are not the same thing. This war is proving that every day.</p>



<h2 class="wp-block-heading">60 hacktivist groups, one internet blackout, and a paradox</h2>



<p class="wp-block-paragraph">Iran&#8217;s internet dropped to somewhere between 1% and 4% connectivity on February 28. That&#8217;s barely functional. You&#8217;d think that would cripple the regime&#8217;s cyber response. And for the state-run APT groups operating inside Iran, it probably did, at least initially.</p>



<p class="wp-block-paragraph">But that&#8217;s not how Iran&#8217;s cyber infrastructure actually works. Tehran has spent years building out proxy networks. Hacktivist groups, some loosely affiliated, some directly run by MOIS or the IRGC, operating from outside Iran&#8217;s borders. When the internet went dark domestically, these external nodes lit up.</p>



<p class="wp-block-paragraph">Unit 42 counted around 60 groups active in the first week alone. Handala Hack, which has documented ties to the Ministry of Intelligence, ran wiper and exfiltration campaigns against Israeli defense targets. On March 12, they hit Stryker, one of the largest medical technology companies in the US. MuddyWater, an IRGC-linked group, turned out to have pre-planted backdoors in Israeli-adjacent defense and financial networks. They didn&#8217;t need to break in after the war started. They were already inside.</p>



<p class="wp-block-paragraph">March 2 was when things escalated beyond the Middle East. Pro-Russian hacktivist group NoName057(16) formally joined the Iranian coalition. Since then, the combined front has been hitting targets in Cyprus, Romania, across the Gulf states. Government websites, airports, telecom providers. The Russia-Iran cyber axis is no longer theoretical. It&#8217;s operational.</p>



<p class="wp-block-paragraph">Now, the OT and SCADA claims. Groups have been posting screenshots alleging access to Israeli water systems, Jordanian grain storage controls, various industrial systems. John Hultquist at Google Threat Intelligence has been saying for years that Iran exaggerates its cyber successes for psychological effect, and he&#8217;s right. A lot of these claims don&#8217;t hold up under scrutiny.</p>



<p class="wp-block-paragraph">But I&#8217;d be careful about dismissing all of it. CyberAv3ngers compromised real US water systems in 2023 using nothing more sophisticated than default passwords on Unitronics PLCs. The capability is proven. What we don&#8217;t know is how much coordination these proxy groups can maintain while their state sponsors are dealing with an actual shooting war.</p>



<h2 class="wp-block-heading">The information battlefield is now indistinguishable from the physical one</h2>



<p class="wp-block-paragraph">Before the first airstrike, Israel had already compromised BadeSaba, a popular Iranian prayer app with over five million users. They pushed messages to regime supporters urging military defection. They hijacked state news websites to publish anti-regime content. Later, they sent AI-equipped drone swarms over Tehran to hit Basij militia checkpoints.</p>



<p class="wp-block-paragraph">Iran&#8217;s been playing the same game in reverse for years. Dozens of Israeli nationals recruited through Telegram, paid to commit low-level sabotage: starting fires, spraying antigovernment graffiti, sowing social discord. A Clemson University researcher called Israel&#8217;s approach &#8220;psychological operations integrated with military operations in one clean campaign with a single goal: toppling the Iranian regime.&#8221;</p>



<p class="wp-block-paragraph">Both sides have turned every digital platform into a weapon. Messaging apps, news sites, social media, traffic infrastructure. There&#8217;s no longer a meaningful line between &#8220;cyber operation&#8221; and &#8220;influence operation.&#8221; It&#8217;s all one battlefield.</p>



<h2 class="wp-block-heading">CISA is running on fumes at the worst possible time</h2>



<p class="wp-block-paragraph">I can&#8217;t write about this conflict&#8217;s cyber dimension without mentioning what&#8217;s happening at CISA. The agency has lost roughly a third of its staff. The temporary director got reassigned to another corner of DHS right as the war kicked off. FBI and NSA have put out joint warnings about Iranian targeting of US defense contractors and financial firms. Jamie Dimon at JPMorgan went on CNBC and said banks are bracing for a wave of cyber and terrorist attacks.</p>



<p class="wp-block-paragraph">So at the exact moment when motivated, state-aligned Iranian cyber actors are looking for American targets, the primary agency that&#8217;s supposed to coordinate civilian cyber defense is hollowed out. That should worry people far more than it seems to.</p>



<h2 class="wp-block-heading">European organizations need to pay attention</h2>



<p class="wp-block-paragraph">The NCSC in the UK puts Iran in the same threat tier as Russia and North Korea. That was true before February 28. It&#8217;s more true now, because the Russian hacktivist groups that joined the Iranian coalition have broadened the targeting aperture into Europe.</p>



<p class="wp-block-paragraph">Organizations in Austria and the DACH region might feel geographically removed from this conflict. They&#8217;re not. If your supply chain touches Israeli technology, if your cloud provider hosts workloads for companies in targeted sectors, if you run Israeli-manufactured OT equipment, you&#8217;re in scope. CyberAv3ngers targeted Unitronics PLCs in 2023 specifically because they were Israeli-made. That logic doesn&#8217;t stop at borders.</p>



<p class="wp-block-paragraph">Trellix published research showing that Iranian threat groups have expanded from targeting a handful of countries to more than twenty since the conflict started. Western Europe is on that list. The tactics are familiar: spear-phishing, unpatched edge devices, ransomware that looks criminal but serves state interests, data leaks timed for maximum embarrassment.</p>



<h2 class="wp-block-heading">This doesn&#8217;t end when the bombing stops</h2>



<p class="wp-block-paragraph">Iranian APT groups like APT42, APT34 and MuddyWater have a well-documented habit of running campaigns for years after the initial trigger. The proxy networks are activated. Russia and Iran have found operational common ground in cyberspace. The infrastructure built for this conflict will be repurposed, not dismantled.</p>



<p class="wp-block-paragraph">Two decades of defense policy debates about whether cyber is a &#8220;real&#8221; domain of warfare just got their answer. In this conflict, cyber was the opening move, the intelligence backbone, the targeting enabler, the psychological weapon, and the retaliatory instrument of choice for a regime that lost its conventional military options in a matter of hours.</p>



<p class="wp-block-paragraph">We&#8217;re not waiting for the first cyber war anymore. We&#8217;re in it.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>
]]></content:encoded>
					
					<wfw:commentRss>https://www.digitalintelligence.at/the-first-cyber-war-how-digital-intelligence-shaped-operation-epic-fury/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The Blind Spot in European Cybersecurity: Why SMEs Are Losing the Attack Surface Battle</title>
		<link>https://www.digitalintelligence.at/the-blind-spot-in-european-cybersecurity-why-smes-are-losing-the-attack-surface-battle/</link>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Fri, 27 Feb 2026 16:09:49 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[critical infrastructure]]></category>
		<category><![CDATA[hybrid threats]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4409</guid>

					<description><![CDATA[Most European small and mid-sized enterprises believe they are too small to be targeted. The data tells a different story. According to ENISA&#8217;s 2025 Threat Landscape Report, over 60% of cyberattacks in the EU now target organisations with fewer than 250 employees. The reason is simple: attackers follow the path of least resistance, and SMEs consistently present the weakest perimeter. Having spent over a decade in intelligence and security operations, from securing diplomatic missions for the German Federal Foreign Office to advising law enforcement on digital threats, I have observed a consistent pattern. Organisations do not fail because they lack]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Most European small and mid-sized enterprises believe they are too small to be targeted. The data tells a different story. According to ENISA&#8217;s 2025 Threat Landscape Report, over 60% of cyberattacks in the EU now target organisations with fewer than 250 employees. The reason is simple: attackers follow the path of least resistance, and SMEs consistently present the weakest perimeter.</p>



<p class="wp-block-paragraph">Having spent over a decade in intelligence and security operations, from securing diplomatic missions for the German Federal Foreign Office to advising law enforcement on digital threats, I have observed a consistent pattern. Organisations do not fail because they lack firewalls or antivirus software. They fail because they do not know what they are exposing to the internet in the first place.</p>



<h2 class="wp-block-heading">The Problem No One Talks About</h2>



<p class="wp-block-paragraph">Every organisation has an attack surface. It includes every domain, subdomain, IP address, open port, exposed API, cloud instance, and forgotten staging server connected to the internet. For a company with even a modest digital footprint, this can amount to hundreds of potential entry points.</p>



<p class="wp-block-paragraph">The challenge is visibility. Most SMEs have no systematic way to inventory their external-facing assets. A marketing team spins up a subdomain for a campaign and never takes it down. A developer leaves a test environment exposed with default credentials. An old mail server runs an unpatched version of Exchange. Each of these is an open door.</p>



<p class="wp-block-paragraph">Large enterprises address this through dedicated security operations centres and expensive enterprise tools. But for a company with 50 or 100 employees, these solutions are neither accessible nor affordable. This gap between awareness and capability is where most breaches begin.</p>



<h2 class="wp-block-heading">Attack Surface Management: From Military Doctrine to Cyber Defence</h2>



<p class="wp-block-paragraph">The concept of attack surface management (ASM) has its roots in military intelligence. Before any operation, you map the terrain. You identify vulnerabilities in your own position before the adversary does. The same principle applies to cybersecurity.</p>



<p class="wp-block-paragraph">Modern ASM platforms automate the process of discovering, cataloguing, and continuously monitoring an organisation&#8217;s external-facing digital assets. They scan for exposed services, misconfigurations, known vulnerabilities, leaked credentials on the dark web, and other indicators of risk.</p>



<p class="wp-block-paragraph">What makes ASM fundamentally different from traditional vulnerability scanning is scope and continuity. A vulnerability scan checks known assets at a point in time. ASM discovers unknown assets and monitors them continuously. It answers the question most security teams cannot: <em>What do we not know about our own exposure?</em></p>



<h2 class="wp-block-heading">The European Dimension</h2>



<p class="wp-block-paragraph">For European organisations, the stakes are compounded by regulation. The NIS2 Directive, which came into full effect across EU member states, imposes strict cybersecurity requirements on a far broader range of companies than its predecessor. Entities classified as &#8220;essential&#8221; or &#8220;important&#8221; must implement risk-based security measures, conduct regular assessments, and report incidents within tight timeframes.</p>



<p class="wp-block-paragraph">GDPR adds another layer. A breach resulting from an unmonitored attack surface does not just cause operational damage. It triggers mandatory notification requirements and potential fines of up to 4% of global annual turnover.</p>



<p class="wp-block-paragraph">Despite these pressures, most European SMEs still rely on periodic penetration tests, conducted once or twice a year, as their primary security assessment. In a threat landscape where new vulnerabilities are disclosed daily and attack infrastructure is automated, annual testing is the equivalent of checking your locks once a year in a neighbourhood where break-ins happen every week.</p>



<h2 class="wp-block-heading">Continuous Monitoring as the New Baseline</h2>



<p class="wp-block-paragraph">The shift from periodic assessment to continuous monitoring is not optional. It is a necessity. Attackers use automated reconnaissance tools that scan the entire IPv4 address space in minutes. If an organisation exposes a vulnerable service, it can be discovered and exploited within hours, sometimes within minutes.</p>



<p class="wp-block-paragraph">This is the operational reality that led me to develop <a href="https://securityscanner.ai?utm_source=digitalintelligence&amp;utm_medium=blog&amp;utm_campaign=asm_article">SecurityScanner.ai</a>, an attack surface management platform designed specifically for the European market. The platform provides continuous external monitoring, automated vulnerability detection, dark web credential monitoring, and AI-driven risk assessment. It is built from the ground up with GDPR-compliant infrastructure and priced for organisations that do not have six-figure security budgets.</p>



<p class="wp-block-paragraph">The philosophy behind it is straightforward. Every organisation, regardless of size, deserves the same level of visibility into its attack surface that was previously only available to large enterprises and government agencies.</p>



<h2 class="wp-block-heading">What a Proper ASM Workflow Looks Like</h2>



<p class="wp-block-paragraph">For organisations beginning to take attack surface management seriously, the process follows a clear logic.</p>



<p class="wp-block-paragraph"><strong>Discovery</strong> is the first phase. You cannot protect what you do not know exists. This means automated enumeration of all domains, subdomains, IP ranges, cloud assets, and third-party services associated with your organisation. The results are often surprising. Most companies discover 30 to 40 percent more external assets than they were aware of.</p>



<p class="wp-block-paragraph"><strong>Assessment</strong> follows discovery. Each discovered asset is evaluated for known vulnerabilities, misconfigurations, exposed sensitive data, outdated software, and weak encryption. This is where automated scanning intersects with threat intelligence, correlating discovered exposures against actively exploited vulnerabilities in the wild.</p>



<p class="wp-block-paragraph"><strong>Monitoring</strong> makes the process continuous. New assets, new vulnerabilities, and new threats emerge constantly. A platform like <a href="https://securityscanner.ai?utm_source=digitalintelligence&amp;utm_medium=blog&amp;utm_campaign=asm_article">SecurityScanner.ai</a> runs these checks on an ongoing basis, alerting security teams to changes in their attack surface before adversaries can exploit them.</p>



<p class="wp-block-paragraph"><strong>Dark web intelligence</strong> adds a critical layer that traditional scanning misses entirely. Stolen credentials, leaked databases, and mentions of your organisation on underground forums represent threats that exist outside your network perimeter but directly impact your security posture. Integrating dark web monitoring into the ASM workflow provides early warning of compromised accounts and data breaches.</p>



<h2 class="wp-block-heading">The Intelligence Perspective</h2>



<p class="wp-block-paragraph">From an intelligence standpoint, attack surface management is fundamentally an exercise in counter-reconnaissance. You are attempting to see yourself the way an adversary sees you, and to close gaps before they are exploited.</p>



<p class="wp-block-paragraph">This is not theoretical. In my advisory work with law enforcement and government institutions, I have seen repeatedly how even well-resourced organisations are compromised through forgotten assets. A subdomain pointing to a decommissioned server. An exposed admin panel with weak authentication. A cloud storage bucket with public read access. These are not sophisticated attacks. They are failures of visibility.</p>



<p class="wp-block-paragraph">The lesson is clear. Cybersecurity is not primarily a technology problem. It is an intelligence problem. And like all intelligence problems, it begins with knowing your own terrain.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">The European cybersecurity landscape is at an inflection point. Regulatory pressure is increasing. Attack automation is accelerating. And the gap between enterprise-grade security and SME capability remains dangerously wide.</p>



<p class="wp-block-paragraph">Attack surface management is not a luxury. It is the foundation upon which all other security measures depend. Without continuous visibility into your external exposure, every other investment in cybersecurity is built on incomplete information.</p>



<p class="wp-block-paragraph">For organisations ready to take this step, the tools now exist to make it practical and affordable. The question is no longer whether you can afford to implement continuous attack surface monitoring. It is whether you can afford not to.</p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>WiFi Signals Can See You: How CSI Sensing Works</title>
		<link>https://www.digitalintelligence.at/wifi-signals-can-see-you-how-csi-sensing-works/</link>
					<comments>https://www.digitalintelligence.at/wifi-signals-can-see-you-how-csi-sensing-works/#respond</comments>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Tue, 06 Jan 2026 17:48:03 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Intelligence]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4401</guid>

					<description><![CDATA[Your WiFi router does more than connect you to the internet. The radio waves it sends are bouncing off everything in your room, including you. And those reflections contain a surprising amount of information. This is called CSI sensing, and it is quietly becoming a big deal in security, smart homes, and healthcare. What is CSI? CSI stands for Channel State Information. When WiFi signals travel from your router to your phone, they dont go in a straight line. They bounce off walls, furniture, and people. This is called multipath propagation. Modern WiFi (802.11n and newer) divides its channel into]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Your WiFi router does more than connect you to the internet. The radio waves it sends are bouncing off everything in your room, including you. And those reflections contain a surprising amount of information.</p>



<p class="wp-block-paragraph">This is called CSI sensing, and it is quietly becoming a big deal in security, smart homes, and healthcare.</p>



<h2 class="wp-block-heading">What is CSI?</h2>



<p class="wp-block-paragraph">CSI stands for Channel State Information. When WiFi signals travel from your router to your phone, they dont go in a straight line. They bounce off walls, furniture, and people. This is called multipath propagation.</p>



<p class="wp-block-paragraph">Modern WiFi (802.11n and newer) divides its channel into many subcarriers. For each one, the system measures amplitude (signal strength) and phase (timing). This data is CSI.</p>



<p class="wp-block-paragraph">Here is why this matters: when a person moves through a room, they disturb these signal paths. The human body contains a lot of water, which affects radio waves significantly. This disturbance shows up in CSI data as measurable changes.</p>



<p class="wp-block-paragraph">So if you can read CSI data and analyze it properly, you can detect human presence and movement without any cameras or sensors on the person.</p>



<h2 class="wp-block-heading">How it actually works</h2>



<p class="wp-block-paragraph">Think about throwing a stone in a pond. The ripples spread out and reflect off the edges. If someone walks through the water, the ripple pattern changes in a predictable way.</p>



<p class="wp-block-paragraph">WiFi signals work similarly. There are regions between transmitter and receiver called Fresnel zones where signals interfere with each other. When you walk through these zones, you cause phase shifts that can be detected.</p>



<p class="wp-block-paragraph">The processing pipeline looks like this:</p>



<p class="wp-block-paragraph">First you collect raw CSI data from WiFi hardware. Then you clean it up, remove noise, fix phase errors. After that you extract features like variance, frequency components, correlation patterns. Finally you feed this into a classifier, could be SVM, could be a neural network like LSTM or CNN.</p>



<p class="wp-block-paragraph">Recent papers from 2024 and 2025 report accuracy rates above 99% for activity recognition on standard datasets. Real world performance is lower, but still impressive.</p>



<h2 class="wp-block-heading">What can you do with this?</h2>



<p class="wp-block-paragraph"><strong>Detecting people</strong></p>



<p class="wp-block-paragraph">The most basic application. Is someone in the room or not? This works even through walls, which is something cameras cannot do. You dont need line of sight.</p>



<p class="wp-block-paragraph"><strong>Activity recognition</strong></p>



<p class="wp-block-paragraph">With good training data, you can distinguish walking from sitting from falling. This is useful for elderly care. If grandma falls and doesnt get up, the system can alert someone. No wearable device needed.</p>



<p class="wp-block-paragraph"><strong>Vital signs</strong></p>



<p class="wp-block-paragraph">This one surprised me when I first learned about it. When you breathe, your chest moves a few millimeters. This tiny movement creates detectable changes in CSI. Researchers have demonstrated breathing rate detection and even heart rate estimation in controlled conditions.</p>



<p class="wp-block-paragraph"><strong>Intrusion detection</strong></p>



<p class="wp-block-paragraph">This is where it gets interesting from a security perspective. Traditional motion sensors have problems. They have blind spots. They can be fooled if you move slowly enough. They need to be installed and maintained.</p>



<p class="wp-block-paragraph">CSI based intrusion detection uses your existing WiFi infrastructure. It can detect slow, careful movement that would fool a PIR sensor. It works through walls. The intruder cannot see where the sensors are because there are no sensors, just your router.</p>



<p class="wp-block-paragraph">Systems like Wi-Alarm have shown reliable detection of various intrusion patterns in research settings.</p>



<p class="wp-block-paragraph"><strong>Counting people</strong></p>



<p class="wp-block-paragraph">You can estimate how many people are in a room. Useful for building management, energy savings, or compliance with occupancy limits.</p>



<h1 class="wp-block-heading">How to Get Started &#8211; Technical Implementation</h1>



<p class="wp-block-paragraph">The cheapest way to experiment with CSI sensing is an ESP32 microcontroller. Espressif provides an official esp-csi toolkit on GitHub. You flash the firmware, connect the ESP32 to your WiFi network, and it starts outputting raw CSI data over serial. The data includes amplitude and phase for each subcarrier, typically 52 values per packet at 100-200 packets per second. From there you pipe it into Python for processing. Basic presence detection works by calculating variance across subcarriers. When someone moves, variance spikes. When the room is empty, it stays flat. You can get this working in an afternoon.</p>



<p class="wp-block-paragraph">For better results you need better hardware. Raspberry Pi 4 with Nexmon firmware gives you access to CSI from the Broadcom WiFi chip. More subcarriers, cleaner phase data, higher sample rates. The setup is more involved, you need to patch the firmware and compile kernel modules, but there is good documentation. Intel 5300 NIC is the classic research platform with the most published code to reference, but requires an older laptop with mini PCIe slot. Once you have data flowing, the processing pipeline is standard: denoise with a low-pass filter or PCA, extract features like variance, entropy, dominant frequency from FFT, then train a classifier. Start with SVM for binary presence detection before moving to LSTM or CNN for activity recognition. Scikit-learn and PyTorch both work fine. The main challenge is not the code, it is collecting good training data for your specific environment.</p>



<h2 class="wp-block-heading">Law enforcement and intelligence use</h2>



<p class="wp-block-paragraph">This is not just academic research. Government agencies are already using this technology operationally.</p>



<p class="wp-block-paragraph">The US Department of Homeland Security has been developing through-wall sensing systems for years. Their latest project, DePLife (Detect Presence of Life), was developed with MIT Lincoln Lab. In 2024, six law enforcement agencies across California, Texas and South Carolina conducted field assessments of the technology. The system uses radar on WiFi frequencies to detect human presence through walls, showing results on a mobile app.</p>



<p class="wp-block-paragraph">Israeli company Camero-Tech makes the Xaver series, which is already deployed by military and police units worldwide. Their XLR80 model can detect people through concrete walls from over 100 meters away. It shows real-time position, movement direction, and can even detect breathing of stationary targets.</p>



<p class="wp-block-paragraph">MaXentric sells the Detex Pro to US law enforcement for around 6000 dollars. It is compact enough to lean against a wall and streams results to a smartphone. Police have used similar devices in hostage situations and warrant services.</p>



<p class="wp-block-paragraph">The Range-R is another device in active use by US police departments. It can detect movement and breathing through standard building materials.</p>



<p class="wp-block-paragraph">What makes WiFi CSI interesting is that you do not need specialized military hardware. The same physics works with commercial routers and cheap microcontrollers. The difference is range and reliability, but the basic capability is accessible to anyone.</p>



<h2 class="wp-block-heading">The security angle</h2>



<p class="wp-block-paragraph">I work in cybersecurity, so I see two sides here.</p>



<p class="wp-block-paragraph">On one hand, CSI sensing is a powerful tool. You can monitor spaces without visible cameras, which some people prefer for privacy. It works in darkness. It is hard to detect or jam. It uses infrastructure you already have.</p>



<p class="wp-block-paragraph">On the other hand, the same capabilities create risks. If an attacker has access to your WiFi network, they could potentially monitor your activities. Research has shown CSI can be used to infer keystrokes, identify individuals by their gait, and build activity profiles.</p>



<p class="wp-block-paragraph">This is not theoretical. The technology exists in commercial products and government hands. Whether it becomes a widespread threat depends on how aware people are and how we design systems going forward.</p>



<h2 class="wp-block-heading">Getting started practically</h2>



<p class="wp-block-paragraph">If you want to experiment with this, you have options at different price points.</p>



<p class="wp-block-paragraph">The cheapest is ESP32, around 5 euros. Espressif provides official CSI tools and it is relatively easy to get started. The data quality is moderate but enough for presence detection.</p>



<p class="wp-block-paragraph">Raspberry Pi with Nexmon firmware is maybe 50 euros total. Better CSI quality, more flexibility, but requires more setup.</p>



<p class="wp-block-paragraph">Intel 5300 NIC is the classic research platform. Good data quality, lots of existing code and papers to reference. You need a compatible laptop though.</p>



<p class="wp-block-paragraph">For software, check out the ESP-CSI repository from Espressif, or the Linux CSI Tool for Intel hardware.</p>



<p class="wp-block-paragraph">A good first project is simple presence detection. Binary classification, room empty versus occupied. Once that works, you can try activity classification or multi-room setups.</p>



<h2 class="wp-block-heading">Limitations</h2>



<p class="wp-block-paragraph">I should be honest about the challenges.</p>



<p class="wp-block-paragraph">Environment sensitivity is the big one. A model trained in your living room probably wont work in your office without retraining. Even moving furniture can break things. This is an active research area but not solved.</p>



<p class="wp-block-paragraph">Hardware support varies. Not every WiFi chipset exposes CSI data. Consumer routers usually dont. You need specific hardware or firmware modifications.</p>



<p class="wp-block-paragraph">Multi-person scenarios are hard. When two people are moving, separating their contributions to the signal is complicated.</p>



<p class="wp-block-paragraph">Real-time processing needs decent hardware. If you want to run neural networks on CSI data continuously, you need computing power.</p>



<h2 class="wp-block-heading">Where this is going</h2>



<p class="wp-block-paragraph">WiFi 7 is coming with wider channels, which means more subcarriers and finer resolution. Some enterprise vendors like Huawei already ship access points with built-in CSI sensing for smart building applications.</p>



<p class="wp-block-paragraph">I expect we will see more commercial products in the next few years. The question is whether security and privacy considerations keep pace with the capabilities.</p>



<h2 class="wp-block-heading">Final thoughts</h2>



<p class="wp-block-paragraph">The WiFi signals in your home carry more information than most people realize. This technology is real, it is improving, and it has both positive and concerning applications.</p>



<p class="wp-block-paragraph">For security professionals, it is worth understanding. For everyone else, it is worth being aware that walls dont provide as much privacy as you might think.</p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.digitalintelligence.at/wifi-signals-can-see-you-how-csi-sensing-works/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AI is the Ultimate Distraction for National Security</title>
		<link>https://www.digitalintelligence.at/ai-is-the-ultimate-distraction-for-national-security/</link>
					<comments>https://www.digitalintelligence.at/ai-is-the-ultimate-distraction-for-national-security/#respond</comments>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Wed, 03 Dec 2025 06:19:21 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Worldwide]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4392</guid>

					<description><![CDATA[Signal Poisoning: Why AI is the Ultimate Distraction for National SecurityThe Haystack Has Changed We used to say that intelligence work was like looking for a needle in a haystack. It was difficult, sure, but at least we knew that if we found something sharp and metallic, it was probably the needle. Those days are over. Today, AI isn&#8217;t just hiding the needle; it’s dumping thousands of &#8220;fake needles&#8221; into the pile every second. They look real, they shine like metal, and they even feel sharp. But they are decoys. The modern analyst’s nightmare isn&#8217;t a lack of information it’s]]></description>
										<content:encoded><![CDATA[
<h1 class="wp-block-heading">Signal Poisoning: Why AI is the Ultimate Distraction for National Security<br>The Haystack Has Changed</h1>



<p class="wp-block-paragraph">We used to say that intelligence work was like looking for a needle in a haystack. It was difficult, sure, but at least we knew that if we found something sharp and metallic, it was probably the needle.</p>



<p class="wp-block-paragraph">Those days are over.</p>



<p class="wp-block-paragraph">Today, AI isn&#8217;t just hiding the needle; it’s dumping thousands of &#8220;fake needles&#8221; into the pile every second. They look real, they shine like metal, and they even feel sharp. But they are decoys. The modern analyst’s nightmare isn&#8217;t a lack of information it’s Information Overload on an industrial scale. We aren&#8217;t just looking for the truth anymore; we are trying to survive a flood of convincing lies.</p>



<p class="wp-block-paragraph">The Weapon of Exhaustion</p>



<p class="wp-block-paragraph">We often think of cyber warfare as hackers breaking down firewalls or stealing secrets. But the new threat is subtler and perhaps more dangerous. It’s what we call a &#8220;Bureaucratic DDoS.&#8221;</p>



<p class="wp-block-paragraph">Think of it as a weapon of exhaustion. Adversaries are using generative AI to create a &#8220;Cognitive Flood&#8221; millions of synthetic reports, deepfake videos, and bot managed panic. The goal isn&#8217;t to destroy our data; it’s to force us to waste our limited resources verifying it. It’s a &#8220;deceleration weapon&#8221; designed to clog the gears of intelligence agencies with perfectly formatted junk.</p>



<p class="wp-block-paragraph">Chasing Ghosts in the Gray Zone</p>



<p class="wp-block-paragraph">This isn&#8217;t just a digital problem; it has physical consequences. We are seeing the rise of &#8220;Physical DDoS&#8221; attacks.</p>



<p class="wp-block-paragraph">Imagine a crisis scenario: An AI bot farm floods emergency channels with reports of a massive fire or an armed conflict in a specific neighborhood. The reports look genuine. Photos generated by AI start circulating. Police and first responders rush to the scene, sirens wailing. But when they arrive, the streets are empty.</p>



<p class="wp-block-paragraph">While our security forces are busy chasing these digital ghosts, the real threat actors are operating unchecked elsewhere. This is the Gray Zone where digital deception translates into real world blindness.</p>



<p class="wp-block-paragraph">The Cost of Verification</p>



<p class="wp-block-paragraph">In this noise, the &#8220;Weak Signals&#8221; the subtle, quiet indicators of a real terrorist plot or a foreign intelligence operations are completely drowned out.</p>



<p class="wp-block-paragraph">There is a concept called &#8220;Open Source Intoxication.&#8221; It means we are getting drunk on bad data. Every hour an analyst spends analyzing a high quality deepfake is an hour stolen from investigating a real threat. The &#8220;Verification Tax&#8221; we are paying is becoming too high to sustain.</p>



<p class="wp-block-paragraph">Fighting Fire with Fire</p>



<p class="wp-block-paragraph">So, how do we fix this? We have to admit that the human eye is no longer enough. We can’t &#8220;eyeball&#8221; our way out of this.</p>



<p class="wp-block-paragraph">We need a &#8220;Zero Trust&#8221; approach to open source data. Unless a piece of information from the web (OSINT) can be cross referenced with human assets (HUMINT) or technical signals, it should be treated as noise.</p>



<p class="wp-block-paragraph">More importantly, we need to adopt an &#8220;AI vs. AI&#8221; doctrine. If the attack comes at machine speed, the defense cannot move at human speed. We need our own algorithms to filter the noise, spot the synthetic patterns, and clear the haystack, so human analysts can get back to doing what they do best: finding the real needle.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.digitalintelligence.at/ai-is-the-ultimate-distraction-for-national-security/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Notes from a Cyber Intelligence Insider: How Digital Disinformation Really Works</title>
		<link>https://www.digitalintelligence.at/notes-from-a-cyber-intelligence-insider-how-digital-disinformation-really-works/</link>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Sat, 22 Nov 2025 12:41:03 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Worldwide]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4105</guid>

					<description><![CDATA[The Greatest Danger is Hacked Perceptions

For years, I have monitored cyber threats for governments and international institutions. From securing diplomatic missions across 12 countries for the German Federal Foreign Office (Auswärtiges Amt) to tracking the digital footprints of terror financing for the Ministry of Interior in Türkiye, I have always encountered the same reality: The greatest danger I witnessed was not hacked devices, leaked databases, or cracked passwords. The greatest danger was hacked perceptions.

Today, when we say “Cyber Security,” we still picture hooded hackers and scrolling green code. But as a cyber intelligence professional who has operated in the field, I can tell you this: To collapse a state or an institution, you no longer need to attack their servers. You only need to target their reputation and the trust that holds their society together. From border security to election manipulation, I have operated wherever data is weaponized. And with this experience, I can tell you: Digital Disinformation is the nuclear weapon of the 21st century.


⚠️ WARNING: HIGH SECURITY CLEARANCE REQUIRED

Access to this intelligence report is restricted to personnel with Operational (Monthly) or Strategic (Yearly) clearance.

⛔ Standard Clearance (Free) does NOT grant access to this content. Please verify your clearance level before upgrading.]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"></p>



<h1 class="wp-block-heading">The Greatest Danger is Hacked Perceptions</h1>



<p class="wp-block-paragraph">For years, I have monitored cyber threats for governments and international institutions. From securing diplomatic missions across 12 countries for the German Federal Foreign Office (Auswärtiges Amt) to tracking the digital footprints of terror financing for the Ministry of Interior in Türkiye, I have always encountered the same reality: The greatest danger I witnessed was not hacked devices, leaked databases, or cracked passwords. <strong>The greatest danger was hacked perceptions.</strong></p>



<p class="wp-block-paragraph">Today, when we say “Cyber Security,” we still picture hooded hackers and scrolling green code. But as a cyber intelligence professional who has operated in the field, I can tell you this: To collapse a state or an institution, you no longer need to attack their servers. You only need to target their reputation and the trust that holds their society together. From border security to election manipulation, I have operated wherever data is weaponized. And with this experience, I can tell you: <strong>Digital Disinformation is the nuclear weapon of the 21st century.</strong></p>



<h1 class="wp-block-heading">We Are in an Invisible War</h1>



<p class="wp-block-paragraph">Understanding Digital Disinformation</p>



<p class="wp-block-paragraph">Wars used to be fought along physical borders. Now, they are fought on the screen of your smartphone, inside that “innocent” tweet you read with your morning coffee. I have personally analyzed how bot networks are coordinated during election periods, how terror organizations manipulate algorithms to spread propaganda, and how “Deepfake” content is designed to disrupt financial markets.</p>



<h1 class="wp-block-heading">1. Who Pushes the Button? (The Geopolitics of Likes)</h1>



<p class="wp-block-paragraph">The biggest misconception is that disinformation is chaotic. It is not. It is a calculated investment with a specific ROI (Return on Investment). The &#8220;button&#8221; is almost always pushed by states and state-sponsored groups. But the motivation isn’t just to cause trouble; it is strictly transactional. In my experience, I have seen that foreign powers invest heavily in influencing elections based on their future interests.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><strong>The Actors and Ethical Complexity :</strong></p>



<p class="wp-block-paragraph"><strong>Two or three major companies, primarily based in Israel and India, operate at the center of this industry, focusing on election interference and disinformation prevention.</strong> <strong>I can attest that the products performing the best in this field are often of Israeli origin.</strong> <strong>Importantly, the necessity of producing counter-information to prevent disinformation inherently gives these software capabilities the potential for intentional or unintentional disinformation.</strong> <strong>This demonstrates the complex dual-use ethical framework of the industry.</strong></p>
</blockquote>



<h1 class="wp-block-heading">2. The Death of the &#8220;Egg Account&#8221; (The Incubation Era)</h1>



<p class="wp-block-paragraph">If you are still trying to spot a bot by looking at its creation date or lack of a profile picture, you are fighting a modern war with a stone axe. Those days are over. Today, millions of accounts are created daily across the globe, but they don’t tweet immediately. They are put into <strong>“Incubation”</strong>. These sleeper accounts are kept dormant for months or years. When the time comes, they are sold to the highest bidder. Because they have a history, they bypass traditional security filters. The only reliable detection method left is analyzing the <strong>Synthetic Text Ratio</strong>. We are no longer looking for a “fake photo”; we are looking for the linguistic fingerprint of an LLM (Large Language Model) in their posts.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><strong>Field Evidence: Instant Data Correlation:</strong></p>



<p class="wp-block-paragraph"><strong>To quantify the access speed of these tools, we conducted a test: We created a new social media account using a freshly acquired, unlisted phone number (a &#8216;zero&#8217; line from the state) and defined political views/interests. We searched this number in an undisclosed disinformation tool on the same day. The result was instantaneous: the tool successfully returned the profile.</strong> <strong>This demonstrates an incredible data ingestion speed, suggesting zero-latency correlation or direct data access, proving that high-value information is immediately accessible.</strong></p>



<p class="wp-block-paragraph"><strong>Operational Depth: Data Enrichment and Sociological Targeting :</strong></p>



<p class="wp-block-paragraph"><strong>Open-market social media analysis tools are useless in elections for this reason.</strong> <strong>Effective disinformation requires data enrichment. These software capabilities must be fed by external data sources, such as previously compromised Turkish Republic personal information databases.</strong> <strong>By adding layers like the user&#8217;s phone number, address, age, and gender, highly potent disinformation applications can be created.</strong> <strong>This process allows for the acquisition of the target audience&#8217;s sociological profile; for example, if the area of residence is economically depressed, disinformation focused on financial matters is the most effective tactic.</strong></p>
</blockquote>



<h1 class="wp-block-heading">3. The Timeline of a Lie: Simultaneous Saturation</h1>



<p class="wp-block-paragraph">How does a lie wash over a nation in minutes? The process I have observed in the field is a masterclass in coordination. It is not a ripple; it is a tsunami. The attack happens simultaneously across three layers:</p>



<ul class="wp-block-list">
<li><strong>The Swarm:</strong> Thousands of small, incubated accounts initiate the spark.</li>



<li><strong>The Merchants:</strong> “Blue Check” verified accounts, which have been bought and repurposed, validate the lie to trick the algorithms.</li>



<li><strong>The Amplifiers:</strong> If necessary, mainstream media channels are engaged through paid advertisements or compromised journalists.</li>
</ul>



<p class="wp-block-paragraph">The key here is location diversity. The attack is launched from different geographical locations at the exact same second to trick the platform’s “organic trend” algorithms.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><strong>The Mechanism of Validation :</strong></p>



<ul class="wp-block-list">
<li><strong>Seeding:</strong> The lie is planted in “news sites” that appear reliable but are actually front operations.</li>



<li><strong>The Echo Chamber:</strong> Bot networks and “useful idiots” (an intelligence term for those who unwittingly spread propaganda) are activated.</li>



<li><strong>Legitimation:</strong> The topic becomes a Trend Topic (TT), and mainstream media validates the lie with headlines like “Claims circulating on social media…”</li>
</ul>
</blockquote>



<h1 class="wp-block-heading">4. The Future: We Need “Police AI”</h1>



<p class="wp-block-paragraph">The sheer volume of AI-generated disinformation has surpassed human capacity to moderate. We cannot fight machines with humans anymore. The future of digital security relies on <strong>“Police AIs.”</strong> We need advanced AI systems designed solely to audit the outputs of other LLMs. These systems must verify information with 100% accuracy against trusted data ledgers.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><strong>Establishing AI Provenance :</strong></p>



<p class="wp-block-paragraph">Given the proliferation of AI models in the market, <strong>it is paramount to establish the origin of any AI-generated content (text, image, etc.).</strong> <strong>For this to be operational, every AI model must be mandated to possess a unique, invisible metadata &#8216;fingerprint&#8217; or identifier.</strong> <strong>While some large AI providers are already implementing such systems, all new AI models entering the public market must be obligated to report this unique identifier to public institutions and regulatory bodies.</strong> <strong>This standardization is necessary to ensure analysis and attribution can be performed swiftly and accurately by intelligence organizations.</strong></p>
</blockquote>



<p class="wp-block-paragraph">In 2025 and beyond, the only thing that can stop a rogue AI manipulating a population is a stronger, ethically coded AI policing the digital borders.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h1 class="wp-block-heading">INTELLIGENCE REPORT</h1>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="683" src="https://www.digitalintelligence.at/wp-content/uploads/2025/11/YBBt9pcOQXSXeGE5NSHXOg-1024x683.jpeg" alt="" class="wp-image-4246" srcset="https://www.digitalintelligence.at/wp-content/uploads/2025/11/YBBt9pcOQXSXeGE5NSHXOg-1024x683.jpeg 1024w, https://www.digitalintelligence.at/wp-content/uploads/2025/11/YBBt9pcOQXSXeGE5NSHXOg-300x200.jpeg 300w, https://www.digitalintelligence.at/wp-content/uploads/2025/11/YBBt9pcOQXSXeGE5NSHXOg-768x512.jpeg 768w, https://www.digitalintelligence.at/wp-content/uploads/2025/11/YBBt9pcOQXSXeGE5NSHXOg-60x40.jpeg 60w, https://www.digitalintelligence.at/wp-content/uploads/2025/11/YBBt9pcOQXSXeGE5NSHXOg-720x480.jpeg 720w, https://www.digitalintelligence.at/wp-content/uploads/2025/11/YBBt9pcOQXSXeGE5NSHXOg.jpeg 1248w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h1 class="wp-block-heading">TECHNICAL ANATOMY OF MODERN DISINFORMATION</h1>



<h1 class="wp-block-heading">Infrastructure, Data Enrichment, and Attribution Protocols (2025)</h1>



<p class="wp-block-paragraph"><strong>Classification:</strong> PUBLIC (Redacted for General Release) <strong>Author:</strong> Ozan Akyol | Digital Intelligence <strong>Sector:</strong> Cyber Warfare &amp; Strategic Intelligence <strong>Date:</strong> November 2025</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h1 class="wp-block-heading">EXECUTIVE SUMMARY</h1>



<p class="wp-block-paragraph">Unlike traditional cyberattacks that prioritize stealth and anonymity, modern disinformation operations prioritize <strong>&#8220;Localization&#8221;</strong> and <strong>&#8220;Persistence.&#8221;</strong> This report outlines the technical architecture of state-sponsored and private-sector influence campaigns observed in the field.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h1 class="wp-block-heading">1. INFRASTRUCTURE &amp; NETWORK ARCHITECTURE</h1>



<p class="wp-block-paragraph">The primary objective of the network layer is not to hide the traffic, but to make it appear indistinguishable from organic local activity.</p>



<ul class="wp-block-list">
<li><strong>4G/5G SIM Farms (The Localization Layer):</strong> Botnets no longer rely solely on datacenter IPs, which are easily flagged. Instead, operators utilize industrial-scale <strong>4G/5G SIM Farms</strong>.
<ul class="wp-block-list">
<li><em>Operational Logic:</em> The goal is to ensure traffic originates from a legitimate mobile carrier (e.g., a specific cell tower in Berlin or Istanbul). This bypasses &#8220;Datacenter IP&#8221; filters and mimics genuine user behavior.</li>
</ul>
</li>



<li><strong>Weaponized IoT Devices:</strong> Compromised IoT devices (smart cameras, home routers) are utilized to achieve <strong>&#8220;Geo-Distribution.&#8221;</strong> By routing traffic through residential devices, the operation signals to platform algorithms that a topic is being discussed organically across the entire country, rather than a single server farm.</li>



<li><strong>Bulletproof Hosting Strategy:</strong> For the &#8220;Seeding&#8221; phase (hosting fake news sites), operators prefer <strong>Bulletproof Hosting</strong> providers located in jurisdictions with high resistance to international takedown requests, specifically <strong>USA, China, and Myanmar</strong>. The priority here is physical control and resilience against legal intervention.</li>
</ul>



<h1 class="wp-block-heading">2. C2 ARCHITECTURE &amp; SOFTWARE STACK</h1>



<p class="wp-block-paragraph">The Command and Control (C2) infrastructure is designed for <strong>Portability</strong> and <strong>Speed</strong>, not aesthetics.</p>



<ul class="wp-block-list">
<li><strong>Tech Stack:</strong> 80% of observed operations utilize a <strong>Python-based</strong> architecture. <strong>Django</strong> is the standard for User Interface (UI) development.
<ul class="wp-block-list">
<li><em>Why Python?</em> It allows for rapid prototyping (Hot-fixes), extensive library support for data manipulation, and easy <strong>Dockerization</strong>. If a server is burned, the entire C2 infrastructure can be migrated to a new jurisdiction in minutes.</li>
</ul>
</li>



<li><strong>Minimalist Design:</strong> These tools do not have polished UIs. They feature raw dashboards focused on inputting targets and monitoring volume/sentiment.</li>
</ul>



<h1 class="wp-block-heading">3. DATA ENRICHMENT &amp; TARGETING (The Kill Chain)</h1>



<p class="wp-block-paragraph">The most lethal aspect of modern disinformation is the fusion of social media data with leaked state databases.</p>



<ul class="wp-block-list">
<li><strong>Database Management:</strong> Operators use SQL-based structures (PostgreSQL/MySQL) to handle massive datasets. Python libraries (Pandas/SQLAlchemy) are employed to ingest &#8220;Dump Data&#8221; (leaked ID numbers, addresses, GSM numbers) and convert them into operational targeting lists.</li>



<li><strong>The Confidence Algorithm:</strong> Systems use a <strong>&#8220;Confidence Score&#8221;</strong> to match a social media profile with a real-world identity:
<ul class="wp-block-list">
<li><em>Match (Name + Surname + Phone):</em> <strong>70% Confidence</strong></li>



<li><em>Match (Name + Surname + Phone + Address):</em> <strong>90% Confidence</strong></li>



<li><em>Tactical Application:</em> This score dictates the attack vector. High-confidence targets in economically depressed areas are targeted with financial disinformation; others may be targeted with political or social polarization content.</li>
</ul>
</li>
</ul>



<h1 class="wp-block-heading">4. DETECTION &amp; FORENSICS</h1>



<p class="wp-block-paragraph">Identifying these networks requires moving beyond simple content analysis to behavioral and visual forensics.</p>



<ul class="wp-block-list">
<li><strong>Temporal Analysis:</strong> We analyze the timestamps of activity.
<ul class="wp-block-list">
<li><em>Indicator:</em> Does the account tweet every day at exactly 13:30? Is there a human-like randomization (jitter) in the intervals, or is it perfectly linear?</li>
</ul>
</li>



<li><strong>Visual Forensics (GAN Detection):</strong> Profile pictures are scanned for artifacts typical of <em>ThisPersonDoesNotExist</em> (GAN-generated) faces, such as asymmetric pupils, background distortion, or ear irregularities.</li>



<li><strong>Network Visualization (Maltego):</strong> While public institutions often use proprietary reporting tools, <strong>Maltego</strong> remains the industry standard for deep analysis. It is used to map the relationship clusters—visualizing who follows whom, who retweets whom, and funding sources.</li>
</ul>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><strong>Figure 1.1:</strong> <em>Visualization of a coordinated botnet cluster targeting specific keywords. Node relationships indicate simultaneous Retweet/Quote actions, revealing the inorganic structure of the network. (Generated via Maltego).</em></p>
</blockquote>



<h1 class="wp-block-heading">5. ATTRIBUTION (Following the Trail)</h1>



<p class="wp-block-paragraph">In the cyber domain, IP addresses can lie, but money cannot.</p>



<ul class="wp-block-list">
<li><strong>&#8220;Follow The Money&#8221;:</strong> Disinformation is expensive. It requires servers, thousands of SIM cards, software development, and ads.</li>



<li><strong>Attribution Methodology:</strong> Technical artifacts (e.g., comments in Russian/Chinese code) are often <strong>False Flags</strong> left intentionally to mislead. The most reliable attribution method is <strong>Cui Bono</strong> (Who Benefits?). Following the financial trail of server payments and spend similar to terror financing investigations often leads to the true perpetrator.</li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>End of Report</strong> <em>Access restricted to Operational and Strategic tier members.</em></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Milipol Paris 2025 Analysis</title>
		<link>https://www.digitalintelligence.at/milipol-paris-2025-analysis/</link>
		
		<dc:creator><![CDATA[Ozan Akyol]]></dc:creator>
		<pubDate>Wed, 19 Nov 2025 10:59:16 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[Worldwide]]></category>
		<category><![CDATA[counter-terrorism]]></category>
		<category><![CDATA[defence technology]]></category>
		<category><![CDATA[homeland security]]></category>
		<category><![CDATA[Milipol 2025]]></category>
		<category><![CDATA[security industry]]></category>
		<guid isPermaLink="false">https://www.digitalintelligence.at/?p=4100</guid>

					<description><![CDATA[Field Notes from Milipol Paris 2025: A Smaller Exhibition, Lower Expectations, and a Noticeable Lack of Innovation Milipol Paris 2025 presented a markedly different atmosphere compared to previous years. The exhibition area was significantly smaller, and the overall pace of the event reflected this downsizing. Walking through the halls at a steady speed, it became clear that the entire fair could be completed in roughly 2.5 to 3 hours, leaving many visitors with the impression that this year&#8217;s edition offered considerably less material, fewer innovations, and a more muted energy. A Noticeable Downsizing: Compact Layout, Limited Movement The most immediate]]></description>
										<content:encoded><![CDATA[
<h1 class="wp-block-heading"><strong>Field Notes from Milipol Paris 2025: A Smaller Exhibition, Lower Expectations, and a Noticeable Lack of Innovation</strong></h1>



<p class="wp-block-paragraph">Milipol Paris 2025 presented a markedly different atmosphere compared to previous years. The exhibition area was significantly smaller, and the overall pace of the event reflected this downsizing. Walking through the halls at a steady speed, it became clear that the entire fair could be completed in roughly <strong>2.5 to 3 hours</strong>, leaving many visitors with the impression that this year&#8217;s edition offered considerably less material, fewer innovations, and a more muted energy.</p>



<h1 class="wp-block-heading"><strong>A Noticeable Downsizing: Compact Layout, Limited Movement</strong></h1>



<p class="wp-block-paragraph">The most immediate observation was the <strong>reduced physical scale</strong> of the event. Booths were positioned more closely than in past years, and the density of exhibitors despite the large names felt objectively lower. This compressed setup resulted in a faster circulation flow, but it also contributed to a sense that Milipol 2025 lacked the depth, diversity, and exploratory appeal that previously defined the fair.</p>



<h1 class="wp-block-heading"><strong>Country-Based Clustering: An Arrangement That Created Distance Instead of Engagement</strong></h1>



<p class="wp-block-paragraph">One of the structural choices that shaped the atmosphere this year was the decision to cluster companies <strong>strictly by country</strong>. While the intention was likely to create national showcases, in practice it led to a somewhat <strong>fragmented and less inviting environment</strong>. Instead of fostering cross-sectional interaction among companies, the country pavilions unintentionally created psychological boundaries between groups.</p>



<p class="wp-block-paragraph">Many exhibitors noted that this arrangement gave the fair a rigid, compartmentalized feel reducing spontaneous engagement and limiting the natural flow of visitors across sectors.</p>



<h1 class="wp-block-heading"><strong>A Clear Sign of Cost-Cutting: The Decline of Traditional Giveaways</strong></h1>



<p class="wp-block-paragraph">In earlier years, Milipol was known for its abundance of branded military caps, tactical accessories, patches, and various promotional items. This year, however, the overwhelming majority of booths offered <strong>nothing beyond a simple pen</strong>.<br>This shift is not trivial; it reflects a broader trend across the industry:</p>



<ul class="wp-block-list">
<li>Firms are <strong>reducing marketing expenditures</strong>,</li>



<li>Trade show ROI is being questioned more openly,</li>



<li>Promotional spending is no longer seen as essential for visibility.</li>
</ul>



<p class="wp-block-paragraph">The minimalistic approach to giveaways mirrors the general tone of the event: <strong>lean budgets, cautious strategies, and a wait-and-see posture across the sector.</strong></p>



<h1 class="wp-block-heading"><strong>Innovation Gap: Few (If Any) New Products on Display</strong></h1>



<p class="wp-block-paragraph">Perhaps the most striking aspect of Milipol 2025 was the <strong>absence of genuine novelty</strong>. Across both hardware and software domains, companies showcased products that were largely familiar iterations or re-presentations of existing solutions rather than newly launched concepts.</p>



<p class="wp-block-paragraph">Notably:</p>



<ul class="wp-block-list">
<li>No groundbreaking surveillance systems,</li>



<li>No next-generation counter-drone innovations,</li>



<li>No major OSINT/SOCINT software advancements,</li>



<li>No significant new tactical hardware platforms.</li>
</ul>



<p class="wp-block-paragraph">The fair felt more like a continuation of previous editions rather than a forward-looking showcase. Many exhibitors appeared to be present only to “maintain visibility,” not to demonstrate new technology.</p>



<h1 class="wp-block-heading"><strong>Conversation with Exhibitors: “We’re Here Out of Obligation, Not Expectation”</strong></h1>



<p class="wp-block-paragraph">During discussions with <strong>three to four companies</strong>, a recurring theme emerged: <strong>minimal expectations</strong>.<br>Multiple representatives openly admitted:</p>



<ul class="wp-block-list">
<li>“We’re not expecting much from this year’s Milipol.”</li>



<li>“We came out of obligation rather than opportunity.”</li>



<li>“Budgets are tight; this is more about presence than results.”</li>
</ul>



<p class="wp-block-paragraph">This sentiment was surprisingly consistent and highlights an important shift in the security and defence exhibition ecosystem. The industry appears to be navigating a transitional phase marked by budget constraints, uncertain market directions, and a reduction in high-impact product launches.</p>



<h1 class="wp-block-heading"><strong>Overall Impression: A Transitional Year for the Security Industry</strong></h1>



<p class="wp-block-paragraph">Milipol Paris 2025 can best be described as a <strong>quiet, transitional year</strong>. While the fair still gathered key players from across the defence, intelligence, and security sectors, the overall energy was restrained. With smaller booths, limited product innovation, cost-cutting signals, and lower expectations among exhibitors, the event reflected broader conditions in the European security landscape marked by strategic caution and reduced investment appetite.</p>



<p class="wp-block-paragraph">Whether this signals a temporary slowdown or a longer-term recalibration remains to be seen. What is certain, however, is that Milipol Paris 2025 provided a clear snapshot of an industry taking measured steps rather than bold leaps.</p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
