episode.ascii — live render
● episode

The Black Folder

TL;DRProject Raven was a secret UAE cyber-espionage program staffed by ex-NSA contractors, including Lori Stroud, who recruited Edward Snowden. They hacked dissidents, journalists, and foreign governments for UAE intelligence, leading to US…

Jordan Bloemen & Scott Francis Winder discuss Project Raven, and the fuzzy line between a good spy and a bad one.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: It's your first day at a new job, and you walk into the room and on the table in front of you are two folders. The first folder is purple and the second folder is black. Inside the first folder is a document that explains the job you're there to do and the job is as follows. You are a cybersecurity professional. It's your job to build firewalls, stop intruders, and plan and build defensive measures. Which makes sense to you, that's the job you showed up to do. But right there on the table is that other folder, the black folder. And you pick it up and you open it. And the black folder says, you know the purple folder? Like the one you just read? It was a lie. It's your cover. It's what you're gonna tell people but it's not what you're actually here to do. You are not a defensive cybersecurity professional. You are an offensive one. You are a cyber spy tasked with hacking whoever we tell you to. You are to use your considerable knowledge to hack people's emails, steal personal information, monitor their conversations, and if possible, track their movement. But you've got the purple folder. You've got the cover. No one has to know what you're actually here to do. And it's all legal. It's totally above board. And you're gonna be paid super well. So you got those two folders, those two different stories, and the question that we're going to talk about today, the question kind of at the heart of this whole story is do you show up for work the next day? So this year, years after that question, exact question, was posed to a handful of people who showed up for work in a villa in the desert, this year charges were laid, and this month a settlement was reached regarding their participation in something called Project Raven, our subject this episode. This is The Black Folder, here on HAPPED. Is that the theme song?

Speaker 2: That's the new theme song, yeah.

Speaker 1: I don't remember that part of the theme song. I could remix that and put it at the end.

Speaker 2: Well, good news. It's in my audio file. So like many other things that shouldn't end up in the podcast episodes that you feel that you do include, I'm sure it will include itself through the final edit.

Speaker 1: Editorial discretion. So, Scott, say you used to work for the NSA or like CSIS here in Canada. Yep. You were a cyber spy for like your government.

Speaker 2: Yep. But

Speaker 1: then you quit being a cyber spy for your government and you move to another country. A country that has their own cyber intelligence organization. Here's a very big question is it legal for you to go and work for them?

Speaker 2: I have no idea. I would assume I would assume that when you start working for the NSA that there is some Yeah. Life binding contracts and agreements that are partaken in. So, I have no clue, but my best guess would be probably not. I think the trees in Hammer is probably pretty close to you at that point.

Speaker 1: Sure. Sure. It's kinda just hanging over your head the second you get off the airplane.

Speaker 2: Yeah. You're like, hey. I'm here to work in your cybersecurity division with all of the knowledge I have from their cybersecurity division. I'm sure I'm sure it's not a good look.

Speaker 1: That would make a lot of sense, wouldn't it?

Speaker 2: Would.

Speaker 1: According to US National Security lawyers, it's, it's it's shockingly legal. Wow. The laws are pretty muddy. Yeah. You can totally do it. You can get on a plane, and if you work for the NSA, you can go work for someone else. But there are importantly two things that remain super, super illegal in that very, very specific situation. It is a mega illegal to go work for a foreign government and share classified information regarding hacking.

Speaker 2: Of course.

Speaker 1: Like you can't share classified methods, classified tools. And it is b illegal to go to another country and then spy on your own countrymen.

Speaker 2: Sure. Actual treason.

Speaker 1: It's just treason at that point. It doesn't matter if you used to spy on Americans legally Yeah. Because you were doing for the NSA. If you do it for someone else, it is still it's treason. Which sounds like a pretty like like okay I can follow those those rules. Don't share classified stuff and don't spy on their countrymen but no part of this story is nearly as clean-cut as that because the cast of the story is spies and they are not a historically forthcoming bunch. Totally.

Speaker 2: And once you learn something as has been historically proven time and time again in intellectual property lawsuits probably, once you learn something, it's hard to not know it and have it not guide your decision making. So violation of of rule one is probably very common as well. Mhmm. Mhmm.

Speaker 1: Yeah. It's pretty tough to be, like, year four at a job and to know how to do something and to not say something because the solution is classified.

Speaker 2: Yeah. And be like, I don't know, guys. What if we tried this? Who knows?

Speaker 1: Yeah. It's a real it's a real thinker, and they're all looking at you, and they're like, we know the NSA knows how to do that, my guy. Like, can

Speaker 2: you please just tell us?

Speaker 1: So only one person has made their name public, and told their experience of working at Project Raven, our subject. So we're gonna tell her story, and it is the story of a woman named Lori Stroud. Lori Stroud worked for the NSA for over a decade for the first six years as a military service member from 2003 to 2009 for jumping over to being an external vendor from 2009 to 2014, where she worked at a consultancy called Booz Allen Hamilton. It was Laurie's job to go digging around for vulnerabilities in foreign government systems. So she would, you know, try and get into some government computers in China or Russia, figure out and identify whose targets were that the rest of the team would then go after. But in 2013, Stroud's, like, shine at the NSA wears off. She's been crushing it for a decade, but then she does something that, she characterized an interview as, quote, ruining her brand. Can you recall anything that happened at the NSA in 2013, Scott?

Speaker 2: Feel like there was a young programmer who released a pile of inside information about surveillance, and maybe he ran away to other countries landing in, I believe, Russia. Does that sound familiar?

Speaker 1: Yeah. So our girl, Lori, while stationed in Hawaii, Stroud recommended that this technician who was working in the building join her team. I I want this guy. He's great. He should join my team. A guy by the name of Edward Snowden.

Speaker 2: Man. And it is Good name.

Speaker 1: A great name. Very memorable, historical even. And it was here as part of her team that Snowden, we don't need to explain what Edward Snowden did. Right? You kind of already did. Yeah. It was here as part of her team. Yeah.

Speaker 2: I said the word trees in, like, all the So I think

Speaker 1: Yeah. They get it. It was as part of her team based on her recommendation to join her team that Edward Snowden gained access to the information that he would go on to leak. Less than sixty days after joining Stroud's team, Snow had vanished with all of that data, and Stroud had kind of accidentally inadvertently given him access to it. So, yeah, her brand at the NSA was not in good shape. And in the aftermath of all that, Stroud gets this really interesting offer. This old colleague, a guy named Mark Baer, that name is gonna come up again, offers her a job to work for a different government contractor at a different government, a company called CyberPoint, who did work in The United Arab Emirates, the setting of this whole story. So, like, Stroud looks around at the big Edward Snowden shaped smoldering pit that she's standing in, and she figures, yeah, I should probably go seek some new opportunities. So she takes the offer. She goes to work at CyberPoint. CyberPoint is a small cybersecurity firm based out of Baltimore, and they've done work for the US Department of Defense, and they do work in The UAE. For context, in 2014, The United today, actually, The UAE and The US are close allies born of shared enemies, in this case, ISIS. Neither of them likes ISIS. Both use their intelligence organizations and hacking specifically to go after ISIS and other terror groups in the region. So the idea of an American consulting company working for The UAE and the American government is not crazy at all. And CyberPoint, for context, has claimed that they have done nothing improper throughout this entire story, which if you define improper as illegal, they might actually be in the clear. Whether or not it was, like, cool stuff they did is a different story, but we're gonna get to that.

Speaker 2: Alright.

Speaker 1: So CyberPoint, generally above board company, pay their managers close to half $1,000,000 a year, offer Stride this job, and she says, let's do this. Scott, say you run a cybersecurity consultancy and you've got this very sensitive client. When do you tell a new hire like Stroud, hey. This is what your job is actually gonna entail. When do you reveal that to them?

Speaker 2: I feel like it's either day one or the one day after their legal probation's over. It's one of those two.

Speaker 1: Right. Yeah. Whatever it says in that very thick NDA you make them sign.

Speaker 2: Yeah. Exactly.

Speaker 1: Yeah. So Stroud signs that very lengthy NDA, which comes up again. She gets on a plane and she arrives in The UAE and she goes to their office, which is this big, huge converted mansion known by the team as the villa. And it's here that she's brought into a room with two folders on a table. The purple folder and the black folder. The purple folder, is her cover. They are contractors in The UAE protecting the government from hackers and other threats. And then there's the other one, the Black Briefing, and explains what Project Raven actually is. To directly quote the Black Briefing that Stroud received, Raven was, quote, the offensive operational division of NESA and will never be acknowledged to the general public. NISA is The UAE's version of the NSA. It's their cybersecurity agency.

Speaker 2: So

Speaker 1: whatever you think NISA think Emirates NSA. Stroud was gonna be part of Raven's analysis and target development shop. She was tasked with helping the government profile their enemies online, hack them, and collect data. And those targets were provided to cyber point by the client, Nisa. So she works for a company, and the company gets assignments from The UAE's NSA, essentially.

Speaker 2: Sure.

Speaker 1: All of this kind of, like, cloak and dagger, all the language of it, Strad said it made her feel right at home because it's exactly how the NSA worked. Yeah. The security infrastructure that they were feeding is the subject of a lot of international criticism, like, that CyberPoint was feeding information into. People talk a lot about what The UAE does with hacking. And in the words of critics of The UAE, they've been accused of suppressing free speech, detaining dissidents, going after domestic targets, not because they're dangerous, but because they're, politically challenging in some way.

Speaker 2: Vocally opposed. Yeah.

Speaker 1: In their words, the UA says, no. It works with Washington to fight extremism. That's it. But disregarding what is said about them, and what they say about themselves, there's who this whole thing is revealed they're actually targeting, in the sort of legal and journalistic fallout. We have a very good sense of who this organization was looking at. And some of them are the foreign adverse adversaries that you would expect. Iran, Qatar, Turkey, these are governments going after other governments. This is kind of what you expect. But then there are the domestic actors, people inside The UAE that the UAE government is targeting using this cyber point company.

Speaker 2: Mhmm. A

Speaker 1: quote directly from Stroud. Quote, some days, it was hard to swallow, like when you target a 16 year old kid on Twitter. But it's an intelligence mission. And you're an operative. I never made it personal. And this is where, I guess, a really interesting boundary between what the American contractors for project Raven would do, the people who worked for CyberPoint, and what the Emirati operatives who also worked for project Raven but not part of cyberpoint would do because there's a difference. There's a really hard line between what one would do and the other would because of those American laws. The Americans would identify the vulnerability of the target. They might develop a tool or a hack to go after them, but it was typically an Emirati operative who would, like, press the button. Because a law might kinda shake out later that, oh, actually going after them was illegal. So it's just easier to create this really clean line in the sand that says, no. The person who was always doing it wasn't an American citizen.

Speaker 2: Oh, interesting.

Speaker 1: And I imagine that yeah. I'm and I'm curious, like, I feel like that kind of compartmentalization probably doesn't exist in most other cybersecurity operations, but it probably exists in every national cybersecurity operation.

Speaker 2: I feel oh, I don't know about every. I think there's a lot of countries that don't really care. They're they're more than willing to push the button themselves, but it just I just find it fascinating because it, you know, ties back a lot to their, you know, post nine eleven, you know, treatment of prisoners, you know, the whole Right. Debacle around torture and, like, you know, Guantanamo. And it's Guantanamo is in Cuba. It's not in The States, so therefore, it's not happening on American soil. And you know, all these weird legalese and legal loopholes. And it's like, yeah. Yeah. No. We're fine to essentially write the script, the plan, the action, everything. Yeah. You know, we just wanna make sure that we've, you know, covered our own. So we're just not gonna put the go button, but if you could just get somebody that you pay to push the go button and then just give us the information, we'd appreciate it. Thanks. It's like We

Speaker 1: just got we just gotta hire a guy to press the go button.

Speaker 2: It just it just feels so brutally Patriot Act American. And I'm probably gonna gonna catch flack on Twitter for saying that, but

Speaker 1: Well, it I mean, without getting too much into it, it would kind of make sense that it would imitate the cybersecurity tactics of the people that they're paying to teach them how to do cybersecurity. Yeah. It's interesting.

Speaker 2: Yeah.

Speaker 1: So on the subject of these targets, the people on the receiving end of that go button push, we're gonna talk about two. And I wanna start with a guy named Rory Donaghy. So in 2012, Rory was a 25 year old British journalist and activist who'd written a bunch of articles criticizing, the country's human rights record. In 2012, he wrote an opinion piece for The Guardian looking at the UAE government's activist crackdown and warning that if continued quote, those in power face an uncertain future. Based on that writing, project Raven gets the assignment from on high to go after this guy. And remember, they had been brought in to bring over all their spy craft from their time at the NSA NSA to kind of mentor and teach these, UAE operatives. Mhmm. Prior to their arrival, prior to 2021, former operatives explained that the early intelligence gathering operations largely relied on agents, like, physically breaking into homes while they were, like the subject was away and physically placing spyware on computers. The Americans start to try and build project Raven and this thing that looks a lot more like what they were doing over in The States. And they're looking for wins that show that this style of you know we're not going to physically break in we're going to find all these other ways to get stuff onto the the victims devices and whatnot. They wanted like a way to show that that worked really well.

Speaker 2: And Right.

Speaker 1: Donahue was this big public target that offered these contractors at cyberpoint a really visible win, kind of a proof of concept. Social engineering is one of our oldest subjects on this show, and they weren't really doing it. They were just physically breaking it. They weren't tricking people. And so CyberPoint says, this is what we're gonna do. We're gonna show off how well this can work. To To quote members of the team from declassified reports, to get close to Donahue, the Raven team set out to, quote, ingratiate themselves to the target by espousing similar beliefs

Speaker 2: Okay.

Speaker 1: Predicting that Donahue would be, quote, unable to resist an overture of this nature. So they invent these characters. Human rights activists like Donahue, they start pretending to be them, and they start emailing Donahue asking for help to bring hope to those who are long suffering. And they they kinda cultivate this relationship pretending to be whistleblowers that wanna talk to him until they finally get Donnie to download and install software that they claimed would make it difficult to track messages, sort of like a signal style encrypted messaging app.

Speaker 2: Mhmm.

Speaker 1: He does. And you can guess where this going. The software installed was actually malware that allowed project Raven to continuously monitor his email accounts, Internet browsing. This project started a little bit before Stroud got there well into the reign of kind of the Americans being there, and it continued well into Stroud's time there. And it was, like, a really big priority for project Raven.

Speaker 2: Mhmm.

Speaker 1: Until one day, Don He eventually figures out, oh, my email's been hacked. In 2015, he gets, like, a different dodgy email from a similar account, decides to get in touch with Citizen Lab who we've interviewed on this show before, and they figured out that he'd been a target for years. He gets the stuff locked down. Donnie's okay. He was spied on his privacy was evaded, but he is, like, physically okay. And a large part of that has to do with the fact that he's not from there. He's he's British. And importantly, not an American. So not illegal for the ex NSA members to hack in the way that it would be if he was from The States. Sure. And that brings us to the other victim the other kind of kind of victim. The victim on the far side of that veil of deniability that this whole place operated on a guy named Ahmed Mansour. He's a prominent, Emirati activist and he was code named in their system Ygritte and he was the target of another kind of one of these campaigns. For years Mansour had been a very public critic of the government, from their war in Yemen to the treatment of migrant workers. And in September 2013, Raven operatives roll into the office of a bunch of senior NISA officials with this big folder of material they've been getting off this computer. Big grins on their face, look how good we did. Inside the folder are photographs that Mansour took of a dissident being held, in prison. And it turns out that taking those pictures of that prisoner is against prison policy and therefore the law. And then when Mansour gets them on his computer sees them, thinks probably shouldn't have these and deletes them, he's now tried to destroy the evidence. So it's not the crime, it's the cover up. Right? It's not the crime, it's the cover up. All of this, helped lead to Munster's conviction in a secret trial in 2017 when he was charged with damaging the country's unity and sentenced to a decade in jail. Yikes. That's kind of a spread on the kinds of folks that Raven was targeting. You've got British journalists who are critical of the government. You've got domestic activists who are trying to, you know, highlight abuses in prison and getting sent in jail for it. Which brings us to their tactics, kinda how they did all this. And a big question if we go back to the legal tension in the middle of the story, is where the line between spy craft and a confidential technique is. And that's sort of what makes all of this legal or not. General spy craft cool, specific tool, not okay. And a big example of that in this story is this piece of technology called Karma. Karma is a bit like the no click iOS exploit that made the news like I think three or four months ago. And it had been turned into essentially a I don't know if you could call it a commercial product, but Karma used most prominently in like twenty sixteen and twenty seventeen is a tool that could remotely give you pretty much full access to an iPhone just by uploading the phone number of the person who used that iPhone or their email account into this automated targeting system front end of Karma. Sure. Yeah. And you can probably think of the part of Apple's, like, service ecosystem that relies on either your phone number or your email. It's iMessage.

Speaker 2: Yeah. It's a a backdoor that causes something to auto preview or load or run-in the background that drags the exploit onto your computer and runs it before you've even had the chance to delete the message.

Speaker 1: Three former operatives said that they understood Karma to work at least based on this, yeah, the zero day exploit in, built in the iMessage. The blue bubble has finally betrayed us. And the way it worked was that you would punch in an email or a number and Karma would send this message that leverage this exploit to install malware and take control of the device, which is like a very, very powerful product when you start thinking about those terms because you can upload hundreds of phone numbers and hundreds of emails and just see what you get.

Speaker 2: Just collect phones.

Speaker 1: It's basically collect phone numbers of everyone that you wanna hack and just hit enter. And an interesting thing that occurred to me is that you would also have to keep that tool in a very, very small number of hands lest Apple find out about it and patch the vulnerability.

Speaker 2: A tech tip about malware installed on your phone. Apple has done such a good job kind of creating a sandboxed OS that writing to the permanent, kind of OS image is very, very hard. So even if you your phone does get exploited, often chances, it won't actually write itself to the boot volume. It'll kind of just live in active memory. So one of the best things you can oddly do to just, like, turn off malware on your phone is just reboot it. Really? It's the classic It's

Speaker 1: like a

Speaker 2: the classic IT thing of just, like, you know, there could be your your phone could probably literally be actively hacked running malware, and if you just reboot it, it will flush the malware out of memory. Yeah. So it

Speaker 1: You,

Speaker 2: You know, obviously, if there's a day zero exploit that no one knows about that they can use to keep getting access, that's a bigger deal. But as it stands now, I think one of the best security tips for for iPhone users is, you know, when in doubt, just reboot it once a day.

Speaker 1: Man, four years ago with bangers like that, you probably could have made, like, 400 working for Project RAIN over there. They would have loved to know about that.

Speaker 2: I mean, like, yeah. Hey, guys. Yeah. I'm here. There, I got this tidbit for you. Just reboot your phone or a couple times a day.

Speaker 1: Hot tip. Have you tried unplugging it? Yeah.

Speaker 2: I I can't remember. Like, I maybe re like, I do my reboot my phone every day now.

Speaker 1: Oh, really?

Speaker 2: But most people never do it. Like, I remember before I kinda had ever thought about it or had heard that, I'd I think it you know, it was probably pretty frequent that I would go months and months without rebooting my phone.

Speaker 1: Me as well. So in 2016, when this comes out, Stroud says that, like, the whole team is is very, very excited. Quote, it was like, we have this great new exploit that we just bought. Get us a huge list of targets that have iPhones right now. It was like Christmas, which is cute and insidious at the same time. According to experts, there's only about 10 current countries in the world that really have the capacity to even develop a tool like karma, which means that the UAE government purchased karma from a vendor outside of the country, a kind of conclusion that was confirmed by the operatives who anonymously spoke with Reuters for the piece that a lot of this is based on.

Speaker 2: Let's talk about what something like Karma sells for. Something something that's based on a day zero bug. So Yeah. Essentially an unknown exploit that will probably be patched at some point in the future Totally. But is super valuable right now. Yep. What is like, I did do you know what they paid for it? Do you have any idea of the licensing fee for something like Karma? For Karma?

Speaker 1: No. I don't know what the licensing fee is. And then you add in the extra layer of and you can't sell it openly because then it stops working because they would fix it. So it means that you have this immensely valuable thing that only an incredibly tiny number of buyer and sellers can participate in the market for.

Speaker 2: Totally. And you also don't wanna tell them what it is because then Mhmm. The people who don't buy it will actively try and patch it. So you're literally like throwing out an RFQ being like, hey, We have the ability to hack anybody with, you know, some conditionals, but most of those conditions are met by most people. Yep. What would you pay for this? Question. Please respond with dollar value. Like like like I would love to sit on the, like, procurement committee for that one.

Speaker 1: Yeah. It's especially interesting when you think of it as, like, this weird intelligence economy of the country that developed it, its x employees might work for the company that you hire to teach your people how to do it. Totally. And they can't bring over confidential tools, but that government is trying to sell you one of those confidential tools. It's like, to say the lines are blurry is, like, implies that there are lines. It it's such a crazy gray mess.

Speaker 2: Well, you're also would be, like, standing at the market, like, the market for this tool.

Speaker 1: Mhmm.

Speaker 2: And whoever you sell it to, you're now a national hero that will never be recognized.

Speaker 1: Yeah. Sure.

Speaker 2: But to every other person in the market that didn't buy it, you're now an enemy of the state.

Speaker 1: 100%.

Speaker 2: Just given this tool to the to your essentially opponents. Like, what a weird what a weird economy that's gotta be to hang out in. Mhmm.

Speaker 1: Yeah. The idea of this keeps coming up on this show, but the, like, the marketplaces that emerge around the cybercrime products and services is fascinating to me. The last episode was was about that, and we've done a few. And it it as it gets more and more mature, they start looking much more like really traditional marketplaces, and that's there's just all kinds of things you can infer from that. It's very interesting.

Speaker 2: I, like, I I wanna see the 2020 version of Lord of War. Totally. But instead of it being, like, selling guns and ammo, it being, like, this crazy intelligence community where you're, like, you know, you've got a bunch of, like, hackers that, like, come up with a day zero exploit, and they're, like, okay. We think this one's got, you know, 1,200,000,000, you know, kind of coverage of 1,200,000,000 people. Mhmm. Therefore, it should be worth, you know, at least a 120,000,000 or, like, whatever they value it at, and then you get, like, a Nicolas Cage type that goes out and, like, tries to sell it to, like, weird, esoteric governments, and they're, like, cybercrime divisions. Like, I'm I would I would watch that film or or series, which I would be happy to help, right, if anybody's listening.

Speaker 1: Yeah. If you if you wanna develop that show, we're we're right here. We're just hanging out.

Speaker 2: We're right here. Call me.

Speaker 1: I I wanna see that opening montage of the bullet getting manufactured from, like, raw metal all the way through to final destination, except it's like a zero day exploit, someone discovering all the way to the point where it's like a cyber product being sold from one government to another. Like, I wanna follow that process.

Speaker 2: Yeah. The Lord of War intro is special.

Speaker 1: It's so good. That one shot, oh,

Speaker 2: it's great. Yeah. Yeah. So we've got this Anyway.

Speaker 1: Full of folks hacking. And the legality of this entire option of this whole operation really hinges on those two big questions. Is it legal in the country where it's happening, The UAE? And is it legal in the country where the contractor CyberPoint is based out of The US? And regarding the latter, if you want to provide like very sensitive defense technologies or services like CyberPoint was providing to a foreign government, you need to get a very special license from both the US state and commerce departments. Both of whom declined to comment on the fallout of this whole thing. But, a 2014 State Department agreement with CyberPoint did show that Washington understood that the contractors were helping launch a cyber surveillance operation in The UAE. They understood the basics of what was going on here. The approval document explains that CyberPoint's contract was to work along NESA in the, quote, protection of UAE's severity by, you know, collecting information and all that stuff. One thing that is very clear and is very, very forbidden. Again, just going to say it again, CyberPoint employees were not allowed to target American citizens or companies as part of those terms as part of that agreement. CyberPoint promised that its own staff and even Emirati personnel supporting the program, the the button pusher quote, will not be used to exploit US persons. And I'm gonna keep saying that because it's a pretty big point of how this whole thing falls apart. Because by 2015, stuff starts to get dodgier. Mhmm. And we're gonna get to that right after this break. Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's going to work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started. You can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.

Speaker 3: All new drinks are now at McDonald's. With refreshers like the strawberry watermelon refresher and the mango pineapple refresher with popping boba to crafted sodas, like the Sprite Berry Blast with berry flavors and cold foam. Who knew ice cold drinks could be so fire? Try Try them all

Speaker 1: now at McDonald's. Refreshers contain caffeine. Copyright 2026, The Coca Cola Company. Sprite is a registered trademark of The Coca Cola Company. You get an assignment at work. Pack into individual users of this ISIS internet forum. That's the assignment. So Project Raven's American contractors get called on to make a computer virus that would infect every person who goes to said ISIS website. Makes sense. Except for what's the one rule. You can't hack Americans for a foreign government. And even if there are Americans visiting an ISIS site, they're still Americans. And this tactic kind of risks capturing them in this. And that little tension is the start of this whole thing dissolving. Because Stroud, she finds herself facing this question in 2015, and she cooks up a policy for what they're gonna do for when project Raven inevitably accidentally hacks an American using kind of a big net approach like this. And it's simple. They're just gonna flag that shit for deletion.

Speaker 2: Sure.

Speaker 1: Accidentally capture some American data. Like, the second you know it's American, there's a thing that just deletes it. But as time goes on, Stroud starts to notice that American data flag for removal, the same little bit of data is showing up again somewhere else in Raven's importantly, NISA controlled data storage. So you can write a rule to make sure you're not breaking the law at work, but the people who that law doesn't apply to might not follow the rule. And where exactly does that leave you?

Speaker 2: Sure. They're cleaning out the trash can and pouring it into their filing cabinet.

Speaker 1: So by this point, it's like 2015 or so, Raven has been chugging along for, like, six years. And when it started in 2009, Abu Dhabi had, like, relatively little cyber expertise compared to some other countries. And the original goal of project Raven was for Americans to come in and develop and run this program for, like, maybe five years, a decade until those UAE intelligence officers knew enough to take over. It was never meant to be permanent. And by 2013, the opposite had kind of happened. The Americans at Raven made up the majority of the team. And so it's right around here when Stroud is starting to ask these these questions that The UAE starts to get kind of uncomfortable with that reality, that this increasingly central national security program is being run by foreigners. So they decide this is gonna change. This program, Raven, is gonna be run through one domestic local company. No more external contractors. It's all gonna go through this company called Dark Matter. And the American contractors were given a very simple choice. You can join dark matter or you can go home. And at least eight operatives took the second choice, they left. There's this guy in The UAE called Faisal Albinay. He's an entrepreneur, created one of the, like, big mobile device companies over there called Acxiom. That company does incredibly well.

Speaker 2: Mhmm.

Speaker 1: He decides I'm gonna make a cybersecurity company, and he calls it Dark Matter. Dark Matter pretty quickly gets The UAE Security Forces as a client, and they start recruiting. They employ 650 people. They acknowledge that they work with the government, but they deny that they're hackers. And this is an interesting aside, according to one of the operatives interviewed, that might actually be true. The black purple folder cover thing was so universally and like rigidly maintained in dark matter that the actual purpose of Project Raving even after dark matter absorbed it was kept secret from at least most of their like top level executives according to this operative. But it's when dark matter took over that the assignments from NISA like from the UAE government started to change and escalate. And more and more like physical rooms of the villa where Stroud worked worked started to become what they called Emirates eyes only. Like, whole projects teams that the foreign contractors were never supposed to see. The beginning of this big shift, which, like, like, you know what they're doing in there because otherwise, you would know what they were doing in there. Like, the second they start locking the door, you can kind of intuit, well, they must be breaking one of the two rules I'm not allowed to break.

Speaker 2: Sure.

Speaker 1: Like, do you quit by now? Yeah. Yeah. Okay. Me too.

Speaker 2: Do I quit by now?

Speaker 1: Do I quit by now? I quit six months ago. Yeah. For sure.

Speaker 2: Yeah.

Speaker 1: I never got on the plane to go over there.

Speaker 2: I don't know. That's a that's a like, let's just hang there for a sec because it's like I feel like most people, and, like, I think our audience will probably confirm or deny this, but I think that most people that are interested in cyber crime and maybe this is just me projecting, but it's like it's the puzzle aspect of it, you know. It's the gamesmanship of it.

Speaker 1: Totally.

Speaker 2: And it's like, I I feel like if you're that kind of person, like, I'm that kind of person.

Speaker 1: Right.

Speaker 2: It's like, if somebody was like, hey, do you wanna solve logic problems all day for $500,000 a year? I'd have a hard time not taking that.

Speaker 1: A 100%.

Speaker 2: And it's like and it's like, that's gonna speak to a lot of people. So it's like, you know, it's it's a personality type, and it's a Sure. A person a per like, it speaks to, like, a core, you know, driver for, like, a lot of people that like games and like that kind of aspect of it. And I I don't know. I don't know. Like, I it'd be tough. It'd be tough. It would be Would you take it? If if you walked into the room and and I'd put in those two folders in front of you, would you would you I Like, I think I think me, I think I would have taken it, you know? I think it's tough.

Speaker 1: I But There's a big part of me that Yeah. Would want to. It's an interesting thing, like, there's lines in this and moments in this where it feels so patently unethical. Totally. And then there's other moments where it's so compelling and provocative. And I'm just vacillating back and forth between those two states. And then you add in, like, hundreds of thousands of dollars a year. I don't know where I am.

Speaker 2: But, like, you also need to, like, think about it from the other side where it's like it seems so unethical now Mhmm. Because we're looking back through these, like, binary glasses of being like, oh my god, you know, they were spying on people.

Speaker 1: For sure.

Speaker 2: And it's like, you know, it's super easy to see the ethical jump there. But when you were a former NSA operative who which in a job which all you did was spy on people Mhmm. And then you got hired to go work for another national security agency where all you do is spy on people Yeah. It's like, you know, you you you're so watered down at that point that do you even really notice the difference? For sure. Like, it's like it's there's there's still just people. And, like, I'm looking at, you know, so many people's information already. Like, what is an extra person, and why is it now unethical? Mhmm. You know, I I I feel like I feel like your your morality at that point has been rewritten. Oh. And it's like it'd be it would not it would not feel unethical.

Speaker 1: No. You

Speaker 2: know? It's it's kind of the the whole thing we have with systemic problems in our society now where they've becomes the norm. Mhmm. And, you know, you have to kind of buck the norm to rewrite, you know, the system. And it's like that's probably the same thing that happened to them is, you know, it's become the norm to be unethical. So, like, what you probably don't even notice.

Speaker 1: Totally. One with how blurry the morality gets, it then raises this other interesting question of what finally functions as a tripwire. Like, what Mhmm. What can cut through that pace?

Speaker 2: You reset. Reset.

Speaker 1: Exactly. And that it's been an interesting part of the story since the beginning considering her relationship to Edward Snowden and it becomes a very interesting part of the story again at the end. So at this point though, it's 2016 and some of these American operatives are coming back to The States and they get off the plane in The US and a bunch of FBI agents come up and they have some questions for them. Which is weird Sure. Because as far as they're concerned, NISA, who's giving them their assignments, is supposed to be working with NSA. So their assignments are supposed to be coming in, like, kind of pre t's crossed and i's dotted. Yep. But the FBI rolling in with a bunch of questions would suggest that that's not the case. And the FBI is asking these contractors, hey, guys. Are you spying on Americans? Hey, guys. Did classified US collection techniques end up in the hands of a foreign government because of you? Because those are all crimes. And those are pretty stressful questions. Two of those agents did approach Stroud in 2016 at the at Virginia's Dulles air Dulles? Duels?

Speaker 2: Dulles? I think it's Dulles.

Speaker 1: In Virginia's big airport. Cool. They caught they bump into her in Virginia. She's on her way back to UAE after a trip home. And Stroud, who is just a fun little scene, she said she was afraid she might be under surveillance, which is why she told them, I'm not telling you guys Jack. And then she got on the plane and she went back. But she would. She would go on to tell them Jack. Back at the Villa. Stroud had been starting to get even more access to internal, like, project Raven databases after she got this, like, big promotion the year before. And by this point, it was her job as lead analyst to go looking for user accounts of potential Raven targets and figure out what kind of vulnerabilities they could use to get a foothold into the victims like email or messaging app. And the way that they kept track of all of these targets was by organizing They had sort of like a big spreadsheet that organized people based on different parameters. One of which was the country that they're from. Iranian targets are coated gray and Yemeni targets are in the brown category. And one morning in spring twenty seventeen, after she'd gotten through all of her targets, Stroud said that she began working through a backlog of other assignments intended for NISA officers or like bosses essentially that she had access to because of this promotion. And she noticed that a passport page of an American was in the system. So, Stroud emails her supervisors to complain, and they tell her, oh no. That data was collected by mistake, we're just gonna delete it. She kinda asked questions. And with her new lead analyst position, she actually has the ability to go into some of these lists and documents that she couldn't see before. So she dives into, like, a essentially, a targeting request list that's typically only limited limited to Ray Raven's Emirati staff. And she finds that the security forces, Nissa, had given two other homework assignments. They'd asked for surveillance against two other people, two Americans, which is not the deal. When she takes that up the line, instead of getting a oh no, that's a mistake, we'll remove it, her bosses give her a bunch of help for accessing the list and tell her to just stop. One Emirati officer wrote to her that the target requests that she viewed were to be processed by, quote, certain people, and you are not one of them. And over the days that follow, she keeps going through and she keeps bumping into more Americans on this list actively being targeted. In the short wind of the fall, she founded another three. And in the notes, along with the nationality, there are other things listed, including their occupations, and she saw that they were targeted because they were journalists, which meant that just down the hall from her, here in the villa, that's who they were going after. American journalists that were critical of the UAE government. She said, quote, it kind of hit me that at a macro level, realizing there was a whole category for US persons in this program, I was sick to my stomach. So again, she goes to her manager, Mark Baer, the guy who way back when brought her into Cyberpoint, and he recommends, yeah, you should drop this. But she doesn't, she asks again and again until finally they decide to put her on leave. But getting put on leave from the intelligence agency of a country that you're not from but you are living in where you were working as a spy is not like getting put on leave at most other jobs. Her phone is immediately taken, her passport is taken, and she's rushed out of the building. And she described it kind of ironically as feeling like, quote, one of those national security targets. I'm stuck in the country. I'm being surveyed. I can't leave. Two months later, they finally let her go, and she gets on a plane and she flies home, and on the way she digs out that business card that the FBI agent gave her back at the airport and she makes a call, saying, quote, I'm a spy. I get that. I'm an intelligence officer, but not a bad one, Which, apparently puts the line between a good spy and a bad spy somewhere between targeting a British journalist, but not an American one. So that brings us to 2021. And the only other three names aside from Laurie Stroud that we know in this entire, like, drama. And they are not the names of people who have come forward, but whose names we nonetheless know. Because in September 2021, charges were laid against Mark Baer, the man who invited her, a guy named Ryan Adams, no relation, and a guy named Daniel Gericke, who admitted the three of them to violating US hacking laws against selling sensitive military technology to a foreign government, all as part of a deal to avoid further prosecution. The three men admitted to hacking into computer networks in The United States and exporting sophisticated, cyber intrusion tools without gaining required permission from the US government. As part of the deal with federal authorities to avoid prosecution, the three former intelligence officials agreed to pay a combined 1,690,000 and to never again seek a US security clearance. Laurie, after phishing out that business card, reached out to the FBI to discuss what had happened. She then reached out to journalists and participated in the kind of public expose that formed the foundation for this episode. She decided when she got back to The States that she was gonna blow the whistle. There were three charges laid and a relatively large fine levied. And that's kind of where this story leaves you. And on one hand, it's the story of it's kind of a classic story of a whistleblower. Like, Stroud saw something wrong, and she said something, and stuff occurred.

Speaker 2: I feel like this is one of those weird situations where it's, like, we all know the nations kinda spy on each other, even the friendly ones.

Speaker 1: For sure.

Speaker 2: It's kinda just a thing that they do, and they've been doing it since way before it was cyber spying, and it was, like, just real spying. You know, there's a reason why we have, you know, ambassadors and, you know, intelligence people in other countries and other country well, you know, there's a reason why these agencies exist. And it's like, really at the heart of this story is just the fact that it was contracted Americans Mhmm. Doing it for another nation.

Speaker 1: For sure.

Speaker 2: That that then also happens to be gathering intelligence even though they it wasn't like it would be naive to think I would think my personal opinion is that I think it would be naive to think that because I'm not allowed to spy on Americans Yeah. That other people aren't spying on Americans. Mhmm. And it's like, you know, you're giving me a Lamborghini and I work in a in a, like, a mysterious villa. Villa? Like, it sounds like too it sounds like too much of, like, a like a like a Bond movie

Speaker 1: 100%.

Speaker 2: Already. And it's like, you you I don't know. Like, it to me, it just seems like, yeah. Of course, people are spying on other people. Like, this really the ethical thing here is just the fact that it's like, you know, it just happened to be American contractors that were doing it instead of nations a nation's own people. Right. Or subcontracting it to some big Israeli syndicate or, you know, one of the Italian syndicate or one of the Russian syndicates or one of you know? It's like, it's gonna happen. It just depends on who's doing it, you know?

Speaker 1: Yeah. Like, will The UAE ever hire ex NSA staff who might end up hacking Americans? Probably not. Why would they? They learned everything they, like, got they wanted. Like but that doesn't mean that other countries won't, like, almost certainly. Maybe Americans, like an an accent essay person might think twice about doing it, which says nothing about all of the other countries that are just as sophisticated who could then go work for someone else after they're done working for CSIS or whoever. Like, there's a market for people that know how to hack for governments.

Speaker 2: Yeah.

Speaker 1: And it's an international market made of spies, and that's gonna be really hard to regulate.

Speaker 2: Well, totally. It's like you train the it's like when you think of you know, they train military soldiers, and lots of them go on to do security forces afterwards. And those security forces get similar contracts for other nation states or the same nation states or major pipeline companies in foreign countries, etcetera, etcetera, etcetera. And it's like, a government spent a bunch of money turning these people into tools. Other people are gonna wanna use those tools. And and those people are gonna wanna use themselves as tools because it's what they do to earn a living and support their families. Mhmm. And and it's like, I don't know. It's just the world we live in at this point.

Speaker 1: And it's like that's that is why Stroud did it. It was a job. It was a career move.

Speaker 2: Totally. You go from a government government salary to tax free in The UAE at a half 1,000,000, you know, working in a fancy villa, living in probably paid accommodations and housing, like, you know, sounds pretty

Speaker 1: Pretty sure.

Speaker 2: If that's what you're into.

Speaker 1: It's a pretty sick deal, And it and it invites all these really fascinating questions about whistleblowing as a general concept.

Speaker 2: Mhmm.

Speaker 1: Like, whether Stroud saw something wrong or whether she saw something that was gonna get her in trouble is a very interesting question. And the probable answer is that it's a bit of both. Like, that maybe after being the person to let Snowden into the NSA, a guy who would go on to have a crisis of faith and do something drastic, Like, the optimistic version is, like, maybe she did find herself in a a similar situation. Maybe she saw that in herself. And seeing that one person blow a whistle making you wanna do the same thing. And, like, maybe that's the whole point of it. I don't know. It's interesting. So now that you know what's in that black folder, you get pulled in that room. Do you show up for work the next day?

Speaker 2: I don't know. Tough, tough one.

Speaker 1: Thanks for listening everybody, but a special thanks. And I and I do mean this because if you made it if you made it this far and you're a new Patreon patron, it's a very special thanks to Alexander Gendron, Jacob Boy Hansen, Brian Martin, Laurent Schupbeck, and Jay Freak. You're all you're all freaky in my books. You're our new Patreon patrons, and your support means a lot. That might be the most new patrons in one month ever. I'm just saying. Get on board. It's a movement. Thank you so much. It's the best way to support the show patreon.com/hackedpodcast. Thank you so much for listening. If you're interested in this story, the Reuters piece by Christopher Bing and Joel Schechtman on which it is based is and I mean this some of the coolest journalism I've read in a very long time. I highly recommend it. Thank you again for listening. We'll catch you on the next

Speaker 2: one.

Speaker 4: Visible puts the ultimate wireless hack in the palm of your hand. You get unlimited five gs data and hotspot designed to keep you connected. All powered by Verizon's five gs network. Plans start at $25 a month or get the premium Visible plus pro plan and save $10 on your first month with promo code hack. Tap the banner to switch today. Terms apply. See visible.com for plan features and network management details.

Speaker 5: Have no fear. Chosen Foods is here to defend your favorite foods from the forces of seedy oils and sketchy ingredients. With cooking oils, salad dressings, and mayo, all powered by the good fats from 100% pure avocado oil and simple delicious ingredients. Chosen Foods.

Speaker 6: Every week, the Snap Judgment podcast drops you inside someone's biggest decision. The kind of decision you can only make once. With everything on the line, what do you believe? What do you want? And what would you risk to get it? Find out. Tap to listen now to Snap Judgment from KQED on Spotify.