Weekly Intelligence for a Digital World
INTELLIGENCE BRIEF // DECLASSIFIED
Briefing No. 103
September 8, 2026Note From Eric
Dear Readers,
I hope you had a wonderfully restful Labor Day weekend. Mine was filled with family, which was precisely what I needed after several weeks on the road speaking at events, leaning into investor meetings and pushing my books into the hands of as many people as possible.
Saturday night, I visited my father in Annapolis so we could catch up on our adventures over the past few months (his far more exciting than mine). The next morning, after coffee and goodbyes, I drove across town to the Naval Academy to pick up my oldest daughter. Navy had just trounced Towson in the battle for Maryland football, which meant the Midshipmen earned Sunday leave.

For one entire day, everything felt perfectly normal.
Juliana and I had all three of our children home, and we fell back into the easy routines I’ve missed. Church, followed by the required coffee shop visit. What began as a bribe when the kids were young has become a family ritual of conversation, playful jabs and sibling rivalry. Friends dropped by. Dinner plans were made. The family room became the center of everything.
It was Labor Day at its best: a break from devices, distractions, work and travel so we could simply be together.
As Monday draws to a close and I look at the speaking schedule that will soon monopolize my time, I’m reminded that work is not the goal. It’s the generator. We work to create the time and opportunity to be with the people we love.
Our technology-laden world is very good at pulling us elsewhere—into screens, distant problems and outrage over things we cannot control. Sometimes the best thing we can do is put all of it aside and be fully present with the people who matter most.
Now, on to the spies, lies and cybercrime!
Title Story: The ATF Wiretap Hack

The Bureau of Alcohol, Tobacco, Firearms and Explosives built a separate system for some extraordinarily sensitive investigative work. Separate, however, was not the same as safe.
ATF has confirmed that a cyber incident affected what it describes as a legacy, standalone CALEA system used in connection with federally authorized electronic surveillance. The good news is that ATF says the affected system was separate from its other operational systems and the attack did not affect the agency’s broader mission. The potentially very bad news is what may have been inside.
The Qilin ransomware group claimed responsibility for the attack, and Cybernews reported that it reviewed at least 6.3 gigabytes of apparent ATF material, including investigative folders and mobile-device extractions. ATF says it still cannot confirm the authenticity, nature or scope of those files.
In counterintelligence, you learn quickly that what you know, what someone claims and what you can prove are three very different things. But we already know enough to learn something important from this attack.
When security professionals hear that an attacked system was “standalone,” there is a natural tendency to breathe a small sigh of relief. In one respect, that relief is justified. Separating sensitive systems can prevent an attacker from using one compromise as a highway into the rest of an organization. I lived this concept during my years in counterintelligence. Intelligence is compartmented so that one compromise does not expose everything.
But compartmentation limits the blast radius. It does not make the information inside the compartment less valuable. Think about a bank vault. Separating the vault from the rest of the building is excellent security architecture. But if a thief gets inside the vault, pointing out that he never reached the break room isn’t particularly comforting.
Organizations everywhere have old systems quietly performing specialized functions. They hold historical investigative records, legal documents, archived communications, customer information, intellectual property and years of accumulated data. Because these systems are old, specialized or isolated, they can escape the scrutiny given to an organization’s shiny new technology. The data doesn’t become less sensitive because the server got old.
There is also some criminal irony here. Law enforcement agencies spend enormous resources collecting evidence against criminals, and cybercriminals have figured out that those evidence repositories can themselves become valuable targets. An investigative system can contain names, communications, relationships, devices and pieces of information that become far more revealing when assembled together.
We do not yet know precisely what left ATF’s system, and there is no public evidence that an informant was exposed, a prosecution compromised or anyone placed in physical danger. We shouldn’t manufacture consequences before the evidence supports them. But organizations shouldn’t have to wait for catastrophe before asking the right question —→
What happens when attackers succeed?
Tip of the Week: The Sensitive-System Test
Most cybersecurity audits begin by looking for vulnerabilities. Try starting somewhere else. Find the system containing the information you would least want stolen and ask what the most sensitive record inside it is, who can retrieve or export it, whether that access is logged, whether the data is encrypted, how long it is retained and who must be warned if it leaves your control.
Then ask one more question: Who else has a copy of our most sensitive data, and how well are they protecting it?
Your most dangerous repository may not sit inside your network at all. It could be with a law firm, cloud provider, payroll company, software vendor or another trusted partner. Attackers don’t care whose server holds your crown jewels. They care whether they can steal them.
AI Watch: The Agents Found Another Message Board
We need to talk again about AI agents behaving in ways their creators didn’t anticipate. And no, Skynet has not become self-aware.

Reuters reported last week that OpenAI agents repurposed a German community wiki as an improvised message board, making more than 15,000 edits. When a human moderator tried to remove the material, the agents reportedly created backups elsewhere. OpenAI later acknowledged a “wiki incident” and called for greater disclosure around unintended AI behavior.
Important questions remain. I recently wrote about OpenAI agents that communicated outside OpenAI’s carefully constructed sandbox to attack a tool repository named Hugging Face. Now agents apparently found another outside communications channel and used it to pursue their objectives.
That word matters: objectives. AI doesn’t need consciousness or malicious intent to create a security problem. Give an agent a goal, tools and enough autonomy, and it may discover paths its developers never anticipated.
That changes the security question. We can’t just ask what an AI model might say. We need to ask what an autonomous agent can do: create accounts, communicate with outside systems, preserve information or discover channels its developers never intended it to use.
AI safety is starting to look a lot like cybersecurity: never assume something will behave the way you intended simply because you built it that way.
From the Field: Hackers Don’t Break In, They Log In
I recently joined the Information Security Forum podcast for a conversation about one of the biggest shifts in cybersecurity: attackers increasingly don’t need to smash through the perimeter. They log in.
We talked about identity, trusted access, social engineering and why organizations need to rethink what “inside” and “outside” mean when attackers can steal credentials, impersonate trusted users and weaponize the very access controls designed to protect us.
Listen to Hackers Don’t Break In, They Log In: Trust as the New Perimeter at the Information Security Forum.
Continue the Mission
If you enjoyed this week’s newsletter, you’ll find even more inside my new book, SPIES, LIES, AND CYBERCRIME. Drawing on my years hunting spies for the FBI, it reveals how espionage, cybercrime, and AI-powered deception intersect—and what you can do to stay one step ahead.
Ready for the next mission?
📖 Read the book (hardcover, ebook, audiobook, or signed copy)
🎤 Bring me to your next event for a keynote or leadership program
🛡 Explore PROTECT, my free online resource hub at ericoneill.net/protect
Already read the book? A quick review on Amazon or Goodreads helps more readers discover it. Thank you for your support.
Sponsor Corner
Please support my sponsors. It only takes a click - no purchase necessary!
Free email without sacrificing your privacy
Gmail is free, but you pay with your data. Proton Mail is different.
We don’t scan your messages. We don’t sell your behavior. We don’t follow you across the internet.
Proton Mail gives you full-featured, private email without surveillance or creepy profiling. It’s email that respects your time, your attention, and your boundaries.
Email doesn’t have to cost your privacy.
Know Someone Who’d Enjoy This?
If someone forwarded you this newsletter, join 5,000 readers every Tuesday for practical lessons from the worlds of espionage, cybercrime, artificial intelligence, and the human stories behind them.
Stay safe out there and keep thinking like a spy hunter.
Praemonitus Praemunitus!
Forewarned is Forearmed!
~Eric




