//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF

Current as of 1238 EDT (UTC-04), Friday 20 March 2026

Contents

24 stories from 0 sources across 0 organizations


Leadership & Organization

Gabbard Distances Herself from Kent and Caldwell as Iran War Fractures ODNI

Director of National Intelligence (DNI) Gabbard publicly stated she 'checks her personal views at the door' in an effort to separate herself from aides Joe Kent and Dan Caldwell, both vocal critics of the Iran war. Kent resigned as National Counterterrorism Center (NCTC) director and is now under FBI leak investigation; Caldwell was hired at Office of the Director of National Intelligence (ODNI) after being cleared in a Pentagon leak probe. The distancing signals internal ODNI fractures over Iran policy are reaching the DNI's immediate staff.

Patel Tells HPSCI Fired FBI Agents Violated Ethics Rules, Declines to Specify

FBI Director Patel testified before House Permanent Select Committee on Intelligence (HPSCI) that agents fired from Counterintelligence (CI)-12 were dismissed for ethics violations, but declined to specify the violations citing pending litigation. Reps. Magaziner and Thompson pressed Patel on whether the firings degraded Iran expertise during active conflict. Patel acknowledged he knew about the administration's Iran strike plans more than a month before the CI-12 firings.

Two Fired FBI Agents Sue Patel, Bondi for Political Retribution Over Trump Investigations

Two former FBI agents filed suit claiming they were fired without investigation, notice, or hearing for their roles in the Arctic Frost election investigation. The agents allege Patel summarily terminated them as political retribution for disloyalty to Trump. The lawsuit names Patel, AG Bondi, the FBI, and DOJ, seeking reinstatement and a finding that their First and Fifth Amendment rights were violated.

CIA Recruitment Videos Targeting Chinese Military Hit 120 Million Views

CIA's Mandarin-language recruitment campaign targeting disillusioned PLA officers has accumulated 120 million YouTube views. A CIA official confirmed the videos have successfully generated new intelligence sources inside China. The latest video includes operational security guidance and instructions for secure contact. China described the campaign as 'a serious infringement' and pledged countermeasures.

Bennet at SSCI: 'The War Is Escalating, Not Ending' as IC Leaders Dodge Imminent Threat Question

Sen. Bennet used his Senate Select Committee on Intelligence (SSCI) questioning time to document the administration's shifting war objectives, noting Iran 'still has a uranium stockpile' despite claims of total program destruction. Bennet pressed IC leaders on whether any agency produced an imminent threat assessment prior to Operation Epic Fury. Neither Gabbard nor Ratcliffe confirmed such an assessment exists, reinforcing the gap between the administration's legal justification and the intelligence record.

Operations & Intelligence Failures

DOJ Seizes Four Domains Linked to Iran's MOIS Psychological Operations Campaign

The Justice Department seized four domains operated by actors tied to Iran's Ministry of Intelligence and Security (Iran) (MOIS), used for psychological operations including false claims of cyberattacks, leaking stolen data, and issuing death threats against journalists, dissidents, and Israelis. The operation directly responded to the Handala group's destructive wiper attack on medical device maker Stryker, which exploited compromised Microsoft Intune credentials.

Analyst Note: Prior IC brief covered this URL. Including for continuity: FBI domain seizure operationalizes the MOIS attribution from the Stryker attack, converting a defensive cyber incident into an offensive counterintelligence action.

Supermicro Co-Founder Arrested in $2.5 Billion AI Chip Smuggling Scheme to China

FBI's Counterintelligence and Espionage Division led the investigation into Supermicro co-founder Wally Liaw and two associates who allegedly diverted $2.5 billion in Nvidia GPU servers to China via a Southeast Asian pass-through company. Workers used hair dryers to swap labels between real and dummy servers to deceive compliance auditors. $510 million in servers were diverted in a single six-week period. The case signals escalating CI enforcement on AI technology transfer.

Analyst Note: This is the largest AI export control prosecution to date. The FBI CI division lead -- rather than BIS or DOJ NSD -- suggests the government views this as an espionage-adjacent case, not merely a trade compliance matter.

Comey Subpoenaed in 'Grand Conspiracy' Case; 130+ Subpoenas Now Issued

Federal prosecutors subpoenaed former FBI Director Comey regarding the 2017 Intelligence Community Assessment (ICA) on Russian election interference. The Miami-based probe under Judge Cannon has now issued 130+ subpoenas targeting Obama-era IC officials including Brennan, Strzok, Page, and McCabe. McCabe's lawyer called it 'a vendetta in search of a crime.' Combined with Ratcliffe's CIA Tradecraft Review referring Comey and Brennan for prosecution, this represents the broadest criminal investigation of former IC leadership in history.

CISA/FBI Issue Urgent Advisory on Microsoft Intune Exploitation After Stryker Wiper Attack

Cybersecurity and Infrastructure Security Agency (CISA) and FBI issued a joint advisory warning organizations to secure Microsoft Intune management systems after the Handala group's wiper attack on Stryker exploited compromised Intune administrator credentials. The attack vector -- using device management tools to mass-wipe endpoint devices -- represents a novel threat model that bypasses traditional network perimeter defenses. CISA is operating at approximately 38% staffing capacity during the response.

NGA Awards BlackSky AI-Enabled Satellite Monitoring Contract Amid Iran BDA Demands

National Geospatial-Intelligence Agency (NGA) renewed its contract with BlackSky Technology for AI-enabled global facility monitoring under the Luno A program. The contract extension comes as NGA faces unprecedented Battle Damage Assessment (BDA) demands from the Iran conflict, where traditional imagery analysis methods are being strained by the volume and pace of strike operations. BlackSky's AI-driven change detection capabilities address the agency's need for rapid automated damage assessment at scale.

Congressional Oversight & Policy

Three Competing FISA 702 Vehicles With 31 Days to Expiration and No Clear Path

Brookings analysis identifies three competing legislative vehicles for Section 702 reauthorization before the April 20 sunset: Cotton's 18-month clean extension, the bipartisan Security and Freedom Enhancement Act (SAFE Act) (Lee-Durbin) requiring partial warrant requirements, and Wyden's Government Surveillance Reform Act banning warrantless data broker purchases. Republicans control all three chambers but the administration's position remains unstated, and the Iran war has scrambled traditional surveillance hawk/dove alignments.

Jayapal: Clean 702 Reauthorization Would Give Stephen Miller a 'Blank Check' for Domestic Surveillance

Rep. Jayapal issued a statement opposing clean 702 reauthorization, citing the FBI's documented non-compliance with querying rules discovered by DOJ's National Security Division in 2024. She specifically tied the Anthropic supply chain risk designation to the surveillance debate, noting the company was 'blacklisted for refusing mass surveillance use of its technology.' The October 2025 IG report found it could not confirm FBI querying compliance issues are 'entirely in the past.'

House Republicans Warm to 702 Renewal Despite Weaponization Fears

House Republicans who previously opposed 702 over FBI weaponization concerns are shifting toward renewal as the Iran war elevates national security arguments. The HPSCI hearing's emphasis on 702's role in Iran intelligence collection appears to have moved skeptics. The Iran conflict creates political cover for members who opposed renewal in 2024 on civil liberties grounds to reverse position without appearing to contradict their prior stance.

IC Whistleblower Complaint Reaches Congress with Executive Privilege Redactions

The IC whistleblower complaint alleging political interference with intelligence reporting finally reached Congress after an eight-month delay, but with significant portions redacted under executive privilege claims. ICIG Christopher Fox hand-carried the complaint to Capitol Hill on February 3. The redactions conceal names and details related to an intercepted communication between a foreign intelligence agent and a Trump associate that DNI Gabbard allegedly suppressed.

Wyden-Lee Introduce Government Surveillance Reform Act: Warrant Requirements and Data Broker Ban

A bipartisan coalition (Wyden, Lee, Davidson, Lofgren) introduced the Government Surveillance Reform Act requiring warrants before accessing Americans' 702-collected communications and banning warrantless government purchase of data broker records. The bill also repeals the 2024 Reforming Intelligence and Securing America Act (RISAA) expansion that broadened the definition of electronic communications service providers. This is the third major 702 vehicle alongside Cotton's clean extension and the Lee-Durbin SAFE Act.

Technology & OSINT

Anthropic Meets House Homeland Security Behind Closed Doors as Supply Chain Phase-Out Begins

Anthropic co-founder Jack Clark briefed bipartisan House Homeland Security Committee members in a closed session focused on model distillation risks and export controls, barely touching the company's ongoing lawsuit over its Pentagon supply chain risk designation. The session is part of a series the committee is convening on Department of Homeland Security (DHS) technology acquisition. Anthropic is simultaneously suing the government while opening a parallel congressional track to contest the designation.

Analyst Note: Prior IC brief noted the Mayer Brown legal analysis of the supply chain designation's effective date. This closed-door briefing signals Anthropic is pursuing a legislative override strategy alongside its judicial challenge.

Anthropic Supply Chain Risk Designation Takes Effect; Six-Month Federal Phase-Out Underway

The Pentagon's supply chain risk designation for Anthropic formally took effect this week, triggering a six-month phase-out period during which all federal agencies and defense contractors must certify they do not use Anthropic's Claude models. The designation -- the first ever applied to an American AI company -- stems from Anthropic's refusal to waive contractual restrictions on mass domestic surveillance and autonomous weapons. Defense contractors face compliance deadlines by September 2026.

CISA Issues Intune Security Advisory After Iran-Linked Wiper Attack Exploits Device Management

CISA and FBI jointly warned organizations about vulnerabilities in Microsoft Intune device management after the Handala group weaponized compromised Intune credentials to execute a mass wiper attack on Stryker's global network. The advisory details how infostealer malware harvested Intune admin credentials, enabling remote factory resets across the company's device fleet. The attack model -- targeting centralized device management rather than individual endpoints -- is novel for Iranian threat actors.

Pentagon Classified AI Training Enclaves Expanding Despite Anthropic Ban

The Pentagon is expanding classified AI training enclaves across IC agencies even as the Anthropic ban forces a rapid migration away from Claude-based systems. Multiple agencies had integrated Claude into classified workflows under the July 2025 contract, and the six-month phase-out is creating operational disruption. OpenAI and Palantir are positioned as primary replacements, though neither has completed the full security accreditation process that Anthropic had already cleared.

Unit 42: Iranian Cyber Threat Actors Expanding Beyond Espionage to Destructive Operations

Unit 42's threat brief documents Iranian cyber actors' shift from espionage-focused operations to destructive attacks targeting critical infrastructure and defense industrial base entities. The analysis notes increased use of wiper malware, supply chain compromises, and credential harvesting via infostealers -- the same TTP used in the Stryker/Handala attack. The brief assesses Iranian cyber capacity as a persistent compensatory tool for degraded conventional military capability.

Hiring & Workforce

Cleared Workforce Hits 5.5 Million Eligible but Active Clearance Holders Flat at 2.3 Million

The eligible cleared population reached 5.5 million, up 900,000 since FY2021, but those actively occupying cleared positions has remained flat at 2.2-2.4 million. Over 3 million people hold clearance eligibility without current access -- a growing shadow workforce of cleared personnel not in cleared roles. For IC applicants, this means competition for cleared positions is intensifying even as the eligible pool expands.

DCSA Investigation Backlog Drops to 100,000; Continuous Vetting Covers 3.8 Million

Defense Counterintelligence and Security Agency (DCSA) reduced its investigation backlog to approximately 100,000 cases in January 2026, a 65% reduction from the start of 2025. Processing targets are now 40 days for Secret, 75 days for Top Secret, and 25 days for public trust positions. Over 3.8 million cleared personnel are enrolled in continuous vetting, slashing periodic reinvestigation timelines. The Trusted Workforce 2.0 'clear once, trusted everywhere' initiative is nearing full implementation.

CISA Loses Cybersecurity Division Leader; Agency at One-Third Staffing

Shelly Hartsook, acting associate director of CISA's cybersecurity division who oversaw the Continuous Diagnostics and Mitigation (CDM) program, resigned effective March 6. Her departure follows the reassignment of CISA's acting director, and the exits of the CIO, CHCO, and threat hunting chief. CISA has lost approximately one-third of its workforce since January 2025 and operates without Senate-confirmed leadership. The agency is responding to the Stryker/Handala incident at severely degraded capacity.

Post-RIF Agencies Turning to AI and Targeted Hiring to Fill Gaps

Federal agencies including IC elements are deploying AI tools and targeted hiring authorities to compensate for workforce reductions. The shift reflects a tacit acknowledgment that Reduction in Force (RIF)-driven headcount cuts have created capability gaps that cannot be absorbed through redistribution alone. Agencies are prioritizing cyber, intelligence analysis, and STEM positions in remaining hiring slots, but the security clearance requirement remains a bottleneck for rapid backfill.

UNCLASSIFIED // OPEN SOURCE