IC BRIEF
Current as of 1238 EDT (UTC-04), Friday 20 March 2026
Contents
- Leadership & Organization (5)
- Operations & Intelligence Failures (5)
- Congressional Oversight & Policy (5)
- Technology & OSINT (5)
- Hiring & Workforce (4)
24 stories from 0 sources across 0 organizations
Leadership & Organization
Gabbard Distances Herself from Kent and Caldwell as Iran War Fractures ODNI
Director of National Intelligence (DNI) Gabbard publicly stated she 'checks her personal views at the door' in an effort to separate herself from aides
Patel Tells HPSCI Fired FBI Agents Violated Ethics Rules, Declines to Specify
FBI Director Patel testified before House Permanent Select Committee on Intelligence (HPSCI) that agents fired from Counterintelligence (CI)-12 were dismissed for ethics violations, but declined to specify the violations citing pending litigation. Reps. Magaziner and Thompson pressed Patel on whether the firings degraded Iran expertise during active conflict. Patel acknowledged he knew about the administration's Iran strike plans more than a month before the
Two Fired FBI Agents Sue Patel, Bondi for Political Retribution Over Trump Investigations
Two former FBI agents filed suit claiming they were fired without investigation, notice, or hearing for their roles in the
CIA Recruitment Videos Targeting Chinese Military Hit 120 Million Views
CIA's Mandarin-language recruitment campaign targeting disillusioned PLA officers has accumulated 120 million YouTube views. A CIA official confirmed the videos have successfully generated new intelligence sources inside China. The latest video includes operational security guidance and instructions for secure contact. China described the campaign as 'a serious infringement' and pledged countermeasures.
Bennet at SSCI: 'The War Is Escalating, Not Ending' as IC Leaders Dodge Imminent Threat Question
Sen. Bennet used his Senate Select Committee on Intelligence (SSCI) questioning time to document the administration's shifting war objectives, noting Iran 'still has a uranium stockpile' despite claims of total program destruction. Bennet pressed IC leaders on whether any agency produced an imminent threat assessment prior to
Operations & Intelligence Failures
DOJ Seizes Four Domains Linked to Iran's MOIS Psychological Operations Campaign
The Justice Department seized four domains operated by actors tied to Iran's Ministry of Intelligence and Security (Iran) (MOIS), used for psychological operations including false claims of cyberattacks, leaking stolen data, and issuing death threats against journalists, dissidents, and Israelis. The operation directly responded to the
Analyst Note: Prior IC brief covered this URL. Including for continuity: FBI domain seizure operationalizes the MOIS attribution from the Stryker attack, converting a defensive cyber incident into an offensive counterintelligence action.
Supermicro Co-Founder Arrested in $2.5 Billion AI Chip Smuggling Scheme to China
FBI's Counterintelligence and Espionage Division led the investigation into Supermicro co-founder Wally Liaw and two associates who allegedly diverted $2.5 billion in Nvidia GPU servers to China via a Southeast Asian pass-through company. Workers used hair dryers to swap labels between real and dummy servers to deceive compliance auditors. $510 million in servers were diverted in a single six-week period. The case signals escalating CI enforcement on AI technology transfer.
Analyst Note: This is the largest AI export control prosecution to date. The FBI CI division lead -- rather than BIS or DOJ NSD -- suggests the government views this as an espionage-adjacent case, not merely a trade compliance matter.
Comey Subpoenaed in 'Grand Conspiracy' Case; 130+ Subpoenas Now Issued
Federal prosecutors subpoenaed former FBI Director Comey regarding the 2017 Intelligence Community Assessment (ICA) on Russian election interference. The Miami-based probe under Judge Cannon has now issued 130+ subpoenas targeting Obama-era IC officials including Brennan, Strzok, Page, and McCabe. McCabe's lawyer called it 'a vendetta in search of a crime.' Combined with Ratcliffe's CIA
CISA/FBI Issue Urgent Advisory on Microsoft Intune Exploitation After Stryker Wiper Attack
Cybersecurity and Infrastructure Security Agency (CISA) and FBI issued a joint advisory warning organizations to secure Microsoft Intune management systems after the
NGA Awards BlackSky AI-Enabled Satellite Monitoring Contract Amid Iran BDA Demands
National Geospatial-Intelligence Agency (NGA) renewed its contract with BlackSky Technology for AI-enabled global facility monitoring under the Luno A program. The contract extension comes as NGA faces unprecedented Battle Damage Assessment (BDA) demands from the Iran conflict, where traditional imagery analysis methods are being strained by the volume and pace of strike operations. BlackSky's AI-driven change detection capabilities address the agency's need for rapid automated damage assessment at scale.
Congressional Oversight & Policy
Three Competing FISA 702 Vehicles With 31 Days to Expiration and No Clear Path
Brookings analysis identifies three competing legislative vehicles for
Jayapal: Clean 702 Reauthorization Would Give Stephen Miller a 'Blank Check' for Domestic Surveillance
Rep. Jayapal issued a statement opposing clean 702 reauthorization, citing the FBI's documented non-compliance with querying rules discovered by DOJ's National Security Division in 2024. She specifically tied the Anthropic
House Republicans Warm to 702 Renewal Despite Weaponization Fears
House Republicans who previously opposed 702 over FBI weaponization concerns are shifting toward renewal as the Iran war elevates national security arguments. The HPSCI hearing's emphasis on 702's role in Iran intelligence collection appears to have moved skeptics. The Iran conflict creates political cover for members who opposed renewal in 2024 on civil liberties grounds to reverse position without appearing to contradict their prior stance.
IC Whistleblower Complaint Reaches Congress with Executive Privilege Redactions
The IC whistleblower complaint alleging political interference with intelligence reporting finally reached Congress after an eight-month delay, but with significant portions redacted under executive privilege claims. ICIG Christopher Fox hand-carried the complaint to Capitol Hill on February 3. The redactions conceal names and details related to an intercepted communication between a foreign intelligence agent and a Trump associate that DNI Gabbard allegedly suppressed.
Wyden-Lee Introduce Government Surveillance Reform Act: Warrant Requirements and Data Broker Ban
A bipartisan coalition (Wyden, Lee, Davidson, Lofgren) introduced the Government Surveillance Reform Act requiring warrants before accessing Americans' 702-collected communications and banning warrantless government purchase of data broker records. The bill also repeals the 2024 Reforming Intelligence and Securing America Act (RISAA) expansion that broadened the definition of electronic communications service providers. This is the third major 702 vehicle alongside Cotton's clean extension and the Lee-Durbin SAFE Act.
Technology & OSINT
Anthropic Meets House Homeland Security Behind Closed Doors as Supply Chain Phase-Out Begins
Anthropic co-founder Jack Clark briefed bipartisan House Homeland Security Committee members in a closed session focused on model distillation risks and export controls, barely touching the company's ongoing lawsuit over its Pentagon supply chain risk designation. The session is part of a series the committee is convening on Department of Homeland Security (DHS) technology acquisition. Anthropic is simultaneously suing the government while opening a parallel congressional track to contest the designation.
Analyst Note: Prior IC brief noted the Mayer Brown legal analysis of the supply chain designation's effective date. This closed-door briefing signals Anthropic is pursuing a legislative override strategy alongside its judicial challenge.
Anthropic Supply Chain Risk Designation Takes Effect; Six-Month Federal Phase-Out Underway
The Pentagon's supply chain risk designation for Anthropic formally took effect this week, triggering a six-month phase-out period during which all federal agencies and defense contractors must certify they do not use Anthropic's Claude models. The designation -- the first ever applied to an American AI company -- stems from Anthropic's refusal to waive contractual restrictions on mass domestic surveillance and autonomous weapons. Defense contractors face compliance deadlines by September 2026.
CISA Issues Intune Security Advisory After Iran-Linked Wiper Attack Exploits Device Management
CISA and FBI jointly warned organizations about vulnerabilities in Microsoft Intune device management after the Handala group weaponized compromised Intune credentials to execute a mass wiper attack on Stryker's global network. The advisory details how infostealer malware harvested Intune admin credentials, enabling remote factory resets across the company's device fleet. The attack model -- targeting centralized device management rather than individual endpoints -- is novel for Iranian threat actors.
Pentagon Classified AI Training Enclaves Expanding Despite Anthropic Ban
The Pentagon is expanding classified AI training enclaves across IC agencies even as the Anthropic ban forces a rapid migration away from Claude-based systems. Multiple agencies had integrated Claude into classified workflows under the July 2025 contract, and the six-month phase-out is creating operational disruption. OpenAI and Palantir are positioned as primary replacements, though neither has completed the full security accreditation process that Anthropic had already cleared.
Unit 42: Iranian Cyber Threat Actors Expanding Beyond Espionage to Destructive Operations
Hiring & Workforce
Cleared Workforce Hits 5.5 Million Eligible but Active Clearance Holders Flat at 2.3 Million
The eligible cleared population reached 5.5 million, up 900,000 since FY2021, but those actively occupying cleared positions has remained flat at 2.2-2.4 million. Over 3 million people hold clearance eligibility without current access -- a growing shadow workforce of cleared personnel not in cleared roles. For IC applicants, this means competition for cleared positions is intensifying even as the eligible pool expands.
DCSA Investigation Backlog Drops to 100,000; Continuous Vetting Covers 3.8 Million
Defense Counterintelligence and Security Agency (DCSA) reduced its investigation backlog to approximately 100,000 cases in January 2026, a 65% reduction from the start of 2025. Processing targets are now 40 days for Secret, 75 days for Top Secret, and 25 days for public trust positions. Over 3.8 million cleared personnel are enrolled in continuous vetting, slashing periodic reinvestigation timelines. The Trusted Workforce 2.0 'clear once, trusted everywhere' initiative is nearing full implementation.
CISA Loses Cybersecurity Division Leader; Agency at One-Third Staffing
Shelly Hartsook, acting associate director of CISA's cybersecurity division who oversaw the Continuous Diagnostics and Mitigation (CDM) program, resigned effective March 6. Her departure follows the reassignment of CISA's acting director, and the exits of the CIO, CHCO, and threat hunting chief. CISA has lost approximately one-third of its workforce since January 2025 and operates without Senate-confirmed leadership. The agency is responding to the Stryker/Handala incident at severely degraded capacity.
Post-RIF Agencies Turning to AI and Targeted Hiring to Fill Gaps
Federal agencies including IC elements are deploying AI tools and targeted hiring authorities to compensate for workforce reductions. The shift reflects a tacit acknowledgment that Reduction in Force (RIF)-driven headcount cuts have created capability gaps that cannot be absorbed through redistribution alone. Agencies are prioritizing cyber, intelligence analysis, and STEM positions in remaining hiring slots, but the security clearance requirement remains a bottleneck for rapid backfill.