← Back to Archive
IC BRIEF
Current as of 0425 EDT (UTC-04), Saturday 23 May 2026
Contents
8 stories from 26 sources across 23 organizations
KEY JUDGMENTS
Acting Director of National Intelligence (DNI) Lukas will oversee Office of the Director of National Intelligence (ODNI)'s most significant leadership restructuring in years, contend with expanding adversary collection in the Western Hemisphere, and navigate an unresolved Iran assessment dispute with the White House, all without the institutional authority of Senate confirmation. Whether a permanent, Senate-confirmed director will be in office before year-end is genuinely uncertain. Moderate confidence reflects a viable party-line confirmation path counterbalanced by the absence of a named nominee.
The FY2027 Intelligence Authorization Act, likely to pass the Senate by year-end, restructures ODNI by collapsing the principal deputy role and creating two Assistant Director positions. Russia and China have nearly tripled espionage personnel in Cuba since 2023, investing in SIGINT facilities that monitor two Florida military headquarters; Cuba is very unlikely to reduce this infrastructure within 12 months absent inducements the administration has not offered.
The IC publicly revising its standing Iran nuclear assessment to align with presidential claims is unlikely within the 2026 calendar year, preserving a credibility check on escalation justifications. If Lukas adopts presidential framing on Iran's nuclear program in his first congressional testimony, the institutional assessment firewall may be eroding.
IC Workforce & Leadership
Trump Names Former CIA Chief of Station Aaron Lukas as Acting DNI After Gabbard Departure
BLUF: Gabbard's exit leaves an acting DNI managing the Iran assessment dispute, and Trump will likely name a permanent nominee before January 2027, though Senate Democratic resistance could stretch the interim arrangement into late 2026.
Gabbard announced on May 22 that she is resigning as Director of National Intelligence effective June 30, citing her husband Abraham's diagnosis with a rare bone cancer 12. A Reuters report cited by SpyTalk said she was forced out, diverging from the stated reason 3. Trump announced on Truth Social that Principal Deputy DNI Aaron Lukas will serve as acting director 124; Lukas is a former CIA chief of station with over two decades in the intelligence community, confirmed by the Senate 51-46 in July 2025 4. NPR reported that in March, Gabbard told Congress the intelligence community did not believe Iran was building a nuclear weapon, a position Trump publicly contradicted, saying "She's wrong" 1.
Analyst Note: Four independent outlets corroborate that Gabbard's departure removes the IC's most senior official as Iran nuclear assessments have become a public rupture with the White House. Lukas faces pressure to reconcile official IC judgments with presidential claims, carrying less institutional authority to resist than a confirmed director would. Trump will likely nominate a permanent DNI before January 1, 2027. That judgment carries high confidence, grounded in the authority gap that sustains Trump's incentive to move quickly. Lukas's narrow 51-46 confirmation signals Democrats will contest any nominee, potentially extending an acting arrangement into late 2026. Departure may instead reflect personal rather than political circumstance. Senate Intelligence members can press a nominee on Iran assessments; absent a nomination before year-end, that leverage does not materialize until at least 2027.
Sources:
1: Gabbard resigns as national intelligence director citing husband's cancer diagnosis - NPR
2: Gabbard Deputy Lukas Will Serve as Acting Director of National Intelligence, Says Trump - U.S. News & World Report
3: Who is DNI Gabbard Successor Aaron Lukas? - SpyTalk
4: Who is Aaron Lukas, Tulsi Gabbard's interim replacement? - Washington Examiner
Gabbard Successor Lukas Aligns With Trump, Questions Russia Election Findings - Bloomberg
Trump Ally Senator Banks Floats Stefanik as Next DNI While Aaron Lukas Serves as Acting Director
BLUF: Banks's endorsement reads as a trial balloon rather than White House intent, and the same House majority math that sank Stefanik's UN bid makes a permanent DNI nomination unlikely this year.
Sen. Jim Banks (R-IN) on May 22 publicly recommended Rep. Elise Stefanik (R-NY) as the next permanent Director of National Intelligence, writing on X that she would be a 'great replacement' for Gabbard and 'easily confirmable' 12. Stefanik has served on the House Permanent Select Committee on Intelligence since 2017 1. Trump initially nominated Stefanik as UN Ambassador after the 2024 election but withdrew the pick over concerns that her House seat vacancy would imperil Republicans' narrow majority; she subsequently launched and suspended a New York gubernatorial campaign and announced she will retire from Congress at the end of her current term 13. Gabbard announced her resignation citing her husband's diagnosis with an extremely rare form of bone cancer, with her departure effective June 30; Principal Deputy Director Aaron Lukas, a 20-year intelligence community veteran and former CIA operations officer who served as NSC deputy senior director for Europe and Russia during Trump's first term, will serve as acting DNI in the interim. Gabbard is the fourth Cabinet official to depart the administration in 2026, following Attorney General Bondi, Homeland Security Secretary Noem, and Labor Secretary Chavez-DeRemer 3.
Analyst Note: Banks's X post carries no corroborating White House signal; three outlets independently cover the endorsement but none carries an administration response, and a Trump nomination of Stefanik as permanent DNI is unlikely within the 2026 calendar year. Moderate confidence rests on that source convergence absent a White House voice. The House majority constraint that killed her UN pick persists: Republicans can lose only two members on any party-line vote, making mid-term departure legislatively costly. Banks may be freelancing to build his own political capital rather than floating an administration-backed candidate. Stefanik's planned retirement dissolves the vacancy problem by early 2027, shifting the calculus if the White House is willing to wait. Her House Permanent Select Committee on Intelligence (HPSCI) tenure since 2017 gives IC governance credentials Gabbard lacked, and a nomination would steer confirmation hearings into oversight terrain the UN process never reached.
Sources:
1: Trump ally Jim Banks floats Stefanik as next intelligence chief - Washington Examiner
2: GOP Sen. Jim Banks floats Elise Stefanik to replace Gabbard as DNI - The Hill
3: Sen. Jim Banks suggests Stefanik replace Gabbard as director of national intelligence - Just The News
Allied Intelligence
Former Austrian Intelligence Officer Egisto Ott Convicted of Spying for Russia and Passing Secrets to Wirecard Fugitive Marsalek
BLUF: Ott's conviction exposes Vienna as a sustained Russian penetration point into EU law enforcement networks, and his assassination-planning role marks Austrian intelligence as having abetted Moscow's lethal operations abroad.
The Vienna Regional Criminal Court on May 20 convicted former Austrian Bundesamt für Verfassungsschutz und Terrorismusbekämpfung (BVT) counterterrorism officer Egisto Ott of espionage, bribery, fraud, and misuse of office, sentencing him to four years and one month in prison 12. Prosecutors alleged Ott passed sensitive information to Russian intelligence and fugitive former Wirecard executive Jan Marsalek between 2015 and 2022, receiving payments exceeding €80,000 1. Brussels Signal, citing the indictment, reported Ott queried national and international police databases and sent unauthorized requests to counterpart services in Italy and the UK, targeting individuals including Bellingcat journalist Christo Grozev 1. The court also found Ott guilty of preparing a "flaw analysis" for Russian intelligence on the 2019 Berlin assassination of Zelimkhan Khangoshvili, which prosecutors said included proposals for targeted killings 1.
Analyst Note: The conviction establishes that Russian intelligence ran a directed penetration of Austria's counterterrorism service for at least seven years, exploiting a cleared officer's access to EU and bilateral law-enforcement databases. Ott's preparation of assassination-planning materials, including proposals for targeted killings tied to the 2019 Berlin murder, crosses from passive collection into operational support for lethal action abroad. Italian and UK partner services now face pressure to audit what data reached Moscow. Coverage draws from a single judicial proceeding rather than independent streams, limiting corroboration weight. The defense's immediate appeal leaves open whether the alleged tasking reflected freelancing for personal gain rather than a directed Moscow relationship. FPÖ-adjacent networks surfaced in testimony add a political liability Austria's coalition cannot easily contain.
Sources:
1: Former Austrian intelligence officer convicted of spying for Russia - Brussels Signal
2: Austrian Spy Found Guilty of Giving Secrets to Wirecard Fugitive - Bloomberg
Burglar Steals DGSE-Branded Laptops Containing Paris Police Plans and Surveillance Data
BLUF: Encrypted floor plans and camera credentials in unknown hands pose a lasting exploitation risk, and French authorities are unlikely to publicly identify or arrest a suspect before 19 August 2026.
On the morning of May 21, an unidentified individual forced open an armored door at OISL Consulting, a security firm in Paris's 19th arrondissement, and stole two Direction Générale de la Sécurité Extérieure (DGSE)-branded Lenovo laptops, fleeing with a black Samsung suitcase 123. The burglar also took two thermal cameras, two camera holsters, and several replica handguns; total material damage is estimated at under €10,000 13. Le Journal du Dimanche reported that the laptops contained encrypted data on Paris police station floor plans and access credentials for the city's surveillance camera network 1. OISL held that data as a contractor supplying video equipment to Île-de-France municipal police; garage surveillance footage captured the burglar at 10:27, and local police opened an investigation that afternoon 123.
Analyst Note: The combination of station floor plans and live surveillance camera credentials raises the operational exposure well above routine equipment loss. All substantive detail originates with Le Journal du Dimanche without independent corroboration. French authorities are unlikely to publicly identify or arrest a suspect by 19 August 2026. Moderate confidence rests on one clear garage-camera record but no corroborating indicators of the burglar's identity or affiliation. DGSE branding on a civilian contractor's hardware signals an asset-labeling gap in France's intelligence supply chain. Encryption slows exploitation but does not foreclose it for a capable actor. The burglar may have targeted OISL for its physical equipment rather than its data, making the data exposure incidental. A stalled investigation leaves the Interior Ministry absorbing unquantified risk with no lever to compel an immediate contractor audit.
Sources:
1: INFO JDD. Paris : des ordinateurs de la DGSE et des plans de commissariats dérobés - Le Journal du Dimanche
2: Des ordinateurs de la DGSE et des plans de commissariats volés lors d'un cambriolage à Paris - Police & Réalités
3: France : un cambrioleur dérobe des ordinateurs de la DGSE et des plans de commissariats - RT en français
In Paris, an unknown person stole the computers of the special services with plans for the commissariats of the capital - Le Journal du Dimanche via Pravda France
Adversary Intelligence
US Intelligence Warns Russia and China Nearly Tripled Espionage Personnel in Cuba With Facilities Monitoring US Military
BLUF: Despite Ratcliffe's Havana warning, Cuba remains very unlikely to take any verifiable step to curb Russian or Chinese collection within 12 months, given durable material dependence on both sponsors.
The Wall Street Journal reported on May 22, citing officials familiar with classified US intelligence assessments, that Russia and China have nearly tripled intelligence personnel in Cuba since 2023 and invested in electronic eavesdropping facilities about 100 miles from the US coast to monitor two Florida military headquarters overseeing Middle East and Latin American operations 12. Both countries have added more modern equipment to intercept military communications, maritime traffic, and intelligence signals from the southeastern United States 12. On May 14, CIA Director Ratcliffe traveled to Havana and warned Cuban officials the "window of opportunity" would not remain open indefinitely 2. China's Foreign Ministry spokesperson Lin Jian called the allegations fabricated and described Beijing's Cuba cooperation as "legitimate, transparent, and in accordance with international law" 2.
Analyst Note: Ratcliffe's Havana visit has not altered the structural incentives making Cuba's accommodation durable. Havana has denied the cooperation's full scope at every diplomatic juncture, derives material support from both sponsors, and faces no coercive lever sufficient to absorb the political and economic costs of reducing adversary collection access. Any verifiable reduction in Russian or Chinese SIGINT infrastructure within 12 months is very unlikely. The classified assessments may instead reflect a coordinated US disclosure designed to pressure Havana before a harder ultimatum, with the intelligence framing serving diplomatic ends. Low confidence attaches to this assessment: sourcing runs through a single outlet citing anonymous officials, with no publicly corroborated imagery or signals reporting to validate the claimed scale. Whether Havana moves determines whether the administration pursues a diplomatic settlement or pivots to sanctions escalation ahead of the Pentagon's June 2026 Cuba intelligence report to Congress.
Sources:
1: U.S. Warns of Growing Russian and Chinese Spying in Cuba - Wall Street Journal
2: United States warns: Russian and Chinese espionage in Cuba is increasing - CiberCuba
U.S. Warns of Russian and Chinese Spying in Cuba - Political Wire
WSJ: Russia and China Expand Intelligence Operations in Cuba - Pravda USA
Russia and China Have Expanded Their Intelligence Operations in Cuba, Tripling Personnel Since 2023 - Pravda USA
Iranian Hackers Target US Aviation and Oil Gas Companies in Sustained Espionage Campaign
BLUF: Iran's pivot to covert access against deep-access engineering targets prioritizes durable espionage over disruption, making a publicly attributed breach at a named firm unlikely before year's end.
Palo Alto Networks' Unit 42 reported Friday that Screening Serpens, also tracked as UNC1549 and Smoke Sandstorm, used fake job postings and malware-laden video conferencing software to target software engineers at US aviation and oil and gas firms, plus organizations in Israel and the UAE 12. In at least one case the operatives impersonated a US airline; one fake posting appeared to be AI-generated, Unit 42 said 12. The campaign, which Unit 42 traces to mid-February 2026, involved six new RAT variants deployed via AppDomainManager hijacking, a technique that manipulates .NET application initialization to disable targets' own security mechanisms 1. Unit 42 told CNN it has no evidence any of those firms were successfully breached, though it believes other unnamed targets in the campaign were compromised 12. The group has maintained high operational tempo with "no signs of slowing down" despite the war and a March IDF strike on what Israel described as Iran's "Cyber Warfare headquarters," Unit 42 said 12.
Analyst Note: Tehran's priority on engineering-level access signals an emphasis on durable covert collection over disruptive operations, consistent with constrained conventional strike options against the US mainland. A publicly attributed intrusion at a named firm is unlikely by December 31, 2026. Low confidence in that assessment reflects Unit 42's reliance on commercial telemetry without corroborating signals intelligence or government attribution. The engineering-access posture itself further depresses the probability of the visible incident that typically triggers public attribution. The campaign's restraint may reflect deliberate escalation management rather than incapacity, preserving more aggressive options for a future confrontation window. Without a confirmed breach, voluntary information-sharing remains the primary defensive mechanism and pressure for mandatory Cybersecurity and Infrastructure Security Agency (CISA) emergency directives stays muted.
Sources:
1: Iranian hackers are targeting aviation, oil and gas companies in espionage scheme, researchers say - CNN via KRDO
2: Iranian hackers are targeting aviation, oil and gas companies in espionage scheme, researchers say - CNN
Tracking Iranian APT Screening Serpens' 2026 Espionage Campaigns - Palo Alto Networks Unit 42
IC Oversight & Authorities
Senate Intelligence Committee Reports FY2027 Intelligence Authorization Act to Senate Floor
BLUF: Senate passage is likely by end of 2026, but the real consequence lies in mandates that strip executive discretion over Ukraine intelligence support and insert an IC checkpoint into Commerce AI export decisions.
The Senate Select Committee on Intelligence reported the FY2027 Intelligence Authorization Act (S. 4615) to the floor on May 20, with Sen. Cotton as the reporting member 1. The bill restructures ODNI leadership, consolidating the principal deputy role into a single Deputy DNI and replacing existing Deputy DNI positions with two Assistant Director slots, while explicitly prohibiting the DNI from domestic law enforcement activities 1. Sen. Bennet secured a provision requiring the IC to sustain intelligence support to Ukraine through any future peace deal and resume full support if Russia violates an agreement 2. Bennet also secured a requirement for IC assessments before Commerce approves AI technology exports or the U.S. government signs AI agreements with foreign governments 2.
Analyst Note: S. 4615 will likely pass the full Senate by end of calendar year 2026, though moderate confidence reflects clean committee passage offset by uncertain floor scheduling and the absence of a House companion. Drawing entirely from committee and sponsor outputs, the analysis carries no independent corroboration. The ODNI restructuring, collapsing the principal deputy into two Assistant Director slots, drives IC reorganization regardless of final enactment. The Ukraine intelligence-support mandate removes executive discretion to trade IC cooperation for diplomatic concessions with Moscow, though the administration may contest this as an executive prerogative infringement, raising a veto threat that could force modifications before floor consideration. The AI pre-export assessment requirement inserts an IC checkpoint into Commerce-led technology transfer. If enacted, IC planners and NSC coordinators absorb Ukraine support as a statutory mandate, not a discretionary line.
Sources:
1: Intelligence Authorization Act for Fiscal Year 2027, as reported on May 20, 2026 - Senate Select Committee on Intelligence
2: Bennet Secures Key Provisions in Senate Fiscal Year 2027 Intelligence Authorization Act - U.S. Senator Michael Bennet
IC Technology & Surveillance
Lawmakers Demand Answers as CISA Contractor Publishes GovCloud Keys and Agency Secrets on Public GitHub
BLUF: Absent forensic evidence that exposed credentials were used, formal confirmation of unauthorized access remains unlikely before end of 2026, denying oversight bodies the breach trigger needed to compel mandatory remediation.
GitGuardian found the "Private-CISA" public repository on May 14, containing AWS AWS Government Cloud (GovCloud) keys, Kubernetes secrets, and CI/CD credentials publicly accessible since November 13, 2025; CISA took it offline on May 15 after GitGuardian reached the agency directly
12.
KrebsOnSecurity reported the contractor had deliberately disabled GitHub's secret-scanning protections before committing the credentials
2. Truffle Security's Dylan Ayrey told KrebsOnSecurity on May 20 that an RSA key granting access to all CISA-IT repositories had not yet been revoked; CISA rotated it following that notification but other critical credentials remain outstanding
2. Congressional letters from both chambers, sent May 19 to Acting Director Nick Andersen, demanded answers; CISA stated there is "no indication that any sensitive data was compromised"
2.
Analyst Note: A formal government confirmation that the exposed CISA credentials were accessed by unauthorized parties is unlikely by end of 2026, leaving Congressional oversight without the Federal Information Security Modernization Act (FISMA) trigger that would compel mandatory remediation reporting. Confidence is moderate: GitGuardian and KrebsOnSecurity converge on the technical facts, but no forensic or signals reporting addresses whether any credential was actually used. The contractor's disabling of GitHub's secret-scanning and CISA's failure to rotate a critical RSA key until outside researchers intervened signal process failures extending beyond a single actor's conduct. The use of a personal GitHub account to sync work materials is more consistent with negligent convenience than deliberate exfiltration, which would shift remediation emphasis toward contractor vetting and endpoint controls rather than insider threat investigation. Absent a confirmed breach, remediation funding and new contractor security legislation compete on a longer timeline.
Sources:
1: How We Got a CISA GitHub Leak Taken Down in Under a Day - GitGuardian
2: Lawmakers Demand Answers as CISA Tries to Contain Data Leak - Krebs on Security
COLLECTION GAPS
- The status of FBI Counterintelligence Division active cases beyond the Ott conviction, including ongoing espionage investigations within the United States, is not available.
- Section 702 FISA surveillance authority usage and compliance findings under the April 2024 reauthorization, including any early indicators of collection scope changes under the new acting DNI, are not available.
- IC Inspector General oversight activities during the DNI leadership transition, including any open investigations into intelligence assessment integrity, are not available.
- Five Eyes intelligence-sharing coordination on Cuba SIGINT and Iran cyber operations, including any friction points between allied services on collection priorities, is not available.