//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF

Current as of 1615 EDT (UTC-04), Friday 26 June 2026

Contents

10 stories from 40 sources across 34 organizations


KEY JUDGMENTS

The U.S. intelligence community's coordination architecture is contracting from executive, legislative, and internal directions simultaneously. Pulte's removal of roughly 50 Office of the Director of National Intelligence (ODNI) personnel, including half the mission integration directorate, is unlikely to be anchored by a formal Director of National Intelligence (DNI) nomination within 90 days. Acting status insulates the restructuring from Senate confirmation exposure the White House has no reason to invite. A Cybersecurity and Infrastructure Security Agency (CISA) director nomination is likely within the same window, though the proposed $707 million budget cut would undermine the planned 600-person workforce rebuild.

FISA Section 702 reauthorization remains deadlocked behind Trump's SAVE Act linkage, and 39,650 FBI noncompliance records due in August will arrive in a legislative environment where the Intelligence Community (IC) Inspector General lacks authority to compel agency cooperation on the compliance questions those records raise. Moderate confidence on both capacity judgments rests on direct congressional testimony and demonstrated White House posture.

Two concurrent Western judicial proceedings against Islamic Revolutionary Guard Corps (IRGC)-directed operations test whether judicial records translate into coordinated diplomatic consequences for Tehran. At least one Hamburg assassination plot defendant is likely convicted by end of 2027. Moderate confidence reflects documented surveillance evidence and cross-border extradition cooperation, offset by trial duration risk in contested Higher Regional Court proceedings.


IC Oversight & Policy

FBI Deputy Director Warns Explosive Drone Attacks in United States Are Only a Matter of Time

BLUF: FBI's public admission that 5G-connected drones eliminate operator-proximity constraints invalidates the detection model protecting every remaining World Cup venue through mid-July.

FBI Deputy Director Chris Raia told Fox News on June 24 that it is "only a matter of time" before explosive-payload drone attacks seen overseas reach the United States 12. Raia described lone-actor attacks as the primary near-term threat and said 5G- and LTE-connected drones are particularly concerning because they could allow an operator in China to control a drone over New Orleans 1. During FIFA World Cup security operations, federal agents have seized more than 300 drones and made eight arrests for unauthorized drone activity 13. Newly unsealed court records in the alleged White House UFC plot suggest conspirators also discussed targeting a World Cup match in Kansas City on July 3 1.

Analyst Note: The public acknowledgment that 5G/LTE connectivity enables remote overseas operators negates the proximity assumption at the core of current counter-drone doctrine. The Kansas City World Cup nexus, surfaced in newly unsealed court filings, compresses the federal planning horizon to days rather than quarters. An acknowledged gap in encrypted-communications coverage leaves the bureau unable to confirm whether additional networks exist beyond those disrupted. Three hundred seizures and eight arrests in roughly two weeks of World Cup operations suggest detection remains volume-based rather than intelligence-led. The warning may primarily serve counter-drone budget and legislative positioning ahead of forthcoming appropriations rather than a discrete intelligence-driven assessment, a reading the single on-record Fox News interview cannot rule out.

Sources:

1: FBI deputy director warns drone attacks overseas will reach the US soon - Fox News

2: FBI Official Warns of Explosive Drone Attacks Reaching US: 'Only a Matter of Time' - The Epoch Times

3: Top FBI official warns that explosive drone attacks in the US are likely: Only a Matter of Time - Just The News

IC Inspector General Warns Congress Agencies Fail to Act on Misconduct Due to Tribalism and Authority Gaps

BLUF: Absent a catalyzing scandal, enactment of the IC IG Parity Act within 12 months is unlikely, leaving IC components with effective veto power over inspector general investigations through procedural delay.

Fox testified before the House Permanent Select Committee on Intelligence on June 24 that his office lacks law enforcement authority to compel agency cooperation and that "agentic tribalism" leads agencies to obstruct oversight requests 12. In one case, an IC employee who purchased illegal firearm components from a Chinese company in February 2023 kept his clearance for 19 months while the IC OIG awaited DOJ action, and was eventually detained by customs on a trip to Israel when the illegal items were discovered 1. A former senior official under probe since March 2021 for post-employment violations was not interviewed until December 2024, more than three years after the investigation opened 1. House Intelligence Chairman Rick Crawford and Sen. Chuck Grassley have introduced the IC IG Parity Act of 2026 to grant the office federal law enforcement authority 1.

Analyst Note: Enactment of the IC IG Parity Act of 2026 within 12 months is unlikely: oversight legislation rarely clears both chambers in a single session without a catalyzing public failure, and the bill carries no visible Senate floor scheduling. Fox's testimony creates a documented administrative record of systemic delay, raising the political cost of inaction for authorizing committee members, though the deference to DOJ prosecution timelines agencies cite is standard legal practice, not necessarily obstruction. Confidence is moderate; the primary hearing record is detailed but draws entirely from one House Permanent Select Committee on Intelligence (HPSCI) proceeding with no corroborating Senate deliberation. IC components retain practical veto authority over Intelligence Community Inspector General (ICIG) investigations through DOJ coordination management until Congress acts. If the Parity Act stalls, current delay structures remain legally defensible and agency slow-rolling continues without recourse.

Sources:

1: Spies Gone Wild: Intel agencies often slow to punish misconduct from guns to grift, watchdog warns - Just The News

2: Effectiveness of the Intelligence Community's Inspector General - House Permanent Select Committee on Intelligence

FBI Delays Release of Nearly 40000 FISA Section 702 Noncompliance Records Until August as Reauthorization Battle Continues

BLUF: Delayed disclosure of nearly 40,000 noncompliance records until after any plausible reauthorization vote ensures Congress will again legislate blind on Section 702 oversight failures.

A June 4 joint status report filed in a Cato Institute Freedom of Information Act (FOIA) lawsuit disclosed that the FBI holds 39,650 records potentially documenting Section 702 noncompliance incidents spanning June 2023 through August 2024 1. The bureau's first production is set for August 15 and will consist of 128 pages 123. Congress missed the June 12 reauthorization deadline, and the Senate adjourned for a two-week recess after Trump conditioned FISA renewal on passage of the SAVE Act, a voter ID bill without Democratic support 23. A classified Foreign Intelligence Surveillance Court (FISC) opinion issued in March, which members of Congress report having reviewed, reportedly criticized an FBI database filter for underreporting searches on Americans' communications 23. A bipartisan group of senators has demanded its declassification, and the administration has provided no timeline 23.

Analyst Note: The August 15 production date forecloses Congressional use of noncompliance records to condition reauthorization. Documents arrive after any vote, reproducing the 2024 cycle when records emerged only post-passage. The FISC has already certified the program for another year, so collection continues regardless of Congressional action before the recess ends. The more consequential gap is the classified March FISC opinion reportedly finding systemic underreporting in the FBI's query filter: no declassification requirement runs until September and no forcing function exists before reauthorization. The production schedule may reflect standard FOIA processing constraints rather than deliberate sequencing around the vote. Low confidence: primary sourcing originates with the Cato Institute, plaintiff in the underlying litigation with a declared adversarial posture toward the program, amplified by the Daily Caller without independent verification.

Sources:

1: FISA Section 702 Noncompliance Records: 39,650 Pages Worth? - Cato Institute

2: FISA Fight Intensifies as FBI Delays Release of Section 702 Abuse Records - Daily Caller

3: How The FBI Will Blindfold Americans Until Congress Approves More Warrantless Spying - Daily Caller News Foundation

Cato Expert: DOJ and FBI Stonewalling on FISA Noncompliance Records Ahead of Section 702 Expiration - Cato Institute

IC Workforce & Organization

ODNI Deputy Director Pushed Out as Pulte Removes Roughly 50 Staff in First Week

BLUF: Pulte's gutting of ODNI's mission integration directorate without a formal nomination, which remains unlikely within 90 days, leaves IC coordination authority functionally headless during an active oversight contraction.

CBS News first reported that Will Ruger, deputy director of national intelligence for mission integration, was placed on administrative leave after Pulte assumed the acting director role Friday 12. Defense One and Government Executive, citing a person familiar with the matter, additionally reported that 15 to 20 mission integration personnel detailed from other IC units were sent back to their home agencies, part of roughly 50 total career and political staff removals since Friday 12. Mission integration coordinates the 18 agencies of the U.S. intelligence community and advises the DNI on collection, analysis, and policy decisions 12. Senate Intelligence Committee Chairman Tom Cotton confirmed Wednesday that Pulte told him 45 to 50 career officers were being returned to home agencies, with a smaller number of front-office personnel departing federal service 12.

Analyst Note: Cotton's on-record confirmation elevates the count from anonymous sourcing: 45 to 50 career officers returned to home agencies, including 15 to 20 mission integration personnel whose departure strips the directorate coordinating collection and analysis across all 18 IC components. Pulte is unlikely to receive a formal presidential nomination within the next 90 days, so restructuring proceeds without the institutional anchor a Senate-confirmed director provides. The removals may track Gabbard's 40% workforce reduction target rather than deliberate disruption, but HPSCI testimony on IC IG authority gaps and delayed FISA 702 noncompliance records mean oversight is contracting from both directions simultaneously. Analytic confidence is moderate, resting on Clayton's unrevoked nominee status. His confirmation before further restructuring determines whether Congress retains any confirmation-based check on ODNI personnel decisions.

Sources:

1: ODNI deputy director pushed out amid Pulte shakeup - Defense One

2: Director of National Intelligence office cuts reach key coordination function - Government Executive

ODNI under Pulte fires 6 staff, sends 45 back to home agencies - CBS News

Prior Reporting - [Acting DNI Pulte forces out top Gabbard deputy Will Ruger](https://jewishinsider.com/2026/06/will-ruger-ousted-odni-bill-pulte-tulsi-gabbard/) (2026-06-24)

DHS Chief Says Trump Has Met With Potential CISA Director Nominee as Agency Plans to Hire 600

BLUF: Mullin's dual-committee testimony likely signals a formal CISA director nomination within 90 days, unlocking a workforce rebuild stalled since the term began.

Testifying before the House Homeland Security Committee on Wednesday and the House Appropriations subcommittee on Thursday, Department of Homeland Security (DHS) Secretary Markwayne Mullin confirmed that President Trump has met with a potential CISA director nominee but declined to name the individual 1234. Mullin said the agency needs approximately 600 additional personnel to reach a target of 2,800, up from its current 2,200, and estimated the rebuilding effort would take roughly a year 14. Nextgov/FCW reported that as of early May, Mullin had submitted a candidate name to the White House that was not Tom Parker, an IBM security executive previously identified as under consideration 2.

Analyst Note: A formal CISA director nomination is likely within 90 days, clearing the primary gate on an agency workforce rebuild that has been stalled at 2,200 personnel for the duration of the second Trump term. Mullin's explicit commitment before two House committees, combined with a candidate already submitted to the White House in early May, signals the nomination process has moved from deliberation to finalization. Senate confirmation scheduling and candidate vetting dynamics outside DHS control remain the primary slippage risk within that window. Moderate confidence rests on Mullin's direct testimony before two committees, corroborated by C-SPAN primary coverage; the candidate's identity and confirmation trajectory remain invisible to open-source collection.

Sources:

1: DHS chief says president has met with potential CISA nominee; agency plans to hire 600 - The Record

2: Trump to soon nominate CISA head, DHS secretary says - Nextgov/FCW

3: Mullin testifies on DHS contract reviews, CISA staffing - Federal News Network

4: DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels - CyberScoop

Homeland Security Secretary Mullin Testifies on DHS Oversight - C-SPAN

Prior Reporting - [Trump considers Palantir exec to lead CISA](https://therecord.media/trump-considers-palantir-exec-to-lead-cisa) (2026-06-04) - [In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA](https://www.securityweek.com/in-other-news-anthropic-maps-ai-threats-unpatched-comodo-flaw-palantir-chief-eyed-for-cisa/) (2026-06-05) - [Trump eyes Palantir Tech Chief to lead CISA](https://www.escudodigital.com/en/cybersecurity/trump-eyes-palantir-tech-chief-to-lead-cisa.html) (2026-06-06)

Adversary Intelligence

Google Reveals FSB-Linked Turla Group Deploying StockStay Backdoor Against Ukrainian Government and Defense Targets

BLUF: STOCKSTAY's parallel deployment alongside KAZUAR confirms Turla has built redundant persistent access into Ukrainian government networks that discovery of either toolkit alone cannot remediate.

Google Threat Intelligence Group on June 26 attributed STOCKSTAY to Turla, publicly linked by CISA to Center 16 of Russia's Federal Security Service (Russia) (FSB) 12. The .NET backdoor has been in continuous development since at least December 2022, primarily targeting Ukrainian government and military organizations; early versions also targeted entities in Italy, the Netherlands, Poland, and Germany before operations shifted to the Ukrainian government and defense focus 12. Google Threat Intelligence Group (GTIG) identified significant code and functional overlaps with KAZUAR, a prior Turla toolkit, and found 2025 variants shifting from a stock-market application masquerade to impersonating PDF readers and calculators 1. Delivery used phishing emails with malicious Remote Desktop Protocol (RDP) configuration files, with lures drawing on academic and diplomatic themes, including a compromised Ukrainian university email account and a hijacked diplomatic education platform 12.

Analyst Note: STOCKSTAY's two-stage architecture, hardcoded initial access then environment-keyed targeting, establishes that Turla completed host-level reconnaissance inside some target networks before deploying the implant. Delivery through a compromised Ukrainian university account and a hijacked diplomatic-education platform signals penetration of trusted institutional infrastructure beyond direct government targets. KAZUAR code lineage reflects deliberate parallel-toolkit construction; a confirmed KAZUAR infection does not establish STOCKSTAY clearance. The concurrent Security Service of Ukraine (SBU)-FBI disclosure of Russian social engineering against messaging accounts across Ukraine and Europe confirms dual-track tradecraft: bespoke implants for high-value targets alongside scalable credential harvesting. Based on Google's telemetry alone, the European early-stage samples may reflect public scanning-service uploads rather than deliberate regional targeting.

Sources:

1: The Latest Addition to Turla's Intelligence Gathering Apparatus - Google Cloud Blog

2: Turla group adds more malware to Russia's espionage efforts against Ukraine - The Record

Ukraine and Eastern Europe defense industry targeted by novel Turla backdoor - Field Effect

Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks - The Hacker News

Top FSB Mole Inside Ukraine SBU Gets Life Sentence After Being Used to Feed Disinformation to Russia

BLUF: Kozyura's seven-year penetration of SBU's anti-terror command exposes how deeply FSB's pre-2014 political recruitment networks have compromised Ukraine's wartime security apparatus.

The Shevchenkivskyi District Court in Kyiv sentenced Colonel Dmytro Kozyura, former head of staff of the SBU's Anti-Terrorist Center, to life imprisonment for high treason under martial law 123. Babel and the Kyiv Independent report Kozyura was recruited by the FSB in Vienna in March 2018 and detained in February 2025 under SBU operation "Rat" 12. From 2024 through his arrest, he transmitted classified data on missile strike aftermaths, SBU unit locations, and critical infrastructure including the gas transportation system and air defense plans 23. The SBU stated it ran a counterintelligence operation using Kozyura to pass disinformation to Moscow and identified his FSB curator as Yuri Shatalov, a former aide to a former Party of Regions MP 2.

Analyst Note: The curator's documented link to former Party of Regions networks indicates FSB's wartime agent recruitment draws on pre-2014 political infrastructure, not post-invasion opportunism. The penetration extended to air defense dispositions and critical infrastructure protection plans. Sourcing traces entirely to SBU and Prosecutor General press statements with no independent judicial documentation, limiting confidence in official characterizations of the disinformation operation's scope. The uncontrolled collection window between his 2018 recruitment and 2025 detection remains classified. SBU's public emphasis on a successful feed operation may be reputational management concealing a longer uncontrolled exposure window before the turn, not a genuine counterintelligence win.

Sources:

1: Former SBU counter-terrorism chief sentenced to life in prison for passing state secrets to Russia - Kyiv Independent

2: He passed data to the FSB. Former head of the SBU Anti-Terrorist Center sentenced to life for high treason - Babel

3: Former SBU Antiterrorist Center staff head Koziura gets life sentence for spying for Russia – SBU - Interfax Ukraine

Top FSB Mole Inside Ukraine's SBU Gets Life Sentence - Kyiv Post

Former senior SBU officer sentenced to life for spying for Russia - TVP World

Two Men Go on Trial in Germany Over Alleged IRGC Quds Force Directed Plots to Assassinate Jewish Leaders

BLUF: Germany's formal prosecution of IRGC-directed assassination plots likely yields at least one conviction by end of 2027, narrowing Berlin's diplomatic space to compartmentalize Iranian intelligence operations from broader EU engagement with Tehran.

Trial opened Friday at Hamburg's Higher Regional Court against two men on charges of espionage, attempted murder, and arson connected to Iranian-directed plots against Jewish community leaders in Germany 12. Lead defendant Ali S., a Danish national of Afghan origin, allegedly surveilled Central Council of Jews president Josef Schuster, former Green MP Volker Beck, and two Jewish-owned food businesses in Berlin during spring 2025 under Quds Force direction, prosecutors say 123. Afghan co-defendant Tawab M. faces attempted murder charges for allegedly agreeing to procure weapons and arrange an assassin targeting Beck 3. Both defendants were extradited from Denmark and declined to speak after the indictment was read; Iran's embassy in Berlin has dismissed the allegations as "unfounded and dangerous" 12.

Analyst Note: The trial's opening converts Germany's diplomatic protest into a formal judicial record, constraining Berlin's room to absorb further IRGC operations without escalating its response. At least one defendant is likely convicted on at least one felony count by end of 2027. Moderate confidence reflects the Mossad-assisted evidentiary base and defendants' silence at arraignment, offset by the 18-month schedule and contested-proceeding uncertainty. The Quds Force's ethnic-Afghan proxy template is replicable across any European state with comparable diaspora communities. A concurrent FBI-Montenegro arrest of an IRGC-linked hacker places two Western judicial actions on the same timeline, raising the threshold for EU diplomatic accommodation of Tehran's objections. The defendants may have inflated their Quds Force ties to secure payment, making the command link to Tehran less direct than charged. Conviction sharpens the political case for expelling Iranian diplomatic personnel; acquittal relieves that pressure and reinforces Berlin's preference for judicial over diplomatic channels.

Sources:

1: German Court Tries Two Men over Alleged Iran-backed Anti-Jewish Plots - Asharq Al-Awsat

2: Man on trial accused of tracking Jewish figures as targets for Iran-backed attacks - The Jewish Chronicle

3: Germany charges suspected Iranian spies over plot to kill Jewish community leaders - Ynet News

Hanseatisches Oberlandesgericht: Hauptverhandlung 'Geheimdienstliche Agententätigkeit für den Iran' beginnt am 26. Juni 2026 - Hanseatisches Oberlandesgericht Hamburg (Gerichtspressestelle)

2 men go on trial in Germany over alleged Iran-backed plots targeting Jews - Times of Israel

Prior Reporting - [Germany charges Dane in alleged Iranian plot to kill Jewish leader, three others](https://www.jns.org/news/world/germany-charges-dane-in-alleged-iranian-plot-to-kill-jewish-leader-three-others) (2026-05-21) - [Alleged IRGC operative charged with plotting to kill German Jewish leader](https://www.timesofisrael.com/alleged-irgc-operative-charged-with-plotting-to-kill-german-jewish-leader/) (2026-05-21) - [Germany charges alleged Iranian agent for scouting out Jewish figures with a view to attacks](https://www.washingtonpost.com/world/2026/05/21/germany-iran-charges-espionage-jews-attacks-plot/ed8702e4-5515-11f1-9c40-7a0a12d9e745_story.html) (2026-05-21) - [Germany charges alleged IRGC agent over plots against Jewish figures](https://www.iranintl.com/en/202605214894) (2026-05-21) - [Two men charged for plot to assassinate German Jewish leaders on behalf of Iran](http://www.jpost.com/diaspora/antisemitism/article-896980) (2026-05-21) - [Anklage wegen geheimdienstlicher Agententätigkeit sowie versuchter Beteiligung an Mord und Brandstiftung erhoben](https://www.generalbundesanwalt.de/SharedDocs/Pressemitteilungen/DE/2026/Pressemitteilung-vom-21-05-2026-2.html) (2026-05-21)

IC Operations & Tradecraft

SBU and FBI Expose Russian Intelligence Campaign to Hack Messaging Accounts of Officials Across Ukraine, Europe and US

BLUF: Russian intelligence has operationalized social engineering at scale against consumer messaging platforms, creating a persistent collection vector that technical countermeasures alone cannot neutralize.

On June 25, the SBU and FBI jointly announced the exposure of a systematic Russian cyber campaign targeting messaging accounts of officials, military personnel, politicians, activists, and ordinary civilians across Ukraine, Europe, and the United States 12. The campaign aimed to extract sensitive military, political, and economic information and steal personal data 13. Attackers used social engineering rather than exploiting application vulnerabilities, with the primary technique involving SMS messages impersonating platform support services sent during early morning hours to exploit reduced user alertness 13. The SBU did not name the responsible Russian service or the targeted platforms; a concurrent FBI IC3 advisory (PSA260626) identified the tracked threat clusters as UNC5792 and UNC4221 and stated the campaign has resulted in unauthorized access to thousands of individual commercial messaging application accounts.

Analyst Note: The joint disclosure reveals Russian services have standardized social engineering as their primary vector for messaging account compromise, bypassing technical defenses with a technique that scales against any platform without exploiting application vulnerabilities. Morning-hours delivery is a deliberate operational adaptation targeting reduced user alertness, creating an attack surface patch cycles cannot close. Anchored on the SSU's own press release with secondary amplification only, the SBU's withholding of attribution, platform names, and victim counts limits the disclosure's operational value. The attribution gap may reflect collection uncertainty rather than operational sensitivity, pointing to a cybercriminal contractor rather than a primary Russian intelligence directorate.

Sources:

1: SSU and FBI expose russian intelligence services' systematic attempts to hack messaging apps of officials in Ukraine, Europe and US - GlobalSecurity.org / SSU

2: Russia Targets Officials' Messaging Accounts Across Ukraine, Europe, and US - Kyiv Post

3: Russia used social engineering to breach prominent messaging accounts, Ukraine says - The Record

Russian Intelligence Services Continue to Target Commercial Messaging Applications - FBI Internet Crime Complaint Center (IC3)

SBU and FBI expose Russian attempts to hack officials' messaging accounts - New Voice of Ukraine

Montenegro Police and FBI Arrest Iranian Hacker Wanted for $3.4 Billion in Cyberattacks on US Infrastructure

BLUF: Joint FBI-Montenegro custody narrows safe transit for IRGC-linked cyber operatives, though dual nationality and European human rights appeals could protract extradition well beyond standard timelines.

Montenegrin police and the FBI arrested a 39-year-old dual Iranian-Turkish national in the coastal resort of Kotor on Thursday, acting on a US extradition request 123. A Montenegrin police statement reported that from 2013 onward the suspect carried out mass hacking attacks on US infrastructure, targeting more than 150 universities and causing an estimated $3.4 billion in damage 123. Stolen data and compromised university accounts were used for the benefit of the IRGC and Iranian universities, the statement added 12. He is sought by the Southern District of New York on charges including conspiracy to commit computer fraud, hacking, and identity theft, with extradition proceedings assigned to a High Court judge in Podgorica 12.

Analyst Note: The arrest surfaces an IRGC-directed credential harvesting network targeting US universities for over a decade, with stolen data channeled to Iranian institutions. The FBI-Montenegro joint custody operation marks an escalation in Western Balkan counterintelligence cooperation. Extradition at Podgorica's High Court will face delay: the suspect's dual Iranian-Turkish nationality and European human rights appeal routes extend the timeline beyond a standard window. NATO membership and active EU candidacy cut the other way, giving Montenegro strong incentive to deliver on a case with a documented IRGC nexus. The decade-long operational span and dual nationality may instead indicate a freelance contractor arrangement rather than a directed operative, which would constrain prosecutors' ability to establish state command and control. Moderate confidence, based on a single primary-classified Reuters report before formal charging documents have been released.

Sources:

1: Montenegro police, FBI arrest Iranian wanted by US for hacking - Reuters

2: Iranian national U.S. sought for $3.4 billion in hacking attacks arrested in Montenegro - CBS News

3: Iranian national sought by US on hacking charges arrested in Montenegro - ABC News

Montenegro Police, FBI Arrest Iranian Wanted by US for Hacking - NTD

COLLECTION GAPS

UNCLASSIFIED // OPEN SOURCE