//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF

Current as of 1649 EDT (UTC-04), Thursday 09 July 2026

Contents

9 stories from 34 sources across 30 organizations


KEY JUDGMENTS

Counterintelligence services advanced on three fronts this cycle: Italy expelled two Russian military attachés tied to a ring that passed NATO Sol-Air Moyenne Portée/Terrestre (SAMP/T) specifications to Moscow, Poland convicted an Federal Security Service (FSB)-recruited couple who combined exile surveillance with an intercepted parcel bomb, and Taiwan sentenced a Democratic Progressive Party (DPP) staffer for Chinese intelligence network-building targeting diplomatic secrets. Whether Moscow retaliates to Rome's expulsions by August 8 is genuinely uncertain. Moderate confidence reflects an 80 percent post-2014 reciprocal expulsion rate balanced against Russia's incentive to preserve ties with a historically sympathetic NATO member. A public Ministry of Foreign Affairs (MFA) retaliatory declaration would shift the assessment.

Five Eyes services are scaling offensive operations alongside public disclosure. Communications Security Establishment (CSE)'s incident response rose 25 percent year-over-year while the agency disrupted ten ransomware groups, confirming a demand-driven expansion visible across consecutive annual reports. MI5's procurement-stage sting of a neo-Nazi planning a mass gun attack demonstrates growing comfort with supply-controlled disruption before plots mature.

FBI and DHS fusion centers are applying National Security Presidential Memorandum (NSPM)-7 threat frameworks to domestic political dissent, embedding partisan commentary as intelligence sourcing in products distributed to local law enforcement. Procedural reforms tightening counterintelligence vetting of the channels exploited in this cycle's espionage cases are unlikely by October, consistent with slow legislative response following comparable convictions.


Allied Intelligence

CSE Annual Report 2025-26 Discloses 3216 Cyber Incidents Responded to and Disruption of 10 Ransomware Groups Targeting Canada

BLUF: Ottawa's shift from isolated takedowns to concurrent disruption of 10 ransomware groups marks Canada's normalization of offensive cyber operations as a standing security function.

In its 2025-2026 Annual Report released June 30, Canada's Communications Security Establishment said its Canadian Centre for Cyber Security responded to more than 3,216 cyber incidents affecting federal institutions and critical infrastructure, held 522 engagements with infrastructure partners, and conducted 13 briefings on quantum-computing threats to cryptography 1. CSE said intelligence support enabled investigations into ransomware-as-a-service operations responsible for more than 25 incidents against transportation, healthcare, pharmaceutical and business sectors, and that the agency took concurrent action against 10 significant ransomware groups this year, using signals intelligence to render one prolific RaaS group's infrastructure inoperable and delete stolen data the group had advertised for sale on the dark web 1. The Record reported CSE's hacking operations targeted three criminal groups in 2025: an extremist organization whose recruitment credibility CSE undermined, a network trafficking fentanyl precursor chemicals, and a ransomware gang, a narrower framing than the report's broader ransomware-group disruption figures 2. CSE Chief Caroline Xavier and Defence Minister David McGuinty both stated in the report that state-sponsored actors are increasingly conducting disruptive cyber activity alongside espionage 1.

Analyst Note: CSE's disclosure of coordinated action against 10 ransomware groups, rather than isolated takedowns, indicates offensive cyber operations are becoming a standing complement to defensive incident response. The gap between that aggregate figure and The Record's narrower three-target account, the only independent secondary reporting against CSE's own primary release, suggests Ottawa is calibrating what it publicly attributes to manage diplomatic exposure while still signaling capability. The aggregate may also reflect joint operations with law enforcement rather than ten unilateral CSE actions, a distinction the report leaves unresolved. Subsequent reporting narrowed that aggregate to identifiable categories, drug trafficking and extremist-network targets, for the first time. Thirteen quantum-cryptography briefings alongside 3,216 incident responses indicate CSE now treats post-quantum migration as an operational priority, with federal institutions and infrastructure operators bearing the transition burden.

Sources:

1: Canada's CSE report details rising cyber threats, ransomware investigations, critical infrastructure protection efforts - Industrial Cyber

2: Canadian spy agency reports hacking three criminal groups in 2025 - The Record (Recorded Future News)

Communications Security Establishment Canada releases its 2025-2026 Annual Report - Communications Security Establishment Canada / Canada.ca

Prior Reporting - [The Communications Security Establishment turns 80](https://wesleywark.substack.com/p/the-communications-security-establishment) (2026-06-29) - [Communications Security Establishment Canada Annual Report 2025-2026](https://www.cse-cst.gc.ca/en/accountability/transparency/reports/communications-security-establishment-canada-annual-report-2025-2026) (2026-06-29) - [CSEC Unveils 2025-2026 Annual Report](https://www.miragenews.com/csec-unveils-2025-2026-annual-report-1701132/) (2026-06-29)

Former Israeli Hospital Spokesperson Reveals Mossad Secretly Saved Erdogan Life During Critical Illness

BLUF: Surfacing this unverifiable claim during Erdogan's summit with Trump reads as a calculated Israeli information operation aimed at undercutting Ankara's anti-Israel posture, not a genuine intelligence disclosure.

Avi Shushan, former spokesperson for Tel Aviv's Ichilov Hospital, said on a Channel 14 panel broadcast Tuesday that an Israeli doctor saved Turkish President Recep Tayyip Erdogan's life roughly seven years ago while Erdogan was being treated for cancer 12. Shushan said the doctor, whom he declined to name, was dispatched at Mossad's request with the approval of Prime Minister Benjamin Netanyahu 1. Shushan said media pressed him at the time to confirm the episode and he declined to do so 1. Erdogan hosted President Trump in Ankara for a NATO summit the same week the broadcast aired 2.

Analyst Note: The claim traces to one unnamed source relayed secondhand by a media commentator, with no corroboration from Ichilov Hospital, Mossad, or Ankara, so it functions as unverifiable political commentary rather than established fact; Arutz Sheva and Maariv coverage of the same broadcast and JFeed's amplification all trace to that single Shushan account. Surfacing during Erdogan's Ankara summit with Trump suggests intent to needle Turkish anti-Israel rhetoric rather than genuine disclosure of classified activity, though the remarks may equally reflect a commentator monetizing insider proximity rather than an authorized leak. If accurate, the episode would point to a long-standing, deniable channel of Israeli-Turkish contact that survived years of public hostility between the two governments, more relevant to understanding back-channel ties than to any near-term policy shift.

Sources:

1: Former Ichilov Spokesperson Reveals: Israeli Doctor Saved Erdogan's Life With Netanyahu's Approval - Arutz Sheva (Channel 7)

2: The Secret Mossad Mission: Israeli Doctor Saved Turkish President Erdogan Life During Critical Illness - JFeed

Live panel broadcast featuring Avi Shushan's claim that an Israeli doctor saved Erdogan's life - Channel 14 ("Sheva" program with Yehuda Shlezinger and Yaakov Bardugo)

⁨דובר איכילוב לשעבר חשף: רופא ישראלי הציל את ארדואן - "המוסד ביקש"⁩ - Maariv (citing Channel 14 broadcast)

MI5 Sting Operation Leads to 13-Year Sentence for Neo-Nazi Who Planned Mass Gun Attack

BLUF: MI5's procurement-stage sting model now extends to lone-actor far-right cases, compressing the disruption timeline but raising questions about scalability as online radicalization pipelines accelerate.

Alfie Coleman, 22, of Great Notley, Essex, was sentenced at the Old Bailey to 13 years and six months in prison plus five years' extended licence after a retrial convicted him of preparing for terrorist acts; Judge Richard Marks KC called him a "dangerous offender" whose views were "virulently racist" 1234. MI5 and Counter Terrorism Policing said they identified Coleman in summer 2023 after he grew more active in online extreme right-wing groups, then used undercover officers to arrange his purchase of a Makarov pistol, five magazines and 200 rounds of ammunition for £3,500 234. Armed counter-terrorism officers arrested him in a Morrisons car park in Stratford, east London, on 29 September 2023 as he collected the pistol and ammunition 234. Investigators said Coleman, radicalised online from age 14, kept a manifesto-style diary naming potential targets including the Lord Mayor of London and a mosque, and idolised Thomas Mair, who murdered MP Jo Cox 1234. A former part-time Tesco worker, he also kept a separate hate list branding colleagues and customers "race traitors" over interracial relationships, recording their vehicle number plates 24. He pleaded guilty to possessing 10 documents likely to be useful to terrorists but denied he was preparing an attack 1234.

Analyst Note: MI5 and Counter Terrorism Policing's use of undercover officers to broker Coleman's pistol purchase reflects a deliberate shift toward disrupting extreme right-wing plots at the procurement stage rather than waiting for attack planning to mature, a single Metropolitan Police statement underlying accounts that otherwise merely repeat the same Old Bailey sentencing. The dangerous-offender finding and 30-year notification order show courts extending post-release monitoring even against mitigating factors like autism-spectrum traits and no prior record, while Commander Flanagan's parental-warning framing pushes early intervention before radicalized individuals reach that procurement stage. Coleman's own defense, that his diary and target list were "hyperbole, bravado, fantasy" born of isolation rather than operational intent, was rejected by the jury but remains his account, meaning parole and monitoring decisions ahead will hinge on assessments of genuine versus performative extremism.

Sources:

1: Neo-Nazi jailed for over 13 years for planning mass gun attack after being snared by MI5 - GB News

2: Neo-Nazi from Essex jailed for more than 13 years for planning mass gun attack as a teenager - ITV News Anglia

3: Former supermarket worker and neo-Nazi, 22, jailed for planning mass gun attack that was uncovered by MI5 in undercover sting - LBC

4: British Neo-Nazi Radicalised at 14 Tried Buying Gun From Undercover Officers for £3,500 - IBTimes UK

Warning to parents after man radicalised online as a teen is jailed for planning extreme right wing terrorist firearms attack - Metropolitan Police

CSE Annual Report Discloses 2,561 Cyber Incidents Handled and 3,385 Foreign Intelligence Reports Produced in 2024-2025

BLUF: Critical infrastructure's emergence as CSE's dominant incident category, now exceeding federal systems, signals that Canada's cyber threat surface is expanding faster than defensive capacity can consolidate.

Communications Security Establishment Canada's unclassified Annual Report for 2024-2025, covering April 1, 2024 to March 31, 2025, states the Cyber Centre responded to 2,561 cyber security incidents, split between 1,155 affecting federal institutions and 1,406 involving critical infrastructure partners 12. CSE reported producing 3,385 foreign intelligence reports for 32 client departments and 3,016 individual clients during the period 12. The agency issued 336 pre-ransomware notifications to more than 300 Canadian organizations, which it estimated averted 74 to 148 ransomware incidents for economic savings of $6 million to $18 million 123. CSE reported a workforce of 3,841 full-time permanent employees, a 6 percent increase from 3,529 the prior year, and total authorities exceeding $1 billion for the year 123.

Analyst Note: CSE's incident and reporting volumes point to genuine scaling of Canada's cyber and signals apparatus rather than steady-state activity, with critical infrastructure now drawing more incident response than federal systems and workforce growth outpacing historical hiring. The subsequent 2025-2026 report shows incident volume climbing a further 25 percent, from 2,561 to 3,216, confirming demand-driven rather than organizational expansion. The critical-infrastructure incident share may instead reflect improved detection and reporting uptake among partners rather than a genuine rise in adversary targeting. Sourcing rests entirely on CSE's own report and the accompanying government release, with secondary outlets merely republishing the same figures, leaving the assessment without independent cross-source corroboration.

Sources:

1: Communications Security Establishment Canada Annual Report 2024-2025

2: Communications Security Establishment Canada releases annual report for 2024 to 2025 - Government of Canada

3: Canada spy agency report highlights hacking threats, foreign interference, extremism - Prism News

Communications Security Establishment Canada releases 2024-25 annual report - Law360 Canada

Israeli Report Details MIT Chief Fidan Dual Role as Mossad Partner and Iranian Axis Interlocutor Amid Turkey Succession Struggle

BLUF: Erdogan's structural incentive to exile Fidan before a succession contest would eliminate the sole functioning back-channel capable of containing Israeli-Turkish crises as public hostility deepens.

A profile in Kikar HaShabbat, relayed by JFeed, reports that Hakan Fidan, who ran Turkey's Millî İstihbarat Teşkilatı (MIT) intelligence service from 2010 to 2023 and now serves as foreign minister, has maintained a covert partnership with Israel's Mossad, at times serving as a secret communication channel between Jerusalem and Ankara and relaying messages to Hamas 12. The two services reportedly disrupted an Iranian terror network in Istanbul in summer 2022 that had been planning to assassinate or kidnap Israeli citizens 12. The report casts Fidan as the most credentialed potential successor to 72-year-old President Erdogan, ahead of Erdogan's son Bilal and son-in-law Selcuk Bayraktar, and cites unnamed analysts as believing Erdogan may sideline him with a diplomatic post abroad 12. Fidan has publicly told Anadolu that Israel may cast Turkey as its next adversary and told CNN Turk that Israel has become a burden humanity can no longer bear, while praising Turkey's halt of roughly $10 billion in trade with Israel 12.

Analyst Note: Fidan's dual role sustains the only functioning Jerusalem-Ankara back-channel even as public rhetoric hardens, so sidelining him would remove the mechanism that has contained prior crises without resolving the underlying rivalry, and his command of sensitive files on Erdogan's inner circle gives the president structural incentive to exile him diplomatically before any succession contest. His ties to the Iranian axis alongside Mossad cooperation leave his ultimate alignment ambiguous. The single-source account, run through Kikar HaShabbat with JFeed relaying rather than independently corroborating, could itself reflect a calculated leak by Israeli or Turkish rivals meant to weaken his standing before Erdogan decides on a successor. Losing him would strip Israel of its most reliable interlocutor inside Turkish security precisely as Ankara's public posture continues to sharpen.

Sources:

1: Erdogan Dangerous Dilemma: The Spy Chief Turned Foreign Minister Who Knows Too Much - JFeed

2: The Dangerous Man in the Middle East: The Heir Threatening to Topple Erdogan - Kikar HaShabbat

Adversary Intelligence

Taiwan Court Sentences Former DPP Staffer to 10 Years for Leaking Diplomatic Secrets to Chinese Intelligence

BLUF: Taiwan's willingness to convict on attempted recruitment absent any classified data transfer sets a lower evidentiary bar that will complicate Beijing's use of business-tie cultivation as an intelligence vector.

The Taiwan High Court on Thursday sentenced former DPP staffer Huang Chu-jung to 10 years in prison for developing an espionage organization on behalf of China under the National Security Act, after finding he recruited then-DPP staffer Chiu Shih-yuan in 2017 and attempted unsuccessfully to recruit Ho Jen-chieh, a former adviser to then-Foreign Minister Joseph Wu, in 2022 12. Prosecutors said Huang and Chiu were paid to solicit classified information, including details of vice presidential trips to Taiwan's diplomatic allies, from Ho and from Wu Shang-yu, a former adviser in the Office of the Vice President 12. The High Prosecutors' Office had sought a sentence exceeding 12 years and sought confiscation of roughly NT$6.08 million in alleged proceeds; the court instead ordered confiscation of NT$4.1 million 12. The ruling is separate from a related case in which the Taipei District Court had sentenced Huang to 10 years for leaking classified state secrets under the Classified National Security Information Protection Act, a sentence the High Court reduced to six years last month 12. The ruling can be appealed 12.

Analyst Note: The verdict confirms Taiwan's courts will convict on network-building alone: Huang's failed approach to Ho Jen-chieh drew the same National Security Act charge as his successful recruitment of Chiu, extending prosecutorial reach to contact with foreign-ministry advisers even absent a completed transfer of classified material. That standard raises exposure for any official maintaining China-linked business ties, since attempted cultivation now carries conviction risk independent of whether data moved. The same court's reduction of Huang's related classified-information sentence from ten to six years last month against today's full National Security Act term points to inconsistent judicial appetite for organizational-leadership charges versus individual-leak charges. Sourcing clusters entirely around the Central News Agency (CNA) wire service, with no outlet independently confirming case details, capping confidence at moderate. The single successful recruit and unconfirmed leak of the vice-presidential travel details also suggest Chinese intelligence's actual penetration of Taiwan's foreign-policy apparatus was more limited than the conviction implies.

Sources:

1: Ex-DPP staffer receives 10 years for developing spy network for China - Focus Taiwan (CNA)

2: DPP staffer sentenced to 10 years for espionage - Taipei Times

綠議員前助理黃取榮為中國發展組織 判刑10年 - Central News Agency (CNA)

共諜案前黨工黃取榮才被判刑6年!另涉國安法發展組織罪 高院判刑10年 - SETN (三立新聞網)

Polish Court Sentences Russian Refugee Couple to Prison for FSB Espionage and Parcel Bomb Plot

BLUF: Poland's prosecution of an FSB network operating under refugee cover exposes Moscow's integration of diaspora espionage with sabotage logistics across NATO territory.

A regional court in Sosnowiec sentenced Igor Rogov, a former "Open Russia" coordinator granted refugee status in Poland, to seven years in prison and his wife Irina Rogova to three years for cooperating with Russia's FSB 12. Polish prosecutors said Rogov gathered information between February and August 2022 on Poland-based Russian opposition figures and their supporters, passing it to Irina on an encrypted device for onward transfer to the FSB in Russia 23. Rogov was also convicted over a July 2024 scheme, carried out with two Ukrainian nationals and another Russian, to ship a courier package containing explosives, including nitroglycerin, military-grade detonators and an improvised initiating device, which Polish security services intercepted at a warehouse in the Łódź region before delivery 245. The trial opened in January in closed session, with prosecutors citing state-security grounds, and the couple has been held in pretrial detention since their 2024 arrest; the verdict is not yet final 24.

Analyst Note: A Sosnowiec court's willingness to convict on FSB penetration of asylum channels signals Warsaw's counterintelligence posture toward Russian emigre monitoring, a vulnerability now forcing tighter vetting of refugee status grants. Pairing that human-source collection with an intercepted parcel bomb built from military-grade detonators and nitroglycerin reads to Polish security services as an integrated sabotage capability riding commercial logistics networks, not isolated espionage, sourcing weighted toward TVN24's courtroom account with uncontested corroboration from four outlets on verdict terms. The bomb plot may instead trace to a Ukrainian intelligence operation shuttling explosive components through Poland toward Russia without Polish authorities' knowledge, according to a competing account drawn from Vot Tak via Meduza. Continued prosecutions on this model squeeze Moscow's recruitment reach among Russian exiles sheltering in Poland.

Sources:

1: Polish Court Jails Russian Activist and Wife for Spying for FSB - The Moscow Times

2: Małżeństwo z Rosji oskarżone o współpracę z wywiadem. Zapadł wyrok - TVN24

3: Former 'Open Russia' coordinator Igor Rogov sentenced in Poland to seven years in prison on FSB espionage charges - Meduza

4: Poland jails former Russian opposition activist and his wife for spying for Moscow - Euronews

5: Poland Convicts Russian Couple of FSB Spying and Parcel Bomb Plot - UNITED24 Media

Counterintelligence

Italy Expels Two Russian Military Attaches After Rome Prosecutors Uncover Espionage Ring Passing NATO Secrets to Moscow

BLUF: Moscow's penetration of Italian military channels feeding NATO's Ukraine aid pipeline demands an allied damage assessment, while reciprocal expulsion of Italian diplomats by August 8 remains genuinely uncertain.

Italian Foreign Minister Antonio Tajani said the government ordered the expulsion of two Russian military attachés, identified as Ivan Petrovich Gorbachev and Mikhail Vasilyevich Astakhov, giving them three days to leave Rome 1234. Tajani said the Rome Public Prosecutor's Office had uncovered the pair's espionage activity and called it part of Moscow's "hybrid weapons" against Italy 14. The expulsions follow the July 7 arrest of two former Italian intelligence officers, named by prosecutors as Gavino Raoul Piras and Vincenzo Di Pasquale, accused of passing classified information to a Russian agent holding diplomatic immunity in Italy over an alleged 12-year period 2, with five others including four military personnel under investigation 1; the case echoes a 2024 conviction of an Italian navy captain for selling classified documents to Russia's embassy 2. Italian media reported the material allegedly passed included details on the SAMP/T air defense system and Aster missiles bound for Ukraine, a NATO mission in Bulgaria, and drone-motor maker Avio 2. Russia's Foreign Ministry, quoted by state agency RIA Novosti, said Moscow would issue "an appropriate response" 25.

Analyst Note: The expulsions confirm Russian intelligence penetrated Italian military channels tied to NATO's Ukraine aid pipeline, forcing Rome's counterintelligence service and allied partners to audit what SAMP/T and Aster logistics data reached Moscow before Piras and Di Pasquale were detained. Whether Moscow answers with reciprocal expulsions of Italian personnel by August 8 is genuinely uncertain, since Ambassador Paramonov's public defiance sits against Russia's pattern of proportionate rather than escalatory retaliation in past attaché expulsions. Confidence in that assessment is low, resting on a single Foreign Ministry statement promising an unspecified response rather than any confirmed retaliatory step. The four Carabinieri and additional suspects still under investigation will determine how far the breach into NATO-linked defense planning actually extends.

Sources:

1: Italy expels two Russian military attachés over espionage uncovered by Rome prosecutors - Euromaidan Press

2: Italy expels two Russian diplomats accused of spying, FM Antonio Tajani says - Euronews

3: Italy expels two Russian military attachés for spying - Ukrainska Pravda

4: Tajani: espulsi due addetti militari dell'ambasciata russa per spionaggio - ANSA

5: Italy Expels 2 Russian Embassy Employees for Spying - The Moscow Times

IC Oversight & Policy

FBI and DHS Fusion Centers Deploy IC Threat Assessment Framework Against Political Dissent Under NSPM-7

BLUF: Fusion centers are operationalizing partisan sourcing and guilt-by-association logic as standard threat methodology, converting protected political activity into actionable intelligence targets for local law enforcement.

Documents obtained by The Intercept show fusion centers and the FBI producing intelligence bulletins on antifa that echo Trump's September 22 executive order and NSPM-7, according to the outlet's review of scores of records distributed through the national fusion center network 1. A 28-page Southeast Florida Fusion Center report, housed at the Miami-Dade Sheriff's Office, describes antifa as seeking the "violent overthrow" of the government, reproduces Trump's executive order in full, and cites sources including Andy Ngo, Jack Posobiec, and the account Far Left Watch 1. The same report names the National Lawyers Guild as antifa's "legal representation," a characterization the group's mass defense director Xavier de Janon disputed, saying no such relationship exists 1. Separately, an FBI "public safety awareness report" dated January 30 warned of anarchist violent extremism in Minneapolis following the shooting death of nurse Alex Pretti by federal officers, and a Dallas Regional Fusion Center bulletin cited the Turtle Island Liberation Front case to justify expanded monitoring of two unrelated pro-Palestine groups with no confirmed Dallas presence 1.

Analyst Note: Fusion centers and the FBI are treating the executive order and NSPM-7 as operational guidance rather than a contested legal claim, embedding partisan sourcing into products meant to inform local policing. Reliance on Andy Ngo, Jack Posobiec, and Far Left Watch lowers the evidentiary bar applied before flagging protected activity, including legal observation by the National Lawyers Guild, as threat indicators, while Dallas's use of an unrelated bombing case to justify monitoring two pro-Palestine groups with no local presence shows threat designation expanding through inference rather than evidence. The assessment rests entirely on one investigative outlet's document review, with no fusion center or FBI confirmation, and the same bulletins could reflect routine threat-monitoring grounded in documented violent incidents rather than coordinated targeting of dissent. Absent judicial or congressional pushback, politically inflected threat products normalize across the fusion center network.

Sources:

1: How Local Cops Are Running With Trump NSPM-7 Attacks on Antifa - The Intercept

COLLECTION GAPS

UNCLASSIFIED // OPEN SOURCE