//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF

Current as of 0325 EDT (UTC-04), Friday 18 September 2026

Contents

10 stories from 50 sources across 40 organizations


KEY JUDGMENTS

European counterintelligence will very likely identify additional non-Russian nationals recruited by Moscow for espionage or sabotage on NATO territory within six months, as active investigations across six countries have already detained nine operatives in the Main Intelligence Directorate (Russian military intelligence) (GRU) arson campaign. Moderate confidence reflects the breadth of ongoing investigations and documented prosecutions. At least one NATO state will likely expel a Russian diplomat before January 2027. Custody of the sheltered coordinators in Russia is unlikely before March 2027 absent a departure from Moscow's non-extradition posture.

Israel will likely impose intelligence-sharing restrictions on the United Kingdom beyond the current retaliatory package within three months, driven independently by both the UK's settlement sanctions dispute and the NAZA documentary leak investigation. Low confidence reflects single-source reporting on MI6's operational concerns. Israel's October 27 election is the variable most likely to alter this assessment, as a change in government could stabilize the bilateral intelligence relationship.

A Five Eyes or NATO advisory addressing AI-orchestrated state cyber-espionage is very likely within six months, as both Russian and Chinese state actors are deploying AI-augmented tradecraft against government targets. Anthropic disrupted Foreign Intelligence Service (Russia) (SVR)-linked multi-agent attack frameworks with minimal human oversight, and European cybersecurity vendor (Bratislava-headquartered) (ESET) documented FamousSparrow's modular backdoor across eight Latin American countries. Moderate confidence rests on vendor detections absent independent government confirmation.


Adversary Intelligence

Anthropic Reports Russian SVR-Linked Group Used Claude AI for Cyber-Espionage Against Government and Defense Targets

BLUF: AI-orchestrated cyber operations by state intelligence services compress defender response timelines and demand reassessment of detection architectures built around human-paced adversary tradecraft.

Anthropic disclosed on September 10 that it disrupted a suspected Russia-linked cyber-espionage campaign, tracked as GTG-20006 and attributed to the Midnight Blizzard group (linked to Russia's SVR), which used Claude to automate reconnaissance, phishing infrastructure, and malware modification, with AI-driven workflows autonomously rebuilding toolkits when security detections triggered them 1. The campaign compromised more than 20 Ukrainian and European government, defense, and drone-manufacturer organizations, stealing drone technology details, including a proprietary SDK for a drone vision system, and exfiltrating hundreds of gigabytes of data, with humans serving mainly as overseers rather than hands-on operators 1. The same disclosure covered a separate effort by Chinese-speaking operators (GTG-1007, likely Hunan-based) conducting vulnerability research and building autonomous exploitation frameworks against roughly 50 organizations, distinct from earlier reported attempts by Chinese AI firms to extract and replicate Claude's capabilities. Disruptions spanned roughly eight months 1. Euronews reported on September 16 that the Russian activity also extended to disinformation and drone-swarm operations, attributing the campaign to the SVR-linked group 2. Anthropic's own September 10 threat intelligence report is the primary source underlying both accounts 3.

Analyst Note: An SVR-linked group's use of multi-agent frameworks with humans confined to oversight signals state cyber operations are shifting from human-paced tradecraft toward AI-orchestrated execution, compressing defenders' window to detect and respond before an operation adapts around them; generalized drone-swarm and disinformation applications suggest the tooling now spans mission sets beyond network intrusion. Sourcing rests entirely on Anthropic's own report, with Japan Times and Euronews amplifying rather than independently verifying its attribution and scope claims, leaving confidence limited to what the vendor observed inside its own platform. The reported target set has broadened beyond last week's Ukraine-focused WhatsApp and ministry campaign to wider government and defense targets, alongside a separate Chinese capability-extraction effort. Anthropic's framing of humans as mere overseers may overstate autonomous AI capability given the company's commercial incentive to showcase both threat severity and its own detection prowess.

Sources:

1: Anthropic disrupts Russian, Chinese AI campaigns targeting its Claude models - The Japan Times

2: Russia used Claude AI for espionage, disinformation and drone swarms - Euronews

3: Countering misuse of AI: September 2026 - Anthropic

Prior Reporting - [Russia uses AI in cyberattacks against Ukraine, Europe, targeting WhatsApp accounts, government ministries, Anthropic says](https://kyivindependent.com/russia-uses-ai-in-cyberattacks-against-ukraine-europe-targeting-whatsapp-accounts-government-ministries-anthropic-says/) (2026-09-11) - [Anthropic caught Russia-linked spies using Claude in hacking operations](https://therecord.media/anthropic-russia-hackers-claude) (2026-09-11) - [Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion](https://www.securityweek.com/anthropic-says-russian-hackers-used-claude-ai-to-automate-malware-evasion/) (2026-09-11)

China-Linked FamousSparrow Deploys New SparroWocky Backdoor Against Latin American Government Agencies

BLUF: FamousSparrow's near-total pivot to Latin American governments and its canal-linked targeting reveal a sustained collection posture calibrated to Beijing's regional commercial and diplomatic pressure points.

ESET Research reported that FamousSparrow, a China-aligned cyberespionage group active since at least 2019, has deployed a new C++ backdoor called SparroWocky against government organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela since at least August 2025 12. ESET researcher Alexandre Côté Cyr said the campaign, tracked since August 2025, has replaced the group's older SparrowDoor implant, and that from mid-2025 into 2026 roughly 90 percent of FamousSparrow's recorded targets were located in Latin America 13. The backdoor exfiltrates files, captures screenshots, collects system and network data, and can load Beacon Object Files; ESET found it incorporates code from open-source projects including Mbed TLS and MinHook 14. ESET noted that one targeted Panamanian entity is involved in an ongoing commercial dispute over ports in the canal area previously operated by a China-based company 23, and separately linked FamousSparrow's SparrowDoor tool to Salt Typhoon, though it tracks the two as distinct due to a lack of technical indicators 1.

Analyst Note: The near-total regional concentration of FamousSparrow's targeting since mid-2025 points to a standing collection mandate rather than a one-off campaign, and the shift from SparrowDoor to the modular SparroWocky backdoor signals investment in stealthier tradecraft built for longer dwell times. This reporting rests on ESET's technical work alone, with The Record and BleepingComputer merely republishing its findings. Targeting a Panamanian entity embroiled in the canal ports dispute shows the group can align cyberespionage with live diplomatic flashpoints, giving Beijing near-real-time visibility into regional responses to US pressure on Chinese investments. The concentration could equally reflect opportunistic exploitation of weaker Latin American network defenses rather than deliberate geopolitical targeting. A publicly floated but ESET-unconfirmed link to Salt Typhoon would, if substantiated, tie a government-facing implant to an operation already implicated in US telecom and Treasury intrusions.

Sources:

1: Beware the SparroWock: The backdoor that bites, the commands that catch - WeLiveSecurity (ESET Research)

2: ESET Research: China-aligned FamousSparrow expands operations in Latin America, targets governments with new backdoor - GlobeNewswire (ESET Research press release)

3: China FamousSparrow hackers target Latin America with new backdoor - The Record

4: Chinese hackers use SparroWocky malware in govt espionage attacks - BleepingComputer

DW Investigation Identifies Cuban Salsa Teacher as GRU-Directed Coordinator of Arson Sabotage Across Four EU Countries

BLUF: Russia's open harboring of an internationally wanted GRU sabotage coordinator makes his arrest within six months very unlikely and signals Moscow views exposed proxy networks as cost-free.

An investigation by Deutsche Welle and three European broadcasters identified Cuban national Oemis Romagoza Durruthy, a Camagüey-born dance instructor who has lived in Russia at least seven years and teaches in Petrozavodsk, as the recruiter known online as "Dios" and "Adrian," who over four months in 2024 directed arson attacks on a building-materials warehouse in Poland, a bus depot in Czechia, a waste-processing plant in Romania, and Lithuania-made equipment bound for Ukraine 12. Lithuanian prosecutors have publicly linked the network to Russia's GRU military intelligence and placed Romagoza on an international wanted list 13. DW reported he recruited at least a dozen operatives via Telegram and Facebook ads offering $1,500 plus bonuses per operation, including Colombian ex-soldier Luis Alfonso Murillo Diosa, who was arrested in Romania and sentenced in 2025 to six years for attempted sabotage 14. At least nine recruits have been detained overall, with two serving six-to-eight-year sentences and others awaiting trial, while Romagoza remains at large and was seen teaching dance in Petrozavodsk as recently as April 12.

Analyst Note: Romagoza's continued public presence in Petrozavodsk, teaching classes as recently as April while under an international wanted notice, indicates Russia is not shielding him through relocation or documentation changes, which very likely reflects Moscow's assessment that GRU disposable-agent networks carry no meaningful cost when exposed. His arrest within six months is very unlikely absent a shift in Russian custodial cooperation, since Moscow has no extradition obligation to Poland, Czechia, Romania, or Lithuania. The Il Riformista investigation naming GRU, Federal Security Service (Russia) (FSB), and SVR diplomatic-cover officers in Rome documents a parallel but more deniable track of Russian intelligence operating in the same NATO theater. Moderate confidence reflects consistent DW-led sourcing on his location and continued recruitment activity, but no independent indicator of Russian intent to surrender him.

Sources:

1: Cuban dance teacher ordered EU sabotage attacks from Russia - DW (Deutsche Welle)

2: By Day, He Taught Salsa in Russia. By Night, He Recruited Saboteurs Across Europe - UNITED24 Media

3: Cuban Dance Instructor Orchestrated Sabotage Attacks Across Europe from Russia for Russian Intelligence - Cuba Headlines

4: Cuban salsa teacher in Russia recruited agents for sabotage across EU, DW finds - Hromadske

Cuban dance teacher ordered EU sabotage attacks from Russia - DW (Deutsche Welle)

Investigation Maps Russian GRU, FSB, and SVR Intelligence Network Operating Under Diplomatic Cover in Rome

BLUF: Italy's exposure of six additional Russian intelligence officers under diplomatic cover in Rome is unlikely to trigger expulsions within three months but maps a broader, multi-service espionage infrastructure targeting NATO from inside allied capitals.

An investigation by Il Riformista's Massimiliano Coccia, published in collaboration with the Kyiv Independent, identifies six additional Russian embassy officials in Rome allegedly tied to Moscow's intelligence services beyond military attachés Ivan Petrovich Gorbachev and Mikhail Vasilyevich Astakhov, whom Italy expelled on July 9 after a Rome prosecutors' probe into two former Italian intelligence officers accused of passing classified information to Russia 1. The investigation names embassy counsellors Igor Alexeyevich Anikeyev and Igor Albertovich Ovechkin as linked to the FSB, focused on Italian military technology and NATO-linked infrastructure, and second and third secretaries Anton Andreyevich Demin and Dmitry Yuryevich Morozenkov as linked to the SVR and GRU, cultivating contacts in Italian cultural, business, and political circles 12. It separately identifies Konstantin Alexeyevich Nemudrov, an attaché accredited to the Holy See whose father was expelled from Italy in 2021 over the Walter Biot espionage case, and reports a source's claim that he has continued part of his father's Vatican contact network 13. The reporting also describes alleged attempts to recruit Belarusian and other Eastern European nationals for sabotage and the systematic collection of digital-infrastructure vulnerability data. Formiche.net and NV.ua both stress these attributions rest on the newspaper's sourcing rather than confirmed Italian government findings 34.

Analyst Note: July's expulsion of two GRU-linked attachés was almost certainly the visible edge of a wider diplomatic-cover network, but Rome is unlikely to expel any of the six newly named officials within three months absent counterintelligence findings independent of this reporting. Anikeyev and Ovechkin's alleged FSB focus on NATO-linked technology and Demin and Morozenkov's SVR/GRU cultivation of cultural and business contacts describe access-building rather than the caught-in-the-act evidence that triggered July's action, and these same activities could equally reflect routine diplomatic outreach Italian counterintelligence has not itself flagged as espionage. Alongside the GRU's Cuban-recruited arson network, the exposures suggest two concurrent GRU operational models across NATO territory: diplomatic cover and third-country proxy recruitment. Confidence is moderate, resting on one deeply reported investigative thread uncorroborated by Italian government attribution. Further expulsions would signal Agenzia Informazioni e Sicurezza Interna (Italian Internal Intelligence Agency) (AISI) has moved from journalistic leads to prosecutable evidence and likely prompt reciprocal Russian expulsions; absent that, the network stays operational and Italian defense and Vatican-linked contacts remain exposed without policy response.

Sources:

1: Chi sono le spie russe che Putin nasconde nell'ambasciata a Roma - Il Riformista

2: Inside Russias intelligence network in Rome - Decode39

3: La rete di Mosca a Roma. Chi sono gli uomini dell'intelligence russa in Italia - Formiche.net

4: Russian Embassy staff in Italy may have recruited foreigners for sabotage — investigation - The New Voice of Ukraine

Trickbot Cybercrime Leader Wanted by Germany and EU-Sanctioned Exposed as Adviser to Russian Duma Deputy Speaker

BLUF: Kovalev's documented advisory role with a Duma deputy speaker reinforces assessed links between Russian cybercriminal networks and state structures, and his arrest or extradition remains very unlikely within twelve months.

Vitaly Kovalev, wanted by Germany's Bundeskriminalamt (German Federal Criminal Police) (BKA) as the alleged founder and leader of the Trickbot hacker group under the aliases Stern and Ben, served as an adviser to State Duma Deputy Speaker Vladislav Davankov for more than a year, according to Davankov's own August 2025 Telegram post and reporting by The Insider citing the GangExposed project 1. Davankov described Kovalev as a New People supporter, entrepreneur, and med-tech investor; the two visited a longevity laboratory at Volgograd State Medical University together 1. Kovalev was initially placed on New People's federal candidate list for the Duma but was removed from regional group No. 18 before the list's July 10 certification, per Vedomosti reporting cited by The Insider and Meduza 12. Interpol issued a Red Notice for Kovalev in May 2025 at Germany's request, and the EU Council added him to its sanctions list in July 2026 over Trickbot- and Conti-linked cyberattacks. iStories additionally reported that the U.S. Treasury has asserted a connection between Trickbot members and Russian intelligence services 13.

Analyst Note: Arrest, extradition, or custody of Kovalev by any government is very unlikely within the next twelve months, given Russia's lack of extradition treaties with Germany or EU states and his demonstrated proximity to Duma leadership. His quiet removal from New People's certified candidate list before the July 10 deadline reflects reputational damage control rather than any new physical-security exposure. Davankov's own August 2025 public endorsement, surfacing alongside EU sanctions and an Interpol Red Notice, points to either institutional vetting failure or tolerance reaching into party leadership. The disclosure's timing, coming right after Kovalev's ballot removal, also fits opposition-aligned kompromat aimed at embarrassing Davankov rather than organic investigative breakthrough. Confidence in this judgment is moderate, resting on a single investigative report reproduced by five outlets without independent confirmation of Kovalev's location or protection. Continued inaction would confirm Trickbot leadership remains beyond the reach of EU and German warrants absent formal Western extradition or asset-freeze action against a Duma-linked adviser.

Sources:

1: Alleged Trickbot hacker wanted by Germany served as adviser to deputy chair of Russia State Duma - The Insider

2: «Новые люди» включили в свой список на выборы в Госдуму Виталия Ковалева. Его разыскивает Интерпол как главу хакерской преступной группировки - Meduza

3: Советник Даванкова оказался лидером хакерской преступной группировки, которого разыскивает Интерпол - iStories

GangExposed Telegram channel post identifying Vitaly Kovalev's advisory role to Duma Deputy Speaker Vladislav Davankov - GangExposed (anonymous Telegram investigator project)

В советнике лидера «Новых людей» признали разыскиваемого Германией хакера - Moscow Times (Russian Service)

Interpol-Wanted Cybercrime Suspect Was Adviser to Russia's 'New People' Leader, Report Says - Kyiv Post

Allied Intelligence

UK Foreign Secretary Miliband Ignored MI6 Warnings That Israel Sanctions Would Damage Intelligence-Sharing Relationship

BLUF: Israel is unlikely to impose additional formal retaliation before its October 27 election, but the intelligence-sharing damage from Miliband's decision is already accruing quietly through reduced Mossad product flow.

According to The Spectator, citing a Labour source close to the intelligence service, MI6 warned Foreign Secretary Ed Miliband that sanctioning Israel over West Bank settlements risked damaging intelligence-sharing with Mossad, but Miliband proceeded with the measures announced last week 1. The Jewish Chronicle and Jewish News, both relaying The Spectator's reporting, note that Health Secretary Andy Burnham joined Miliband in disregarding Foreign, Commonwealth and Development Office (UK) (FCDO) and intelligence advice on the West Bank sanctions 2. The Spectator additionally reported that National Security Adviser Jonathan Powell and UK Ambassador to Israel Simon Walters advised delaying action until after Israel's October 27 election, and that Israeli Foreign Minister Gideon Sa'ar made the same request to Miliband by phone on August 11 1. Israel responded to the sanctions by closing its British consulate in East Jerusalem, ending UK training for Palestinian Authority security forces, and imposing travel bans on 11 British MPs including Jeremy Corbyn 1. Unnamed security sources described Gulf states as reliant on Israeli intelligence passed through the UK and warned that the rift could reduce Gulf willingness to share information with British services 23.

Analyst Note: Israel is unlikely to escalate formally against the UK before its October 27 election, since Netanyahu's government gains more from framing the sanctions as foreign interference during the campaign than from further retaliation, while MI6's access to Mossad product and Gulf states' reliance on that Israeli-sourced material both narrow at the margins regardless of any additional Israeli action. This judgment carries moderate confidence, resting on a single well-placed Labour source describing internal MI6 sentiment without independent corroboration of operational impact on shared product. The sanctions proceeded despite explicit objections from MI6, the National Security Adviser, the UK ambassador to Israel, and Israel's own foreign minister, and Israel's retaliatory package: consulate closure, PA training suspension, and MP travel bans, is now in effect. The delay advice may have served Netanyahu's electoral interests as much as UK security interests, denying his opponents a pre-election grievance rather than protecting intelligence-sharing itself. Continued Israeli restraint lets Miliband treat the current package as the ceiling, while any further escalation would force MI6 and the FCDO to accelerate contingency planning for Gulf-state intelligence redundancy.

Sources:

1: Revealed: Ed Miliband ignored MI6 warnings over Israel sanctions - The Spectator

2: Burnham and Miliband ignored FCDO and intelligence advice on West Bank sanctions - Jewish News

3: Miliband 'ignored MI6 warning' against Israeli sanctions - The Jewish Chronicle

Revealed: Ed Miliband ignored MI6's warnings over Israel sanctions - The Spectator

Prior Reporting - [UN expert Francesca Albanese calls for true paradigm shift as Miliband resets policy on Israel](https://www.theguardian.com/world/2026/sep/07/un-francesca-albanese-miliband-israel-palestine-settlements-trade) (2026-09-07) - [Sources: U.K. to Ban Trade With Israeli Settlements, Declare Occupation in West Bank, Gaza Unlawful](https://www.haaretz.com/west-bank/2026-09-07/ty-article/.premium/sources-u-k-to-ban-trade-with-israeli-settlements-declare-occupation-unlawful/000001a0-7cfe-da8b-afbe-7eff664c0000) (2026-09-07) - [UK's Burnham Risks Trump Anger With New Sanctions on Israel](https://www.bloomberg.com/news/articles/2026-09-07/uk-s-burnham-risks-trump-anger-with-new-sanctions-on-israel) (2026-09-07) - [Ed Miliband set to ban UK trade with Israeli settlements in West Bank in move which risks Donald Trump's fury](https://www.lbc.co.uk/article/ed-miliband-uk-trade-sanctions-israel-palestine-west-bank-us-trump-5Hjdh6q_2/) (2026-09-07)

Finland Detains Two Swedish Citizens on Espionage Charges After Covert Activity Near Arctic Military Sites

BLUF: Finland's detention of two Swedish nationals near Arctic military sites under a low evidentiary threshold makes formal espionage charges by December 18 unlikely absent disclosed evidence of intent.

Finland's Central Criminal Police (KRP) detained two Swedish citizens, aged 37 and 40, on suspicion of espionage, with the Helsinki District Court remanding both into custody on September 16 under Finland's lower "reason to suspect" threshold 1; pretrial detention on espionage suspicion is extremely rare in Finland 2. Court documents place the alleged offenses between August 30 and September 12, and Yle reported the men were arrested in Finland's northern Lapland region several days prior to the hearing 123. The suspects do not appear in Finland's population register but share a surname and a registered address in Härnösand, Sweden. A Yle investigation found both were born in Neuilly-sur-Seine, France, and traced financial ties to a Panamanian foundation and a British Virgin Islands company, with Pandora Papers records naming one man as the BVI entity's beneficial owner 24. Finnish media have speculated a possible link to the September 13-14 European Arctic Summit in Rovaniemi or to a new air force base under construction in the region, though Yle said the target of the alleged espionage remains unconfirmed 23. KRP Commissioner Jussi Luoto said the investigation is in its early stages and declined to disclose how authorities obtained the underlying information 4.

Analyst Note: The detentions signal Finnish counterintelligence is actively hardening the northern flank ahead of further Arctic Summit-adjacent diplomacy and construction at the new air base, though formal indictment by December 18 is unlikely since establishing intent and target under Finland's low "reason to suspect" threshold remains unresolved. Moderate confidence reflects reliance on a single primary account from Yle, with Militarnyi, The New Voice of Ukraine, and TVP World republishing its findings without independent verification. The men's undisclosed foreign addresses and Pandora Papers exposure, rather than confirmed tradecraft, may have driven the arrests, with authorities using the low threshold to buy investigative time. Continued custody without disclosed evidence will likely extend the pretrial timeline past that window. An eventual indictment would hand Finnish and NATO officials a public case for tightening access controls around Arctic bases, while a lapsed case would shift resources back to monitoring and prompt partners to discount the episode as a false alarm.

Sources:

1: Keskusrikospoliisi on aloittanut vakoilututkinnan – kaksi miestä vangittu - Yle

2: Finland detains two men over espionage - The New Voice of Ukraine

3: Two held in Finland on suspicion of spying - TVP World

4: Two Swedes Detained in Finland on Suspicion of Espionage - Militarnyi

IDF Requests Shin Bet Assistance Investigating NAZA Documentary Over Potential Unit 8200 Classified Leaks

BLUF: Zamir's decision to route the NAZA leak probe through Shin Bet rather than internal channels likely delays prosecutorial action by 90 days while insulating Unit 8200's foreign liaison equities from direct IDF scrutiny.

IDF Chief of Staff Lt. Gen. Eyal Zamir ordered Military Advocate General Maj. Gen. Itai Ofir to open an investigation into the "NAZA" documentary on Monday and directed a review of information-security aspects, including whether classified material was leaked for use in the film 123. IDF officials approached the Shin Bet on Tuesday for investigative assistance, but the agency told the military it is awaiting a formal request, which will follow Ofir's decision in coordination with Attorney General Gali Baharav-Miara 123. Haaretz reported the IDF has told the Shin Bet it cannot proceed with its own investigation until it has viewed the film 4. The probe is examining whether any of the documentary's interview subjects are active-duty or reserve personnel, with particular scrutiny on Unit 8200 given its ties to intelligence agencies and international partners 12. Zamir also established a multi-organizational team under the Planning Directorate to formulate responses to the film's claims 1.

Analyst Note: Routing the classified-leak probe through Shin Bet rather than handling it internally likely signals Zamir wants deniability on findings touching Unit 8200's sourcing chains before deciding on prosecutions. Because Shin Bet is withholding formal engagement pending the Military Advocate General's decision and Attorney General coordination, scope and pace now hinge on legal-political sign-off rather than operational urgency. Shin Bet will likely receive and act on the formal referral within 90 days given Zamir's personal commitment and both agencies' aligned procedural sequence, though the requirement to view the film first and coordinate with the Attorney General will push the timeline past the initial request. Confidence is moderate: reporting traces to a single Ynet account sourced to Israeli security officials, with JFeed, Jerusalem Post, Arutz Sheva, and Haaretz recirculating rather than independently confirming it. Shin Bet's insistence on a formal request may reflect bureaucratic reluctance to enter a politically fraught media fight rather than genuine procedural necessity. Authorization would shift Shin Bet resources toward tracing leak pathways into Unit 8200 and open the door to prosecutions against filmmakers and sources; stalling leaves the IDF's internal Information Security Department probe as the sole channel with weaker evidentiary backing.

Sources:

1: IDF Turns to Shin Bet for Help Investigating NAZA Documentary - JFeed

2: IDF chief Eyal Zamir pursues investigation into 'NAZA' film, seeks Shin Bet support - The Jerusalem Post

3: IDF turns to Shin Bet in 'Naza' investigation - Israel National News (Arutz Sheva)

4: IDF Tells Shin Bet: We Can't Investigate 'NAZA' Before Watching It - Haaretz

⁨גורמים בצה"ל פנו לשב"כ: צריכים סיוע בחקירת הסרט נז"א (IDF officials turn to Shin Bet: need assistance investigating the NAZA film)⁩ - Ynet

JASDF RQ-4B Global Hawk Intelligence Reconnaissance Drone Crashes Into Sea of Japan During Classified Mission

BLUF: Japan's investigation will likely attribute the Global Hawk loss to technical failure by March 2027, but Tokyo's refusal to disclose the mission preserves ambiguity that could complicate allied Intelligence, Surveillance, and Reconnaissance (ISR) coordination.

A Japan Air Self-Defense Force (JASDF) RQ-4B Global Hawk assigned to the 502nd Squadron at Misawa Air Base took off at 10:20 a.m. on Tuesday and lost communication at 12:55 p.m., disappearing from radar three minutes later roughly 30 miles north of Tottori Prefecture over the Sea of Japan 12. A Japan Coast Guard helicopter and an F-15J fighter located floating debris that afternoon, and the JASDF confirmed by 5:20 p.m. that the wreckage belonged to the missing aircraft based on photographs taken by Japan Maritime Self-Defense Force (JMSDF) fast attack craft Hayabusa 13. JASDF chief Gen. Takehiro Morita said the drone was not on a training flight but declined to disclose its mission. The Air Self-Defense Force (Japan) (ASDF) has since canceled Global Hawk training flights and formed an accident investigation committee 13. Defense Ministry spokesman Kimihito Aguin said the loss of the aircraft, one of Japan's three Global Hawks, will not impede SDF operations 2.

Analyst Note: JASDF's investigation committee will likely attribute the crash to mechanical or technical failure rather than external interference by March 18, 2027, absent evidence tying the aircraft's undisclosed mission to a hostile actor. Morita's refusal to detail the mission keeps an alternative explanation open, but the platform's overall safety record and the ministry's routine-investigation posture point toward an internal cause. We have high confidence in this judgment, reflecting consistent sourcing across four outlets on the timeline, debris recovery, and command response, with no outlet reporting indicators of external involvement. Canceled training flights and the empaneled committee signal Tokyo expects a technical finding rather than an incident requiring diplomatic escalation.

Sources:

1: Japan Air Self-Defense Force Recon Drone Crashes into Sea of Japan - USNI News

2: Japan probes first Global Hawk crash, says surveillance missions will continue - Stars and Stripes

3: Japan's ASDF Confirms Crash of Missing Global Hawk Drone - Nippon.com (Jiji Press)

Japan Air Self-Defense Force confirms Global Hawk drone crash - Nikkei Asia

IC Oversight & Policy

Former CIA Director Brennan Subpoenaed as Target in DOJ Grand Conspiracy Probe With October Grand Jury Date

BLUF: Despite the October grand jury date, internal DOJ friction and acknowledged evidentiary gaps make indictment of Brennan in either probe unlikely by January 15, 2027.

Former CIA Director John Brennan received a subpoena on September 10 to testify October 15 before a federal grand jury in Fort Pierce, Florida, signed by then-prosecutor Joe diGenova before his resignation that same day, according to attorney Ken Wainstein's court declaration 123. Prosecutor Kurt Olsen told Wainstein the Fort Pierce case is a "far-reaching" conspiracy probe into whether Trump's civil rights were violated, in which Brennan is a "subject," while a separate, narrower Washington-based investigation names him a "target" over alleged false statements to Congress regarding the 2017 Russia intelligence assessment 12. DiGenova, in dueling remarks to the New York Post and Associated Press, cited both ethical concerns over indictments lacking evidence and internal disagreement over the investigation's pace 14. Wainstein sought a court order before Judge Jia Cobb to preserve DOJ records, including Signal communications, for a future vindictive-prosecution defense. The Justice Department called the request premature, and Cobb had not ruled as of Monday 12. U.S. Attorney Jason Reding Quiñones now leads the investigation with support from Main Justice 2.

Analyst Note: Indictment of Brennan in either track is unlikely before January 15, 2027, given the leadership vacuum from diGenova's resignation, unresolved preservation litigation before Judge Cobb, and evidentiary gaps diGenova himself acknowledged; Quiñones' assumption of the Fort Pierce probe with Main Justice support signals prosecutors need time to rebuild before the October 15 grand jury can plausibly move to charges. Confidence is moderate, reflecting consistent reporting on internal DOJ friction over pacing but no direct visibility into charging deliberations; reporting converges on a single court declaration rather than independent sourcing. DiGenova's contradictory public remarks suggest his exit reflects personal friction over resources rather than a substantive case collapse. Brennan's exposure has sharpened from one subpoena to confirmed dual-track jeopardy, and DOJ's "premature" framing of the preservation request signals prosecutors intend to control evidentiary timing themselves: a Cobb ruling granting preservation would make internal and Signal communications discoverable, constraining how aggressively Quiñones can pursue charges, while denial removes that friction entirely.

Sources:

1: Ex-CIA chief issued subpoena in Trump grand conspiracy investigation, lawyer says - NPR

2: Trump loyalist subpoenaed John Brennan before resignation last week - NBC News

3: Prosecutors subpoena ex-CIA Director John Brennan in 'grand conspiracy' probe - UPI

4: Former CIA Director John Brennan Subpoenaed Over Russiagate Conspiracy Against Trump - The Daily Caller

Prior Reporting - [The Grand Conspiracy ... Adrift on a Skiff](https://emptywheel.net/2026/09/14/the-grand-conspiracy-adrift-on-a-skiff/) (2026-09-14) - [Exclusive: Tense phone call and resignation upend Justice Department probe into Trump's top foes](https://www.cnn.com/2026/09/14/politics/todd-blanche-joe-digenova-trump-turmoil-call-resignation) (2026-09-14) - [Former CIA chief John Brennan subpoenaed in Florida "grand conspiracy" probe](https://www.cbsnews.com/news/cia-john-brennan-subpoenaed-grand-conspiracy-probe-trump/) (2026-09-14) - [Prosecutor who led 'grand conspiracy' probe of Trump targets resigns](https://www.nbcnews.com/politics/justice-department/prosecutor-led-grand-conspiracy-probe-trump-targets-resigns-charging-a-rcna597123) (2026-09-14)

COLLECTION GAPS

UNCLASSIFIED // OPEN SOURCE