Latest
When a Client Thinks the Ghostwriter Used AIThe Clients Who Pay and VanishWhat an AI Detector Score on Your Manuscript Is WorthWhen Your Memoir Should Be a NovelWhat Belongs on a Copyright PageThe One-Hour Call Before I Quote Your BookThe Work You Would Never Have StartedWhen Your Own Memoir Sounds Like BraggingMonthly or Milestone: How Ghostwriting Gets BilledWhat It Costs to Fix an AI-Written ManuscriptThe Quotation Marks That Get Authors SuedThe Hugging Face AI Agent Attack: An Operations ReadingBehind the Book: The Mysterious Island, Neb’s SideHow to Organize Decades of Memories Into a MemoirWhy Rotten Tomatoes Sucks: The Score Does Not Mean What You ThinkWhy Amazon KDP Sucks: They Terminated My Account OvernightIngramSpark: How I Publish Now and WhyWhy Fiverr Sucks for Ghostwriting: The Buyer’s SideWhy eBay Sucks Now: A Seller’s Numbers and a Buyer’s WarningThe Ghost Story TraditionThe Gothic TraditionThe Christmas Ghost Story TraditionBooks to Give a WriterResurrection as a Narrative StructureThe Beach Read ArgumentWhy It’s a Wonderful Life Failed on ReleaseWhat to Read in SpringWhat to Read in SummerWhat to Read in OctoberHow Warner Bros. Dismantled a $17 Billion Cartoon EmpireThe Imaginary Scarcity TrapThe Graph That Goes Vertical Is Usually Somebody Else’sSubstack Is Not Collapsing. The Promise Was.The Disasters That Happen to Ordinary PeopleToba: The Winter That Almost Ended UsJay Stifflemire: Nothing Ever Gets Written DownGeorgie-Ann Getton: I Forgot I Had Free WillAI Detection Cannot Be Evidence, and Publishing Is Using It That WayAI Consciousness Left Philosophy and Entered the LaboratoryThe Office Block Where the Bedrooms AreThe Web Got Fenced: What AI Search Costs Small SitesBlack Tuesday: The Web Ring War Nobody Outside It NoticedWhat the AI Visibility Industry Sells, and What the Evidence SaysBlack Tuesday: The Original ring-master.net Page, 2000Behind the Book: Peacekeeper, The Dissolution WarsBehind the Book: Real World SurvivalBehind the Book: Publish Your BookBehind the Book: ReincarnationBehind the Book: Sell Your BooksBehind the Book: Selling on eBay
The Writing King Your Ethical Ghostwriter. Your Story, Done Right.

Crypto AG: The Company That Sold Spying as Security for Fifty Years

This entry is part 7 of 13 in the series Nothing Is Isolated
TL;DR: For more than half a century, governments around the world bought encryption machines from a respected Swiss company called Crypto AG to keep their secrets safe. The company was secretly owned by American and West German intelligence, and the machines were rigged so those agencies could read every message. More than a hundred countries paid good money to be spied on by the people selling them the lock. This is the seventh article in a series on attacks that beat isolation, and it is the oldest and purest example of the trap: the thing you buy to protect yourself belongs to the people you are protecting yourself from.
Series Navigation  (13 parts)

Imagine buying the best safe on the market. You research it, you pay a premium, you bolt it to the floor, and you put your most valuable things inside, confident that only you have the combination. Now imagine the company that built the safe was owned, in secret, by the exact people you were hiding those valuables from, and every safe they ever sold came with a hidden way in that only they knew about.

That is not a thought experiment. It is the true story of Crypto AG, and it ran for over fifty years. It is the pager attack again, decades earlier and without the explosives, and it is worth studying because it shows how old and how patient this trick really is.

What did Crypto AG sell, and to whom?

Crypto AG was a Swiss company that made encryption machines, the devices governments used to scramble their diplomatic and military messages so that anyone intercepting them would see only gibberish.

Switzerland’s reputation for neutrality and precision made a Swiss maker especially attractive. If you were a smaller nation that didn’t trust the Americans or the Soviets, a machine from neutral Switzerland felt like the safe choice.

The company was good at its job, and it sold to everyone. Over the decades, more than 120 countries used Crypto AG equipment: Iran, Egypt, Pakistan, Saudi Arabia, Italy, the military governments of Latin America, and many more. Embassies ran their traffic through these machines. Militaries trusted them with operational orders. For a huge share of the world’s governments outside the two superpowers, Crypto AG was how you kept a secret.

What none of those customers knew is that the company had been compromised from close to the beginning, and not by an outside attacker. It was compromised by its owners.

Who really owned Crypto AG?

The answer stayed hidden for decades. It was confirmed in 2020 by a trove of internal intelligence histories reported by the Washington Post and the German broadcaster ZDF: Crypto AG was secretly owned and run by the American CIA and the West German intelligence service, the BND. The operation went by several code names over the years. The BND called it Rubicon. The CIA called it Minerva. Earlier it was Thesaurus.

The arrangement traces back to a quiet deal in the late 1940s between the company’s founder, a Swedish businessman named Boris Hagelin, and American intelligence. Hagelin agreed to build hidden weaknesses into his machines, weaknesses invisible to anyone who didn’t know to look, that American code-breakers could exploit and his foreign customers could not.

By 1970 the CIA and BND had moved from that informal understanding to outright ownership, buying the company through a web of shell corporations so nothing pointed back to Washington or Bonn. The company was, in every legal sense that mattered, a front. Its engineers designed real machines, its salespeople made real sales, and its customers received real products. The only thing wrong with any of it was that the encryption had been deliberately weakened in ways only the owners could exploit.

The details of the split read like fiction. The two agencies divided the company’s profits each year, and by one account the BND handled the accounting and delivered the CIA’s share as cash in an underground parking garage.

The Americans and Germans argued, the way partners do, over money and over how many allies it was acceptable to spy on. The Germans were reportedly uneasy about how freely the Americans read the traffic of NATO members like Spain, Greece, Turkey, and Italy. In 1993 the CIA bought out the German stake for around $17 million and ran the operation alone into the 2000s.

How did the rigged machines work?

The genius of the operation, and the reason it lasted so long, is that the agencies did not have to break the encryption. They owned it. They controlled the design.

Think about the difference. Breaking a code is hard, expensive work that you have to redo every time the target changes the code. But if you build the lock, you can put a master key mechanism in the blueprints, invisible to anyone who doesn’t know it’s there.

The Crypto AG machines were built with exactly that: weaknesses engineered into the encryption algorithms, subtle enough that a customer inspecting the machine or the math would see a strong, working cipher. To the buyer, the messages were secure. To the CIA and BND, who knew where the hidden weakness lived, the same messages fell open.

The payoff was staggering. At its height, intelligence from Crypto AG machines made up a large share of what American and German code-breakers produced. By some internal accounting, the compromised devices accounted for roughly 40 percent of the NSA’s machine-derived decryption at one point, and for the BND they supplied around 90 percent of its diplomatic intelligence reporting. One rigged company was carrying a huge fraction of two nations’ entire foreign intelligence take.

The agencies read Iran’s traffic during the 1979 hostage crisis. Country after country conducted its most sensitive business believing it was speaking in private, into a device that was carrying every word to Washington and Bonn.

And there was a telling moment that shows how carefully the secret was guarded. At one point an engineer at the company, not fully in on the operation, improved the algorithms and produced a batch of machines with genuinely strong encryption. Those machines had to be quietly bought back and destroyed, because the owners could not allow properly secure devices to reach the market. The product was never allowed to be as good as it looked.

What did the spying make possible?

It’s easy to read a story like this as a clever caper, spies outwitting other spies, no real victims. The record is darker than that.

Among the countries running their traffic through rigged Crypto AG machines were the military governments of Latin America during the years of Operation Condor, a coordinated campaign of repression, disappearance, and killing carried out by regimes in Chile, Argentina, Uruguay, and their neighbors. Declassified records show the United States was reading those governments’ communications as they conducted that campaign.

What Washington knew, when it knew it, and what it did or failed to do with the knowledge is a heavy question historians are still working through. I raise it only to make one point clear: this was never a victimless game. Real people lived and died inside the traffic those machines were carrying.

That is worth holding onto when the supply chain attacks later in this series arrive wearing the bloodless language of software. A poisoned update or a backdoored device is described in terms of records accessed and systems compromised, but the systems run real hospitals, real power, real lives. Crypto AG is the reminder that a compromised supplier is not an abstraction. It reaches all the way down to the people the traffic is about.

Why does a Cold War spy operation belong in this series?

Because it is the clearest, longest-running proof of the single idea this whole series is built on: when the thing you trust to protect you is controlled by your adversary, no amount of care with that thing can save you.

Every Crypto AG customer did the responsible thing. They recognized that their communications needed protection, and they went out and bought protection from a reputable, neutral supplier. That is exactly the instinct that led Iran to air-gap Natanz and led Hezbollah to switch to pagers. And it failed for exactly the same reason. The defense was sound against the threat they imagined, an outsider intercepting scrambled messages, and useless against the threat they never considered, that the supplier itself was the adversary.

I keep coming back to a hard truth from thirty-three years around these systems. You can inspect a product all you like, and inspection only tells you whether the product does what it claims. It cannot tell you who else the product answers to.

A Crypto AG machine encrypted your messages exactly as advertised. It also decrypted them for someone else, and nothing a customer could examine would reveal that second job. The betrayal lived in the design, placed there by the people you paid, and the people you paid were the last people you would think to suspect.

The modern versions of this are all around us, and they don’t require a front company. They require a supplier who can be pressured, a piece of software with a hidden function, a device that phones home to somewhere you didn’t authorize. Crypto AG is the ancestor of every one of them, and its lesson is the same one the pager attack wrote in blood: trust in a supplier is not a small risk to manage at the edges. It is the whole game.

The next article goes back to a USB drive in a parking lot and the breach that created the U.S. military’s cyber force. For the wider view, the cybersecurity hub collects the rest of my work on this.

Frequently Asked Questions

What was Crypto AG?
Crypto AG was a Swiss company that made encryption machines used by governments around the world to protect their diplomatic and military communications. Its Swiss neutrality made it especially attractive to countries that trusted neither superpower. More than 120 nations bought its equipment over the decades, including Iran, Egypt, Pakistan, Saudi Arabia, and the military regimes of Latin America.
Which intelligence agencies were behind Crypto AG?
The company was secretly owned and operated by the American CIA and the West German intelligence service, the BND, an operation known by the code names Rubicon, Minerva, and earlier Thesaurus. The arrangement dated to the late 1940s and became direct ownership around 1970, held through shell companies. In 1993 the CIA bought out the German stake and ran it alone into the 2000s. It was confirmed publicly in 2020 by the Washington Post and German broadcaster ZDF.
How did the Crypto AG machines let the CIA spy?
The agencies did not break the encryption; they controlled the design of the machines. Weaknesses were deliberately engineered into the encryption algorithms, subtle enough that a customer would see a strong, working cipher. Anyone who knew where the hidden weakness was, meaning the CIA and BND, could read the messages, while the customer believed they were secure.
Which countries were spied on through Crypto AG?
More than 120 countries used the equipment and were potential targets. Documented examples include Iran, whose traffic was read during the 1979 hostage crisis, along with Egypt, Pakistan, Saudi Arabia, Italy, and the Latin American military governments. The operation also read the communications of some NATO allies, a habit that caused friction between the American and German partners.
Why is Crypto AG relevant to modern supply chain security?
It is the oldest and clearest example of a supply chain attack: the supplier itself was the adversary. Customers did the responsible thing by buying protection from a reputable, neutral vendor, and it failed because the vendor was controlled by the very people they were guarding against. That is the same structure as the Hezbollah pager attack and modern software supply chain compromises, without any need for explosives.
Could a customer have detected the Crypto AG backdoor?
Almost certainly not through ordinary means. The machines encrypted messages exactly as advertised, so inspection would confirm the product worked. Inspection tells you whether a product does what it claims, not who else it answers to. The weakness was engineered into the design by the owners, hidden from the customers who paid for the devices.
What happened when Crypto AG made secure machines by accident?
At one point an engineer who was not fully aware of the operation strengthened the algorithms and produced a batch of machines with genuinely strong encryption. Those machines had to be quietly bought back and destroyed, because the owners could not allow properly secure devices to reach the market. The product was never permitted to be as good as it appeared.

Continue the Series

1. The Morris Worm |
2. Stuxnet: The History |
3. Stuxnet: Crossing the Air Gap |
4. Stuxnet: The Aftermath |
5. The Pager Attack |
6. The Pager Supply Chain |
7. Crypto AG |
8. Agent.btz |
9. NotPetya |
10. SolarWinds |
11. The Target Breach |
12. The XZ Backdoor |
13. The Line to AI

📝 Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.

0 comments

No comments yet. Yours can be the first.

Was this useful?

Leave a comment