☰Series Navigation (13 parts)
Imagine buying the best safe on the market. You research it, you pay a premium, you bolt it to the floor, and you put your most valuable things inside, confident that only you have the combination. Now imagine the company that built the safe was owned, in secret, by the exact people you were hiding those valuables from, and every safe they ever sold came with a hidden way in that only they knew about.
That is not a thought experiment. It is the true story of Crypto AG, and it ran for over fifty years. It is the pager attack again, decades earlier and without the explosives, and it is worth studying because it shows how old and how patient this trick really is.
What did Crypto AG sell, and to whom?
Crypto AG was a Swiss company that made encryption machines, the devices governments used to scramble their diplomatic and military messages so that anyone intercepting them would see only gibberish.
Switzerland’s reputation for neutrality and precision made a Swiss maker especially attractive. If you were a smaller nation that didn’t trust the Americans or the Soviets, a machine from neutral Switzerland felt like the safe choice.
The company was good at its job, and it sold to everyone. Over the decades, more than 120 countries used Crypto AG equipment: Iran, Egypt, Pakistan, Saudi Arabia, Italy, the military governments of Latin America, and many more. Embassies ran their traffic through these machines. Militaries trusted them with operational orders. For a huge share of the world’s governments outside the two superpowers, Crypto AG was how you kept a secret.
What none of those customers knew is that the company had been compromised from close to the beginning, and not by an outside attacker. It was compromised by its owners.
Who really owned Crypto AG?
The answer stayed hidden for decades. It was confirmed in 2020 by a trove of internal intelligence histories reported by the Washington Post and the German broadcaster ZDF: Crypto AG was secretly owned and run by the American CIA and the West German intelligence service, the BND. The operation went by several code names over the years. The BND called it Rubicon. The CIA called it Minerva. Earlier it was Thesaurus.
The arrangement traces back to a quiet deal in the late 1940s between the company’s founder, a Swedish businessman named Boris Hagelin, and American intelligence. Hagelin agreed to build hidden weaknesses into his machines, weaknesses invisible to anyone who didn’t know to look, that American code-breakers could exploit and his foreign customers could not.
By 1970 the CIA and BND had moved from that informal understanding to outright ownership, buying the company through a web of shell corporations so nothing pointed back to Washington or Bonn. The company was, in every legal sense that mattered, a front. Its engineers designed real machines, its salespeople made real sales, and its customers received real products. The only thing wrong with any of it was that the encryption had been deliberately weakened in ways only the owners could exploit.
The details of the split read like fiction. The two agencies divided the company’s profits each year, and by one account the BND handled the accounting and delivered the CIA’s share as cash in an underground parking garage.
The Americans and Germans argued, the way partners do, over money and over how many allies it was acceptable to spy on. The Germans were reportedly uneasy about how freely the Americans read the traffic of NATO members like Spain, Greece, Turkey, and Italy. In 1993 the CIA bought out the German stake for around $17 million and ran the operation alone into the 2000s.
How did the rigged machines work?
The genius of the operation, and the reason it lasted so long, is that the agencies did not have to break the encryption. They owned it. They controlled the design.
Think about the difference. Breaking a code is hard, expensive work that you have to redo every time the target changes the code. But if you build the lock, you can put a master key mechanism in the blueprints, invisible to anyone who doesn’t know it’s there.
The Crypto AG machines were built with exactly that: weaknesses engineered into the encryption algorithms, subtle enough that a customer inspecting the machine or the math would see a strong, working cipher. To the buyer, the messages were secure. To the CIA and BND, who knew where the hidden weakness lived, the same messages fell open.
The payoff was staggering. At its height, intelligence from Crypto AG machines made up a large share of what American and German code-breakers produced. By some internal accounting, the compromised devices accounted for roughly 40 percent of the NSA’s machine-derived decryption at one point, and for the BND they supplied around 90 percent of its diplomatic intelligence reporting. One rigged company was carrying a huge fraction of two nations’ entire foreign intelligence take.
The agencies read Iran’s traffic during the 1979 hostage crisis. Country after country conducted its most sensitive business believing it was speaking in private, into a device that was carrying every word to Washington and Bonn.
And there was a telling moment that shows how carefully the secret was guarded. At one point an engineer at the company, not fully in on the operation, improved the algorithms and produced a batch of machines with genuinely strong encryption. Those machines had to be quietly bought back and destroyed, because the owners could not allow properly secure devices to reach the market. The product was never allowed to be as good as it looked.
What did the spying make possible?
It’s easy to read a story like this as a clever caper, spies outwitting other spies, no real victims. The record is darker than that.
Among the countries running their traffic through rigged Crypto AG machines were the military governments of Latin America during the years of Operation Condor, a coordinated campaign of repression, disappearance, and killing carried out by regimes in Chile, Argentina, Uruguay, and their neighbors. Declassified records show the United States was reading those governments’ communications as they conducted that campaign.
What Washington knew, when it knew it, and what it did or failed to do with the knowledge is a heavy question historians are still working through. I raise it only to make one point clear: this was never a victimless game. Real people lived and died inside the traffic those machines were carrying.
That is worth holding onto when the supply chain attacks later in this series arrive wearing the bloodless language of software. A poisoned update or a backdoored device is described in terms of records accessed and systems compromised, but the systems run real hospitals, real power, real lives. Crypto AG is the reminder that a compromised supplier is not an abstraction. It reaches all the way down to the people the traffic is about.
Why does a Cold War spy operation belong in this series?
Because it is the clearest, longest-running proof of the single idea this whole series is built on: when the thing you trust to protect you is controlled by your adversary, no amount of care with that thing can save you.
Every Crypto AG customer did the responsible thing. They recognized that their communications needed protection, and they went out and bought protection from a reputable, neutral supplier. That is exactly the instinct that led Iran to air-gap Natanz and led Hezbollah to switch to pagers. And it failed for exactly the same reason. The defense was sound against the threat they imagined, an outsider intercepting scrambled messages, and useless against the threat they never considered, that the supplier itself was the adversary.
I keep coming back to a hard truth from thirty-three years around these systems. You can inspect a product all you like, and inspection only tells you whether the product does what it claims. It cannot tell you who else the product answers to.
A Crypto AG machine encrypted your messages exactly as advertised. It also decrypted them for someone else, and nothing a customer could examine would reveal that second job. The betrayal lived in the design, placed there by the people you paid, and the people you paid were the last people you would think to suspect.
The modern versions of this are all around us, and they don’t require a front company. They require a supplier who can be pressured, a piece of software with a hidden function, a device that phones home to somewhere you didn’t authorize. Crypto AG is the ancestor of every one of them, and its lesson is the same one the pager attack wrote in blood: trust in a supplier is not a small risk to manage at the edges. It is the whole game.
The next article goes back to a USB drive in a parking lot and the breach that created the U.S. military’s cyber force. For the wider view, the cybersecurity hub collects the rest of my work on this.
Frequently Asked Questions
Continue the Series
1. The Morris Worm |
2. Stuxnet: The History |
3. Stuxnet: Crossing the Air Gap |
4. Stuxnet: The Aftermath |
5. The Pager Attack |
6. The Pager Supply Chain |
7. Crypto AG |
8. Agent.btz |
9. NotPetya |
10. SolarWinds |
11. The Target Breach |
12. The XZ Backdoor |
13. The Line to AI
