CIA Fake Websites: Covert Comms with Informants
· Por Archivo Bélico editorial team
How the CIA used innocuous-looking websites as a covert channel with its informants, why the system failed, and what it cost between 2010 and 2013.
The CIA's fake websites were internet pages of entirely banal appearance — sports results, gardening forums, music fan sites or travel services — that in reality concealed a covert communication channel between agency officers and their informants abroad. The concept itself was old and classic: a dead drop, a point where two people leave and collect messages without ever meeting. What was new was the medium, a web server reachable from any computer in an internet café.
What is a digital dead drop
In the espionage tradition, the physical dead drop was a gap in a wall, a park bench or the underside of a car where a microfilm or a note was left. The digital equivalent transplants that logic onto the internet: the informant visits an apparently public page, types a specific sequence into an internal search box or form, and thereby opens a hidden interface where a coded message can be entered. To any casual visitor, and in theory to the internet provider as well, the traffic looks like that of an ordinary website.
The technical name for this family of tools in American intelligence jargon is covcom, short for covert communications. Its main advantage is that it avoids in-person meetings, which are the moment of greatest risk for an agent: there is no encounter to watch and no physical object to intercept.
The system's failure between 2010 and 2013
The existence of these platforms became public because they failed. Between 2010 and 2012, according to later journalistic investigations, CIA informant networks were dismantled in Iran and in China. A 2018 Foreign Policy report and a 2018 Yahoo News investigation described a web-based communication system, originally designed for lower-risk settings such as the Middle East, that had been reused in countries with far more capable counterintelligence services.
In 2022, the organisation Citizen Lab, together with Reuters, published a technical analysis of a set of more than 300 domains that shared highly recognisable patterns: adjacent blocks of IP addresses, repeated design templates and near-identical URL structures. That uniformity made the network enumerable: once one site was found, it was possible to locate the others and, from there, to identify who was visiting them from particular countries.
Why it is a design flaw, not the failure of a single officer
The case is cited in security literature as an example of a structural error. Iranian and Chinese counterintelligence services did not need to infiltrate anyone: traffic analysis and metadata correlation were enough. Reuters documented in 2022 the case of Gholamreza Hosseini, an Iranian who described how he was arrested after using one of these portals. The total numbers of people detained or executed have not been independently confirmed, and published estimates vary.
What patterns gave the network away
- Domains registered in blocks and hosted on consecutive IP ranges.
- Visual templates and source code reused across sites with no apparent thematic link.
- URL structures with identical parameters on supposedly unrelated websites.
- Scant genuine traffic and no credible history in search engines or web archives.
- Shallow content, with no sustained updates or real community behind it.
The difference from the traditional dead drop is one of kind, not just of medium. The classic version was a gap in a wall, a bench or a vehicle; its digital version is an ordinary-looking website. The risk with the first was physical surveillance of the drop point; with the second, it is traffic and metadata analysis. The physical dead drop barely scaled — one point per contact — whereas the digital one scales easily, and that is precisely the problem: reusing the same infrastructure for many contacts allows them to be linked to one another. Finally, the trace of a physical handover is fleeting if carried out well, whereas on the internet the records remain in networks and archives for years.
Consequences and reforms
The CIA has publicly acknowledged, through statements by former officials reported in the press, that sources were lost during this period. In 2021, an internal cable from the Counterintelligence Center sent to all stations — revealed by The New York Times — warned of the number of informants captured or neutralised in various countries and called for tighter operational security in recruiting and handling sources. The specifics of current systems are not public, and any claim about them belongs to the realm of speculation.
Preguntas frecuentes
- What were the CIA's fake websites?
- Ordinary-looking websites — about sports, leisure, travel — that concealed a messaging interface used by informants to communicate with the agency without in-person meetings.
- How were they discovered?
- Through 2018 journalistic investigations by Foreign Policy and Yahoo News, and through a 2022 technical analysis by Citizen Lab and Reuters that identified hundreds of domains with common hosting and design patterns.
- Why did the system fail?
- Because the sites were too similar to one another and were reused in countries with highly capable counterintelligence services: finding one was enough to enumerate the rest and monitor their visitors.
Fuentes y referencias
- Citizen Lab, «Statement on the fatal flaws found in a defunct CIA covert communications system» (2022)
- Reuters, «America's Throwaway Spies» (2022)
- Foreign Policy, «Botched CIA Communications System Helped Blow Cover of Chinese Agents» (2018)
- Yahoo News, «The CIA's communications suffered a catastrophic compromise» (2018)
- The New York Times, «Captured, Killed or Compromised: C.I.A. Admits to Losing Dozens of Informants» (2021)