Intelligence

Crypto AG: the CIA, the BND and Operation Rubicon

· By Archivo Bélico Editorial Team

Operation Rubicon secretly turned a trusted Swiss encryption company into a major intelligence source for the United States and West Germany.

Crypto AG and Operation Rubicon: a hidden window into encrypted traffic

For decades, governments trusted Crypto AG machines with diplomatic and military communications. Records disclosed in 2020 and a Swiss parliamentary inquiry confirmed that the CIA and West Germany’s BND secretly purchased the company in 1970. The programme—first Thesaurus, later Rubicon—gave them access to messages customers believed were secure.

From a neutral supplier to covert ownership

Boris Hagelin built Crypto AG’s reputation from Switzerland, whose neutrality added commercial credibility. The CIA and BND acquired the firm through intermediaries in June 1970. Ownership remained hidden from customers and most staff. The BND withdrew in 1993; the CIA retained control until the assets were sold and reorganised in 2018.

How the intelligence advantage worked

The owners influenced selected designs so that systems were vulnerable to analysts who understood their hidden weaknesses. There was no single master key and not every customer received the same equipment. Rubicon combined manipulated products, privileged cryptographic knowledge and a global sales network.

Customers and limits

Crypto AG sold equipment to more than one hundred states, including Iran, India, Pakistan and several Latin American governments. The Soviet Union and China were not major customers. That distinction matters: Rubicon was extraordinarily productive, but it did not give Washington access to every encrypted government message.

Switzerland and political oversight

A Swiss parliamentary investigation found that intelligence officials knew about and benefited from the arrangement while the Federal Council was not formally informed until 2019. It identified political co-responsibility and weak oversight. Swiss neutrality had functioned not merely as a setting, but as part of the company’s credibility.

Operation Condor and human-rights questions

Documents collected by the National Security Archive show that South American regimes associated with Operation Condor used Crypto AG equipment. The resulting access raised a profound question about what US agencies knew of repression and abuse. Evidence establishes visibility into communications, but does not by itself prove a direct causal role in every crime.

The 2020 disclosure and its legacy

The Washington Post, ZDF and SRF exposed the operation in February 2020 using internal histories and other records. Rubicon remains a warning that supply-chain trust can matter as much as mathematical strength—and that intelligence history must distinguish documented ownership, reconstructed operations and inferred consequences.

Frequently asked questions

Did the CIA own Crypto AG?
Yes. The CIA and BND secretly acquired it in 1970. West Germany withdrew in 1993, while US control continued afterwards.
Were all Crypto AG machines compromised?
The evidence does not support that claim. Products and customers differed, and selected systems were deliberately weakened.
When was Operation Rubicon revealed?
The principal public disclosure came in February 2020, followed by a Swiss parliamentary investigation.

Sources and references

  • Swiss Parliament, GPDel Crypto AG inquiry (2020): https://www.parlament.ch/press-releases/Pages/mm-gpdel-2020-11-10.aspx?lang=1031
  • The Washington Post, The intelligence coup of the century (2020): https://www.washingtonpost.com/graphics/2020/world/national-security/cia-crypto-encryption-machines-espionage/
  • National Security Archive, CIA Minerva and Operation Condor: https://nsarchive.gwu.edu/briefing-book/chile-cyber-vault-intelligence-southern-cone/2020-02-11/cias-minerva-secret
  • Reuters, Swiss investigation into Crypto AG (2020): https://www.reuters.com/article/business/swiss-investigate-report-that-firm-helped-cia-break-codes-idUSL8N2AB59Q/