DECLASSIFIED · RELEASED FOR PUBLIC REVIEW
OSA OFFICE OF SITUATIONAL AWARENESSRECORDS DIVISION · CITIZENBANNED.COM
FILE № OSA-114 CONFIRMED

CRYPTO AG

the CIA owned the company selling cipher machines to 120 governments
OWNED BYCIA and West German BND from 1970; CIA alone from 1993 to 2018
CUSTOMERSMore than 120 governments, including Iran, Argentina, Libya and the Vatican
REVEALEDFebruary 2020, by the Washington Post, ZDF and SRF
STATUSConfirmed by the CIA's own classified history of the operation

THE CLAIM

That the leading supplier of encryption equipment to the world's governments was secretly owned and controlled by American and West German intelligence, which weakened the machines so that traffic sent on them could be read.

THE THEORY, AS ITS PROPONENTS TELL IT

This file requires no steelmanning at all. The claim was regarded as paranoid speculation for decades and is now established by the intelligence services' own internal histories.

Crypto AG of Zug, Switzerland, was the pre-eminent commercial cipher manufacturer of the Cold War, and Swiss neutrality was central to its sales pitch. From 1970 it was owned in secret by the CIA and the West German BND, an arrangement codenamed Thesaurus and later Rubicon. Machines sold to designated countries were rigged so that their output could be broken with far less effort than the advertised key length implied.

The reach was extraordinary. At its height the operation covered communications from more than 120 governments. American analysts read Iranian traffic during the hostage crisis, Argentine traffic during the Falklands, and Libyan traffic after the 1986 Berlin discotheque bombing. The Vatican was a customer.

The point proponents draw is about the shape of real intelligence conspiracies. This one lasted fifty years, involved two national services and a commercial company, survived internal suspicions and at least one employee arrest, and stayed secret until a journalistic investigation obtained the classified histories in 2020.

WHAT IS KNOWN

The operation is confirmed by the CIA's own classified history and by a BND account, both obtained by the Washington Post, ZDF and SRF and reported in February 2020. The CIA history describes it as the intelligence coup of the century.

Suspicion long predated proof. Cryptographers had questioned Crypto AG's products for years, and the 1992 arrest of salesman Hans Buehler in Iran, and his subsequent release after the company paid a ransom it then tried to recover from him, sharpened those doubts without resolving them.

The BND sold its stake in 1993. The CIA continued alone until 2018, when the company was liquidated and its assets split. A Swiss parliamentary inquiry reported in 2020 that Swiss intelligence had known.

EVIDENCE FOR

  • The CIA's own internal history of the operation, obtained and reported in 2020, which has not been disputed by the Agency.
  • The corresponding BND account, independently corroborating the American one.
  • A Swiss parliamentary inquiry that confirmed domestic intelligence knowledge of the arrangement.
  • Decades of technical suspicion from cryptographers, now retrospectively vindicated.

EVIDENCE AGAINST (THE LIMITS)

  • Not every machine was rigged and not every customer was targeted. Countries the services considered friendly often received genuinely secure equipment, which is part of why the operation survived technical scrutiny for so long.
  • The Soviet Union and China were not significant customers and largely used their own systems, so the operation's reach, while vast, was not universal.
  • Claims that every commercial cryptographic product is similarly compromised do not follow from this and are not supported by evidence.

ASSESSMENT

Confirmed, recent, and probably the single most useful file in this cabinet for calibrating priors. For fifty years, the proposition that a major Western intelligence service secretly owned the world's leading cipher company and sold deliberately weakened equipment to allies and adversaries alike would have been dismissed as a conspiracy theory. It was true, it was documented internally the whole time, and it was exposed by journalists rather than by oversight. Read next to OSA-016, which is the same argument with different hardware, and OSA-015, which is what unbreakable traffic actually looks like when nobody owns the manufacturer.

WHAT WOULD CHANGE THE GRADE

  • CONFIRMED by the CIA's own classified history and a corresponding BND account, both obtained by journalists in 2020 and neither disputed since.
  • Open: the full customer and targeting list. Which of the 120-plus governments received rigged machines and which received sound ones has never been published.
  • The wider claim, that commercial cryptography is generally compromised, does not follow from this file. Rubicon worked precisely because it was an exception maintained with enormous care for fifty years.

FURTHER READING

  • Crypto AG · Wikipedia
  • Greg Miller, The intelligence coup of the century, Washington Post (2020)
  • Swiss parliamentary Control Delegation report on the Crypto AG affair (2020)

RELATED FILES IN THIS ARCHIVE

OSA RECORDS DIVISION RELATED: OSA-016 PRISM & THE SNOWDEN DISCLOSURES REV. 2026-08

The Office of Situational Awareness is an independent publication. Evidence grades are editorial assessments of the public record, not statements of new fact. Corrections welcome.