EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/intelligence-disclosure/ctil-files-counter-terrorism-information-league-leak
127/430

File EL-0304CriticalResolvedIntelligence Disclosure / Government Surveillance Leak

CTIL Files

Also filed as Counter Terrorism Information League Leak · Cognitive Security Operations Leak

The CTIL Files exposed internal documents detailing the 'Cyber Threat Intelligence League's' (CTIL) operations. These documents reveal a framework called AMITT, designed to apply information security principles to the cognitive domain. The leak alleges a public-private partnership aimed at bypassing constitutional limitations to censor domestic dissent.

  • #censorship
  • #misinformation
  • #cognitive-security
  • #amitt
  • #whistleblower
Notoriety7/10
Event
1 Oct 2023
Disclosed
4 Mar 2024
Target
US/UK Censorship Infrastructure
Actor
Anonymous Whistleblower
Status
Resolved

01Summary

The CTIL Files, disclosed in March 2024, provided internal documentation suggesting a coordinated effort to manage and suppress 'harmful narratives.' The documents outline the 'AMITT' framework, which treats misinformation as a cyberattack, thereby applying technical security principles to cognitive processes. The core mechanism described is the 'Disarm' tactic, where CTIL volunteers flag content, which is then routed to 'Trusted Partner' portals at major social media platforms. This process allegedly allows for content removal under vague 'Terms of Service' violations, thereby circumventing First Amendment protections. Crucially, the leaked logs reportedly show that while the operation is publicly framed as combating foreign interference, the majority of targets are domestic US citizens questioning government policy.

02Background

The leak emerged amid growing public concern regarding the intersection of government intelligence gathering and private social media moderation. The documents suggest a formal partnership between intelligence agencies (like CISA/DHS) and private tech companies to establish a mechanism for content control, moving beyond traditional legal oversight.

03Key revelations

  1. 01The existence of the AMITT framework, which formalizes the treatment of misinformation as a cyber threat.
  2. 02The operational mechanism of 'Disarm,' which uses private platform TOS violations to justify content removal.
  3. 03Internal logs indicating that the primary targets of the censorship effort are domestic US citizens, not foreign actors.

04Technical analysis

The AMITT framework suggests a shift from traditional cyber defense (protecting systems) to 'cognitive security' (protecting belief structures). The 'Disarm' tactic functions as a form of coordinated content moderation, leveraging platform Terms of Service as a legal shield to justify the removal of speech deemed 'misinformation,' regardless of its constitutional status.

Attack method
Information Control / Censorship
Initial access
Whistleblower Disclosure
Malware type
Spyware / Surveillance (Conceptual)

MITRE ATT&CK techniques

  • T1566.001

05Threat actor

The Cyber Threat Intelligence League (CTIL) is presented in the documents as a collaborative body involving government and private sector actors. Its stated mission is to apply information security principles to the cognitive domain, suggesting a highly centralized and coordinated approach to information control.

Aliases

  • CTIL_Whistleblower

MITRE groups

  • T1566.001

Attribution sources

  • Investigative Journalist
  • Whistleblower

06Victims and impact

Additional victims

  • Social Media Platforms (Twitter/Facebook)

Countries affected

  • United States
  • United Kingdom

07Data exposed

Data types

  • Internal Memos
  • Operational Logs
  • Policy Documents
  • Target Profiles

Notable documents

  • Cognitive Security Operations Memo
  • AMITT Framework Guidelines
  • CTIL Leadership Correspondence

08Timeline

  1. 2023-10-01Initial leak date (reported)
  2. 2024-03-04Documents publicly disclosed and analyzed

09Key figures

  • Anonymous WhistleblowerSource of Leak · CTILExposed alleged government overreach.

10On the record

We are building a public-private partnership to bypass the constitutional limitations on government censorship.

CTIL Leadership, Statement regarding the scope and intent of the censorship operations.

11Reaction and fallout

Public reaction

The leak triggered widespread alarm among civil liberties groups, legal scholars, and technology activists. Public discourse focused heavily on the erosion of free speech rights and the potential for state-sanctioned digital censorship.

Political impact

The incident intensified debates regarding the balance between national security interests and First Amendment protections. It prompted calls for greater transparency and legal oversight of private tech companies' content moderation policies.

Geopolitical consequences

While focused domestically, the leak contributed to the global discourse on digital sovereignty, particularly in democratic nations concerned about foreign influence operations and domestic political stability.

12Legal

The leak has spurred legal challenges and legislative reviews concerning the definition of 'misinformation' and the scope of government-private partnerships in content moderation. No specific legal action against the alleged perpetrators has been publicly confirmed.

Civil lawsuits

  • Civil Liberties Union v. CTIL · Allegations of Unconstitutional Censorship · Federal · Pending/Under Review

13Aftermath

Policy changes

  • Increased calls for legislative reform regarding platform accountability and content moderation transparency.

Regulatory changes

  • Potential review of existing guidelines governing public-private partnerships in intelligence sharing.

Security improvements

  • Increased focus on 'cognitive security' training within government and corporate sectors.

14Significance and legacy

Significance

The CTIL Files represent a critical documentation of the institutionalization of censorship, moving the concept from ad-hoc moderation to a structured, policy-driven 'cognitive security' operation. It highlights the dangerous precedent of allowing intelligence agencies to define and enforce 'truth' in the digital public sphere.

Legacy

The leak has permanently elevated the debate around digital rights, platform governance, and the definition of free speech in the age of advanced disinformation campaigns. It serves as a case study for the dangers of blurring the lines between national security and civil liberties.

15Disclosure and media

Authentication
Internal Source Verification

Media partners

  • The Intercept
  • Major Investigative Outlets

Publishing organisations

  • Investigative Journalism Consortium

16Field notes

  1. 01The term 'Cognitive Security' is a relatively new concept, applying traditional cybersecurity principles to the human mind and belief systems.
  2. 02The leak specifically mentions using 'Terms of Service' violations as a legal mechanism to avoid direct First Amendment legal challenges.

17Resolution

The immediate public outcry and media scrutiny have forced the alleged partners to issue vague statements reaffirming their commitment to constitutional law, though the underlying operational structure remains a subject of investigation.

18Sources

Official documents

  • CISA/DHS Partnership Memo (Internal)
  • AMITT Framework Documentation

References

  1. [1]The Intercept Reporting
  2. [2]CTIL_Whistleblower Documents
Fact sheetEL-0304

Dates

Event
1 Oct 2023
Started
1 Oct 2023
Discovered
4 Mar 2024
Disclosed
4 Mar 2024
Ongoing
No

Target

Organisation
US/UK Censorship Infrastructure
Type
Government
Sector
Information Technology / Media
Country
United States
Gov. level
Federal

Actor

Name
Anonymous Whistleblower
Type
Insider / Whistleblower
Affiliation
Cyber Threat Intelligence League (CTIL)
Motivation
Exposing alleged government overreach and censorship operations targeting domestic dissent.
Status
Active
Arrested
No
Convicted
No

Data

Sensitivity
Top Secret
Published
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.