EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/cyberattack/operation-ironside-anom-sting
182/430

File EL-0249CriticalResolvedCyberattack / Government Surveillance Leak

Operation Ironside (AN0M)

Also filed as Operation Trojan Shield · AN0M Sting

Codename Trojan Shield

Operation Ironside was a joint Australian Federal Police and FBI sting operation that utilized a controlled, encrypted messaging application called AN0M. The platform served as a sophisticated honeypot, allowing law enforcement to monitor and intercept communications from international criminal organizations. The operation's details were revealed through unsealed court documents, exposing the depth of state surveillance capabilities.

  • #an0m
  • #encryption
  • #surveillance
  • #law-enforcement
  • #australia
  • #fbi
  • #honeypot
Notoriety8/10
Event
8 Jun 2021
Disclosed
8 Jun 2021
Target
International Criminal Networks
Actor
Australian Federal Police (AFP) / FBI Joint Taskforce
Scale
12K records
Status
Resolved

01Summary

The operation involved the deployment of AN0M, an encrypted messaging app designed to appear secure to criminal users. In reality, the platform was a government-run honeypot, meaning all communications were monitored and logged by the AFP and FBI. The system was engineered not to break encryption, but to silently blind-copy (BCC) every message sent to an AFP server, thereby circumventing the perceived security of the app. Over a period of three years, the operation successfully intercepted communications from over 12,000 devices across more than 100 countries. The intercepted data revealed extensive details on drug trafficking, murder plots, and corruption within criminal and even law enforcement circles.

02Background

The operation was conducted in the context of Australia's controversial Assistance and Access Act 2018 (TOLA Act). This legislation granted the Australian government significant powers to compel legitimate technology companies to build similar interception capabilities, a power that drew intense scrutiny regarding privacy rights and civil liberties. AN0M served as a real-world demonstration of the surveillance capabilities sought under this legal framework.

03Key revelations

  1. 01The existence of a government-controlled, encrypted messaging honeypot (AN0M).
  2. 02The scale of surveillance, involving 12,000+ devices and 27 million intercepted messages.
  3. 03The use of the operation to expose plots ranging from murder to drug trafficking, and internal corruption.

04Technical analysis

AN0M was not a traditional backdoor that compromised the encryption algorithm. Instead, it was a man-in-the-middle surveillance tool built into the application's infrastructure. The key technical mechanism was the silent blind-copying (BCC) of all message content to a dedicated law enforcement server. This allowed the agencies to gain full visibility into the content of communications without requiring the user to suspect monitoring.

Attack vector
None (The system was designed by the state to intercept communications).
Attack method
Honeypot Surveillance / Mass Interception
Initial access
User voluntary installation (via criminal networks)
Persistence
Server-side logging and monitoring
Exfiltration
Internal transfer to law enforcement databases
Tool / malware
AN0M
Malware type
Spyware / Honeypot

MITRE ATT&CK techniques

  • T1071.001

05Threat actor

This profile details a state-level surveillance operation rather than a typical hacker group. The operation represents a joint effort between law enforcement agencies (AFP and FBI) to gain intelligence on criminal networks using advanced technical capabilities.

Aliases

  • Operation Trojan Shield

MITRE groups

  • T1071.001

Known members

  • Reece Kershaw

Attribution sources

  • Australian Federal Police (AFP)
  • FBI
  • Media Reports

06Victims and impact

Countries affected

  • Australia
  • Global

07Data exposed

Data types

  • Text messages
  • Coordinates
  • Financial transaction details
  • Criminal plans

Notable documents

  • Unsealed Court Documents (Operation Ironside)
  • AFP/FBI Joint Taskforce Reports

08Timeline

  1. 2018-01-01Start of the AN0M honeypot operation (estimated)
  2. 2021-06-08Unsealing and public disclosure of Operation Ironside court documents

09Key figures

  • Reece KershawAFP Commissioner · Australian Federal PoliceAustralianSpoke publicly about the operation's findings.

10On the record

We were in the back pockets of organized crime. We saw everything.

Reece Kershaw, Referring to the comprehensive visibility gained through the AN0M honeypot.

11Reaction and fallout

Public reaction

The public reaction was marked by significant concern over government overreach and the erosion of digital privacy. Civil liberties groups immediately questioned the legality and scope of the surveillance powers demonstrated by the operation.

Political impact

The operation intensified the national debate surrounding digital privacy rights and the scope of state surveillance powers, particularly concerning the controversial TOLA Act. It fueled calls for legislative reform to limit law enforcement access to private communications.

Geopolitical consequences

The operation highlighted the global race between law enforcement agencies and encrypted communication technologies, setting a precedent for state-sponsored surveillance models in allied nations.

12Legal

The unsealed court documents provided evidence for ongoing criminal investigations, but the operation itself spurred legal challenges regarding the constitutional rights of digital communication and the necessity of such invasive surveillance tools.

Civil lawsuits

  • Challenges to the TOLA Act (General)
  • Privacy rights lawsuits against government surveillance

13Aftermath

Policy changes

  • Increased scrutiny of surveillance legislation (e.g., TOLA Act review)
  • Calls for judicial oversight of surveillance technology deployment

Regulatory changes

  • Potential amendments to national telecommunications and surveillance laws

Security improvements

  • Increased industry focus on end-to-end encryption standards
  • Development of decentralized communication protocols

14Significance and legacy

Significance

Operation Ironside is a landmark case study in modern state surveillance, demonstrating the technical feasibility and legal justification for creating 'backdoor' honeypots within encrypted platforms. It set a critical precedent for the balance between national security interests and fundamental digital privacy rights.

Legacy

The operation has contributed to a global discourse on 'privacy by design' and the limitations of state power in the digital age. It has accelerated the development of more robust, decentralized, and privacy-preserving communication technologies.

15Disclosure and media

Authentication
Court Filing/Joint Taskforce Release

Media partners

  • Australian Federal Police (AFP)
  • FBI

Publishing organisations

  • Australian Federal Police (AFP)
  • FBI

16Field notes

  1. 01The operation monitored communications across 100+ countries, demonstrating global reach.
  2. 02The core mechanism was not breaking encryption, but rather intercepting messages via a controlled, compromised application layer.

17Resolution

The operation's findings were integrated into ongoing criminal investigations, but the public disclosure led to significant policy and legal debates.

18Sources

Official documents

  • Unsealed Court Documents (Operation Ironside)
  • AFP/FBI Joint Taskforce Reports

References

  1. [1]AFP/FBI Joint Taskforce
  2. [2]Australian Federal Police (AFP) Statements
  3. [3]Media Coverage of TOLA Act
Fact sheetEL-0249

Dates

Event
8 Jun 2021
Started
1 Jan 2018
Ended
8 Jun 2021
Discovered
8 Jun 2021
Disclosed
8 Jun 2021
Ongoing
No

Target

Organisation
International Criminal Networks
Type
Criminal Organization
Sector
Organized Crime
Country
Global

Actor

Name
Australian Federal Police (AFP) / FBI Joint Taskforce
Type
Intelligence Agency
Nationality
Australia / United States
Nation-state
Australia / United States
Affiliation
Australian Federal Police (AFP)
Motivation
Disruption of organized crime and criminal networks.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

Records
12,000
Volume
27 Million messages
Sensitivity
Top Secret
Published
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.