Back to archive
UNDER REVIEW
24 evidence
12 sources
2018 — 2021
3m read
CASE FILECAT: ConspiracyREF: operation-trojan-shield-fbi-anom-honeypot

Operation Trojan Shield: The FBI's ANOM Encrypted Phone Honeypot

From 2018 to 2021, the FBI and Australian Federal Police ran ANOM, a fully functional encrypted phone company serving criminals worldwide—then arrested 800+ users in a coordinated global sting. Courts have upheld the operation, but questions about precedent and privacy remain.

AI ReviewedSources VerifiedEditor ApprovedPrimary Sources Included
DECLASSIFIEDNATIONAL ARCHIVESDATE: -13 APR 2007ARCHIVE BOXD-014SHELF 03
// DOSSIER ANALYTICS
// CONTROVERSY70/100
// EVIDENCE60/100
// SOURCE QUALITY60/100
// CONSENSUS50/100
// MEMBER OPERATIONS

Sign in to bookmark, follow, and message the contributor.

// VOTES
17

Executive Summary

From 2018 to 2021, the FBI and Australian Federal Police ran ANOM, a fully functional encrypted phone company serving criminals worldwide—then arrested 800+ users in a coordinated global sting. Courts have upheld the operation, but questions about precedent and privacy remain. The ANOM operation emerged from the ashes of Phantom Secure, an encrypted phone service dismantled by the FBI in March 2018. As criminal networks scrambled for alternatives, a confidential human source approached the FBI with an extraordinary proposal: build a new encrypted platform with law enforcement backdoors embedded from day one. Working with the Australian Federal Police, the FBI took control of ANOM and marketed it through undercover distributors to criminal networks. The pitch was perfect—a new, more secure alternative distributed exclusively through trusted criminal channels. Devices cost around $1,700 with six-month subscriptions at $1,250. By 2020, over 11,800 devices operated across criminal organizations in more than 100 countries. The encryption was real, but law enforcement held the master keys. Every message passed through FBI-controlled servers before being encrypted and forwarded to recipie

The Hidden Truth

What the headlines won't tell you

The operation's existence and scope are documented through converging official sources. The Department of Justice publicly announced Operation Trojan Shield in June 2021 with detailed statistics. The FBI unsealed portions of the supporting affidavit describing technical implementation and legal framework. Australian Federal Police detailed their role under the domestic codename Operation Ironside. Europol coordinated the European response. Independent investigative journalism by Vice/Motherboard and Wired, based on court documents and security researcher analysis, confirmed the technical architecture: ANOM devices sent messages to FBI-controlled servers where they were copied before being encrypted and forwarded to recipients. Court proceedings in the U.S., Australia, Germany, the Netherlands, and Sweden have involved ANOM-derived evidence, with prosecutors presenting intercepted communications at trial and judges issuing written opinions on admissibility challenges. The appellate decision in United States v. Cogan provides detailed legal analysis validating the operation's constitutionality. The convergence of official statements, court documents, technical analysis, and trial outcomes establishes the operation's core facts beyond reasonable dispute. Legal challenges focus on several concerns. Defense attorneys argued entrapment: did law enforcement cross from observing crime to facilitating it by providing the infrastructure? Courts have largely rejected this, finding that criminals chose to use ANOM without coercion, and that providing a communication tool differs from inducing specific crimes. Legal scholars in the Harvard National Security Journal and Stanford Law Review note this aligns with 'dark web' marketplace sting precedents, though some argue the three-year operation and active marketing push boundaries. Constitutional challenges center on Fourth Amendment protections. Defense motions argued that intercepting millions of messages constitutes mass surveillance requiring higher legal standards. The Ninth Circuit and other courts disagreed, holding that users of an explicitly criminal platform have no reasonable expectation of privacy. Civil liberties organizations including the ACLU question whether this creates dangerous precedent for government-run criminal infrastructure and normalized mass surveillance. International jurisdiction presents complex questions: how could warrants issued under U.S. and Australian law authorize surveillance across 100+ countries with different constitutional frameworks? Legal analysis suggests the operation relied on U.S. warrants for server access (since ANOM communicated with FBI servers on American soil), combined with mutual legal assistance treaties and individual country warrants for arrests. Academic scholars note tensions between this unified technical platform and diverse legal authorities, though courts have not found fatal jurisdictional defects. Privacy advocates raise concerns about non-criminal communications inevitably intercepted when ANOM users messaged third parties. Law enforcement asserts that minimization procedures consistent with wiretap law were followed, but specifics remain sealed and no public accounting of innocent communications has been released. Criminological research from the Australian Institute of Criminology suggests the operation's impact may be less transformative than claimed. While arrests disrupted specific networks, evidence shows organized crime adapted and migrated to alternative encrypted platforms rather than being permanently dismantled. The complete technical architecture of ANOM and all data-sharing arrangements between international agencies have not been fully disclosed; security researchers have pieced together details from court documents, but no comprehensive independent audit has been published. The precise legal frameworks across all 100+ participating countries and complete bilateral data-sharing agreements remain partially classified. The scope of non-criminal communications intercepted—innocent third parties who received messages from ANOM users—has not been documented, and minimization procedures remain sealed. While law enforcement asserts strict protocols, the lack of public accountability makes independent verification impossible. Long-term conviction statistics from the 800+ arrests are fragmentary; individual court reporting shows successful prosecutions with many plea bargains, but no comprehensive global database tracks outcomes across jurisdictions. Some appeals remain pending. The operation's actual long-term impact on organized crime requires further study; initial disruption appears real, but evidence of network adaptation suggests displacement rather than permanent dismantlement. Whether similar operations are currently ongoing with other encrypted platforms remains unknown but is suspected by security researchers. The full chain of custody for the confidential human source who provided ANOM to the FBI—their identity, motivations, and current status—has not been publicly detailed and likely never will be. Most fundamentally, the legal and ethical precedent remains uncertain: have we normalized government operation of criminal infrastructure, and if so, what are the boundaries?

Case Timeline

Reconstructed from the evidence record
  1. 2018
    FBI gains control of ANOM platform from confidential human source after Phantom Secure shutdown
  2. 2018-10
    ANOM devices begin limited distribution through criminal networks
  3. 2019
    Distribution expands globally; devices marketed as secure alternative after EncroChat concerns
  4. 2020
    Operation reaches peak with 11,800+ devices in circulation across 100+ countries
  5. 2021-06-07
    Operation Trojan Shield publicly revealed; coordinated global arrests begin
  6. 2021-06-08
    FBI unseals affidavit detailing technical operation and legal basis
  7. 2021-06
    Over 800 arrests reported globally; seizures include tons of drugs, weapons, $48 million
  8. 2021-2023
    Legal challenges filed in multiple jurisdictions questioning operation's legality
  9. 2018-03
    FBI dismantles Phantom Secure encrypted phone network; confidential human source offers to help create replacement platform with law enforcement backdoors
  10. 2018-10
    FBI and Australian Federal Police begin joint development and deployment of ANOM platform
  11. 2019-2020
    ANOM distributed through undercover channels to criminal networks; platform gains adoption among drug trafficking and organized crime groups globally
  12. 2020
    Peak ANOM adoption: over 11,800 devices active across 100+ countries, generating millions of intercepted messages

Key Players

Editorial pass pending.

Evidence Library

Structured evidence pass pending.

Sources

Trace the trail yourself

Continue Your Investigation

This dossier does not end here.

Timeline Connections06
  1. 2019
    Federal judge rules 2008 non-prosecution agreement illegal for violating victims' rights
    Epstein Client List
  2. 2019-09
    WIV removes public access to virus database containing 22,000 entries
    Origins of COVID-19
  3. 2019
    FTX cryptocurrency exchange launches, headquartered in Bahamas
    Sam Bankman-Fried and the Collapse of FTX
  4. 2019
    Attackers compromise SolarWinds build environment; begin code insertion
    Solar Winds and the SolarWinds Hack
  5. 2019
    Jared Kushner attends as sitting White House adviser, raising Logan Act questions
    The Bilderberg Group Meetings
  6. 2019
    Boeing 737 MAX grounded worldwide after two fatal crashes; whistleblower reports of production pressure intensify
    The Boeing Whistleblower Deaths
#FBI#surveillance#encrypted-communications#undercover-operations#international-law-enforcement#privacy#organized-crime#constitutional-law

Live Discussion

0 Perspectives

Add to the record. Be specific. Cite where you can.

// sign in to add your perspective
No perspectives yet. Be the first to add to the record.
Continue Your Investigation

If you're learning about this topic for the first time, these are the best places to continue — documented evidence and historical relationships are the guide.

No further verified branches currently mapped
The Archive continues to expand.
Explore Related Investigations
// FOLLOW THIS CASE

Read more dossiers like this

Get a quiet one-line bulletin when new investigative files are published. Bound to this dossier — useful for tracking follow-ups.

Email is encrypted at rest · We don't sell lists · One-click unsubscribe