
Vault 7
WikiLeaks published CIA hacking tools in 2017, exposing global cyber-surveillance capabilities and sparking security debates.
Sign in to bookmark, follow, and message the contributor.
Executive Summary
Vault 7 was WikiLeaks' largest-ever publication of classified CIA documents, revealing the agency's sophisticated cyber-espionage arsenal capable of compromising smartphones, smart TVs, and encrypted communications. The March 2017 release sparked fierce debate over national security versus transparency, the ethics of hoarding software vulnerabilities, and whether the disclosure helped adversaries more than the public. Former CIA contractor Joshua Schulte was later convicted for the leak, but questions persist about oversight of intelligence agencies' cyber-capabilities.
- 01.CIA maintained undisclosed vulnerability stockpile exceeding 500 zero-days across consumer platforms as of 2016.
- 02.Agency lost institutional control of entire cyber-arsenal; tools circulated among contractors with unknown scope of compromise.
- 03.Weeping Angel program converted Samsung smart TVs into covert listening devices while appearing powered off.
The Hidden Truth
What the headlines won't tell you
The Mainstream Narrative
On March 7, 2017, WikiLeaks began publishing approximately 8,761 classified CIA documents and files under the name "Vault 7," describing it as the largest intelligence publication in history. The documents detailed the CIA's Center for Cyber Intelligence hacking tools, techniques for compromising smartphones (iOS and Android), smart TVs, Windows, macOS, and Linux systems, and methods to bypass encryption on popular messaging apps like Signal and WhatsApp. Major news outlets reported that the tools allowed the agency to turn consumer devices into covert surveillance instruments. The U.S. government never formally authenticated the documents but tacitly acknowledged their legitimacy through aggressive leak investigations, ultimately charging former CIA software engineer Joshua Schulte, who was convicted in 2022 after two trials and sentenced to 40 years in prison.
Under-Reported Dimensions
The Vault 7 documents revealed that the CIA had accumulated a library of software vulnerabilities—so-called "zero-days"—without disclosing them to manufacturers, directly contradicting the Obama administration's 2014 Vulnerabilities Equities Process that supposedly balanced security and intelligence needs. Academic researchers at Harvard's Berkman Klein Center noted that hoarding exploits left millions of civilian devices vulnerable to criminal hackers and foreign adversaries who could discover the same flaws. The disclosures also showed extensive CIA collaboration with MI5's Joint Development Group and liaison relationships with other Five Eyes partners, suggesting coordinated international cyber-espionage programs with minimal legislative oversight. Furthermore, the documents indicated the CIA had lost control of its entire hacking arsenal by 2016—circulating among former government hackers and contractors—raising questions about internal security protocols that received scant congressional scrutiny.
Credible Dissenting Voices
Former NSA technical director William Binney and whistleblower Thomas Drake argued that Vault 7 exposed a surveillance apparatus operating beyond meaningful democratic accountability, with Drake telling The Intercept that the CIA's cyber-tools represented "the weaponization of code" without public debate. Cybersecurity expert Bruce Schneier wrote that the revelations demonstrated intelligence agencies prioritizing offense over defense, actively making the internet less secure for everyone. Conversely, former CIA officials like Michael Hayden defended the programs as essential intelligence-gathering in an era when adversaries and terrorists use encrypted communications, arguing WikiLeaks recklessly endangered operations and assets. Legal scholar Jack Goldsmith of Harvard Law School noted the disclosures created a paradox: they revealed troubling practices but through illegal means that undermined rule of law, leaving no clear heroes in the controversy.
Follow the Money
The CIA's cyber-programs represented billions in classified "black budget" spending, with the agency's Science and Technology Directorate receiving substantial funding increases post-9/11 to develop offensive cyber-capabilities. Defense contractors including Raytheon, Booz Allen Hamilton, and SAIC held lucrative contracts supporting the Center for Cyber Intelligence, creating a revolving door where former agency personnel commanded high salaries in the private sector. Joshua Schulte himself had worked as a contractor before becoming a full CIA employee, illustrating how the intelligence-industrial complex operated. After Vault 7, cybersecurity firms like FireEye and CrowdStrike saw increased demand for services protecting against the newly-public CIA techniques, while zero-day brokers faced market disruption as disclosed vulnerabilities were patched. Politically, the revelations bolstered anti-surveillance advocates' calls for intelligence reform, though congressional oversight committees largely defended existing programs, with funding for cyber-operations continuing to grow in subsequent National Intelligence Program budgets.
Open Questions
How many of the disclosed CIA exploits had already been discovered independently by foreign intelligence services or criminal organizations before WikiLeaks published them? What specific oversight mechanisms exist to prevent intelligence agencies from stockpiling vulnerabilities that endanger civilian infrastructure, and are they effective? Did the FBI and CIA adequately investigate how Schulte allegedly exfiltrated thousands of classified files despite security protocols, and have systemic insider-threat vulnerabilities been addressed? What legal frameworks govern intelligence agencies' development of cyber-weapons, and do current statutes provide sufficient democratic accountability for programs that affect global digital security? Why did it take two trials to convict Schulte, and what role did classified evidence play in preventing full public understanding of the leak's circumstances and motivations?
Case Timeline
- 2013COURT RECORDJoshua Schulte joins CIA as software engineer in Center for Cyber IntelligenceSchulte worked in the Operations Support Branch developing hacking tools that would later appear in the Vault 7 disclosures, giving him direct access to the entire cyber-arsenal.
- 2016COURT RECORDCIA discovers massive unauthorized access to classified cyber-tools; Schulte leaves agency amid disputesThe breach occurred after Schulte had contentious disputes with colleagues and management, with CIA security concluding the tools had been exfiltrated to an unauthorized location before his departure.
- 2017PRIMARY SOURCEWikiLeaks begins publishing Vault 7 documents on March 7, releasing 8,761 classified filesThe publication was titled "Year Zero" and represented the first installment of what WikiLeaks claimed were multiple series documenting CIA cyber-capabilities from 2013-2016.
- 2017COURT RECORDFBI raids Schulte's New York apartment in March; formal investigation beginsInvestigators seized computers and digital storage devices, later discovering encrypted communications and WikiLeaks-related search histories on Schulte's systems.
- 2018COURT RECORDSchulte indicted on child pornography and classified disclosure chargesProsecutors alleged the child pornography was discovered during the leak investigation and stored on an encrypted server Schulte maintained; he was charged separately for both matters.
- 2020COURT RECORDFirst trial on leak charges ends in hung jury on main countsJurors deadlocked on the most serious espionage counts while convicting on lesser charges related to lying to investigators and contempt of court.
- 2022COURT RECORDSchulte convicted in second trial on espionage and related chargesThe retrial jury found him guilty on eight counts of espionage, one count of obstruction, and one count of making false statements after prosecutors presented digital forensic evidence linking him to the leak.
- 2023COURT RECORDSchulte sentenced to 40 years in federal prisonJudge Jesse Furman described the disclosure as causing "almost incalculable damage to national security" and representing one of the most brazen CIA breaches in history.

U.S. Air Force Academy cadet Ben Charlebois competes in the pole vault competition during the Twilight Open at the Cadet Outdoor Track and Field Complex in Colorado Springs, Colo., May 5, 2023. The team concluded their regular season by rec
Key People
Organizations
Evidence Library
- leakDOC-V7AVault 7 Year Zero Documents (WikiLeaks Publication)
Collection of 8,761 classified CIA documents published March 7, 2017, detailing hacking tools, malware, and exploits targeting consumer devices. The documents themselves serve as primary evidence of CIA cyber-capabilities, though their authenticity was never formally confirmed by government statements, only tacit acknowledgment through prosecution.
- documentpartial redactionDOC-V7BObama Administration Vulnerabilities Equities Process (VEP) Policy (2014)
White House policy framework requiring intelligence agencies to weigh whether discovered software vulnerabilities should be disclosed to vendors or retained for intelligence purposes. Vault 7 documents revealed systematic CIA non-compliance with this disclosure process, contradicting stated policy commitments.
- court filingpartial redactionDOC-V7CUnited States v. Joshua Adam Schulte Superseding Indictment (S3 17 Cr. 548)
Department of Justice charging document alleging Schulte unlawfully transmitted classified national defense information to WikiLeaks and obstructed investigation. Includes specific counts under Espionage Act and details of alleged digital forensic evidence linking defendant to the breach.
- court filingpartial redactionDOC-V7DSchulte Second Trial Verdict and Sentencing Memorandum (2022-2023)
Court records documenting conviction on eight espionage counts and subsequent 40-year sentence. Government sentencing memorandum detailed national security damage assessment and characterized leak as unprecedented compromise of CIA cyber operations.
- documentDOC-V7EBerkman Klein Center Analysis: Vulnerabilities Equities Process and Vault 7
Harvard academic analysis examining how CIA's vulnerability hoarding practices revealed in Vault 7 undermined civilian cybersecurity. Provides scholarly assessment of policy tensions between intelligence collection and protecting critical infrastructure from criminal and foreign exploitation of same vulnerabilities.
- documentheavy redactionDOC-V7FCIA Center for Cyber Intelligence Internal Assessment (referenced in court proceedings)
CIA internal investigation concluded in 2016 that massive unauthorized access had occurred and entire hacking arsenal had been compromised. Referenced in court filings as establishing timeline and scope of breach before WikiLeaks publication.
Evidence Gallery
Sources
Trace the trail yourself
Investigation Network
This dossier does not end here.
- The 2024-2026 Deaths of American Aerospace and Nuclear ScientistsA cluster of aerospace and nuclear scientist deaths sparks questions about coincidence versus covert operations.Shared organization: FBI Counterintelligence Division
- The Crypto Wars and Encryption BackdoorsDecades-long battle over whether governments should mandate encryption backdoors for law enforcement accessShared subject: Cybersecurity, Surveillance
- Solar Winds and the SolarWinds HackRussian espionage campaign breached US agencies via software supply chain in massive intelligence failureShared subject: Cybersecurity, Espionage
- Pegasus Spyware and NSO GroupIsraeli cyberweapon sold to governments worldwide, used to surveil journalists, activists, and political opponents.Shared subject: Cybersecurity, Surveillance
- 2018Amnesty International researchers find Pegasus infections on devices of Saudi dissident Omar Abdulaziz, associate of Jamal Khashoggi.Pegasus Spyware and NSO Group
- 2019Attackers compromise SolarWinds build environment; begin code insertionSolar Winds and the SolarWinds Hack
- 2019WhatsApp sues NSO Group for exploiting call-handling vulnerabilities to infect 1,400 devices across 20 countries.Pegasus Spyware and NSO Group
- 2020EARN IT Act introduced in Congress, threatening encryption through liability frameworkThe Crypto Wars and Encryption Backdoors
- 2020-03Malicious Orion software updates distributed to ~18,000 customersSolar Winds and the SolarWinds Hack
- 2020-12-08FireEye publicly discloses breach of its own systemsSolar Winds and the SolarWinds Hack
Live Discussion
0 Perspectives
Add to the record. Be specific. Cite where you can.
If you're learning about this topic for the first time, these are the best places to continue — documented evidence and historical relationships are the guide.
Named in “Vault 7” and 1 other published dossier.
Shares 1 documented key player with “Vault 7”, including FBI Counterintelligence Division.
Read more dossiers like this
Get a quiet one-line bulletin when new investigative files are published. Bound to this dossier — useful for tracking follow-ups.
