{"id":4304,"date":"2018-06-25T16:09:10","date_gmt":"2018-06-25T16:09:10","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/29073\/The-NSAs-Hidden-Spy-Hubs-In-Eight-U.S.-Cities.html"},"modified":"2018-06-25T16:09:10","modified_gmt":"2018-06-25T16:09:10","slug":"the-nsas-hidden-spy-hubs-in-eight-u-s-cities","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\/","title":{"rendered":"The NSA&#8217;s Hidden Spy Hubs In Eight U.S. Cities"},"content":{"rendered":"<div data-reactid=\"203\" readability=\"40.797808219178\">\n<p><span data-shortcode-type=\"dropcap\" class=\"dropcap\">T<\/span><u class=\"project-y\">he secrets are<\/u> hidden behind fortified walls in cities across the United States, inside towering, windowless skyscrapers and fortress-like concrete structures that were built to withstand earthquakes and even nuclear attack. Thousands of people pass by the buildings each day and rarely give them a second glance, because their function is not publicly known. They are an integral part of one of the world\u2019s largest telecommunications networks \u2013 and they are also linked to a controversial National Security Agency surveillance program.<\/p>\n<p>Atlanta, Chicago, Dallas, Los Angeles, New York City, San Francisco, Seattle, and Washington, D.C. In each of these cities, The Intercept has identified an AT&amp;T facility containing networking equipment that transports large quantities of internet traffic across the United States and the world. A body of evidence \u2013 including classified NSA documents, public records, and interviews with several former AT&amp;T employees \u2013 indicates that the buildings are central to an NSA spying initiative that has for years monitored billions of emails, phone calls, and online chats passing across U.S. territory.<\/p>\n<p>The NSA considers AT&amp;T to be one of its most trusted partners and has lauded the company\u2019s \u201cextreme willingness to help.\u201d It is a collaboration that dates back decades. Little known, however, is that its scope is not restricted to AT&amp;T\u2019s customers. According to the NSA\u2019s <a href=\"https:\/\/theintercept.com\/document\/2018\/06\/25\/fairview-overview-with-notes\">documents<\/a>, it values AT&amp;T not only because it \u201chas access to information that transits the nation,\u201d but also because it maintains unique relationships with other phone and internet providers. The NSA exploits these relationships for surveillance purposes, commandeering AT&amp;T\u2019s massive infrastructure and using it as a platform to covertly tap into communications processed by other companies.<\/p>\n<\/div>\n<div class=\"ProjectY-Map\" data-reactid=\"204\">\n<div class=\"img-wrap align-bleed xtra-large-bleed width-auto ProjectY-Map--map section section--with-background\" data-reactid=\"254\"><img decoding=\"async\" class=\"ProjectY-Map--background aligncenter\" src=\"https:\/\/cdn01.theintercept.com\/static\/project-y\/map.png\" data-reactid=\"255\"\/><\/div>\n<\/div>\n<div data-reactid=\"256\" readability=\"201.73358770059\">\n<p>Much has previously been reported about the NSA\u2019s surveillance programs. But few details have been disclosed about the physical infrastructure that enables the spying. Last year, The Intercept <a href=\"https:\/\/theintercept.com\/2016\/11\/16\/the-nsas-spy-hub-in-new-york-hidden-in-plain-sight\/\">highlighted<\/a> a likely NSA facility in New York City\u2019s Lower Manhattan. Now, we are revealing for the first time a series of other buildings across the U.S. that appear to serve a similar function, as critical parts of one of the world\u2019s most powerful electronic eavesdropping systems, hidden in plain sight.<\/p>\n<p>\u201cIt\u2019s eye-opening and ominous the extent to which this is happening right here on American soil,\u201d said Elizabeth Goitein, co-director of the Liberty and National Security Program at the Brennan Center for Justice. \u201cIt puts a face on surveillance that we could never think of before in terms of actual buildings and actual facilities in our own cities, in our own backyards.\u201d<\/p>\n<p>There are hundreds of AT&amp;T-owned properties scattered across the U.S. The eight identified by The Intercept serve a specific function, processing AT&amp;T customers\u2019 data and also carrying large quantities of data from other internet providers. They are known as \u201cbackbone\u201d and \u201cpeering\u201d facilities.<\/p>\n<p class=\"alignnone\">While network operators would usually prefer to send data through their own networks, often a more direct and cost-efficient path is provided by other providers\u2019 infrastructure. If one network in a specific area of the country is overloaded with data traffic, another operator with capacity to spare can sell or exchange bandwidth, reducing the strain on the congested region. This exchange of traffic is called \u201cpeering\u201d and is an essential feature of the internet.<\/p>\n<p>Because of AT&amp;T\u2019s position as one of the U.S.\u2019s leading telecommunications companies, it has a large network that is frequently used by other providers to transport their customers\u2019 data. Companies that \u201cpeer\u201d with AT&amp;T include the American telecommunications giants Sprint, Cogent Communications, and Level 3, as well as foreign companies such as Sweden\u2019s Telia, India\u2019s Tata Communications, Italy\u2019s Telecom Italia, and Germany\u2019s Deutsche Telekom.<\/p>\n<p>AT&amp;T currently boasts 19,500 <a class=\"project-y\" data-tooltip=\"An access point that connects to the internet, located inside a facility that contains routers, servers, and other networking equipment.\">\u201cpoints of presence\u201d<\/a> in 149 countries where internet traffic is exchanged. But only eight of the company\u2019s facilities in the U.S. offer direct access to its \u201ccommon backbone\u201d \u2013 key data routes that carry vast amounts of emails, internet chats, social media updates, and internet browsing sessions. These eight locations are among the most important in AT&amp;T\u2019s global network. They are also highly valued by the NSA, documents indicate.<\/p>\n<p>The data exchange between AT&amp;T and other networks initially takes place outside AT&amp;T\u2019s control, sources said, at third-party data centers that are owned and operated by companies such as California\u2019s Equinix. But the data is then routed \u2013 in whole or in part \u2013 through the eight AT&amp;T buildings, where the NSA taps into it. By monitoring what it calls the \u201cpeering circuits\u201d at the eight sites, the spy agency can collect \u201cnot only AT&amp;T\u2019s data, they get all the data that\u2019s interchanged between AT&amp;T\u2019s network and other companies,\u201d according to Mark Klein, a former AT&amp;T technician who worked with the company for 22 years. It is an efficient point to conduct internet surveillance, Klein said, \u201cbecause the peering links, by the nature of the connections, are liable to carry everybody\u2019s traffic at one point or another during the day, or the week, or the year.\u201d<\/p>\n<p>Christopher Augustine, a spokesperson for the NSA, said in a statement that the agency could \u201cneither confirm nor deny its role in alleged classified intelligence activities.\u201d Augustine declined to answer questions about the AT&amp;T facilities, but said that the NSA \u201cconducts its foreign signals intelligence mission under the legal authorities established by Congress and is bound by both policy and law to protect U.S. persons\u2019 privacy and civil liberties.\u201d<\/p>\n<p>Jim Greer, an AT&amp;T spokesperson, said that AT&amp;T was \u201crequired by law to provide information to government and law enforcement entities by complying with court orders, subpoenas, lawful discovery requests, and other legal requirements.\u201d He added that the company provides \u201cvoluntary assistance to law enforcement when a person\u2019s life is in danger and in other immediate, emergency situations. In all cases, we ensure that requests for assistance are valid and that we act in compliance with the law.\u201d<\/p>\n<p>Dave Schaeffer, CEO of Cogent Communications, told The Intercept that he had no knowledge of the surveillance at the eight AT&amp;T buildings, but said he believed \u201cthe core premise that the NSA or some other agency would like to look at traffic \u2026 at an AT&amp;T facility.\u201d He said he suspected that the surveillance is likely carried out on \u201ca limited basis,\u201d due to technical and cost constraints. If the NSA were trying to \u201cubiquitously monitor\u201d data passing across AT&amp;T\u2019s networks, Schaeffer added, he would be \u201cextremely concerned.\u201d<\/p>\n<p>Sprint, Telia, Tata Communications, Telecom Italia, and Deutsche Telekom did not respond to requests for comment. CenturyLink, which owns Level 3, said it would not discuss \u201cmatters of national security.\u201d<\/p>\n<div class=\"img-wrap align-bleed xtra-large-bleed width-auto\" readability=\"7\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-194677\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/map-gifs-4-1529435205.gif?auto=compress%2Cformat&amp;q=90\" alt=\"map-gifs-4-1529435205\"\/><\/p>\n<p class=\"caption overlayed\">The maps The Intercept used to identify the internet surveillance hubs.<\/p>\n<p class=\"caption source pullright\">Maps: NSA\/AT&amp;T<\/p>\n<\/div>\n<p><span data-shortcode-type=\"dropcap\" class=\"dropcap\">T<\/span><u class=\"project-y\">he eight locations<\/u> are featured on a top-secret NSA map, which depicts U.S. facilities that the agency relies upon for one of its largest surveillance programs, code-named <a class=\"project-y\" data-tooltip=\"An NSA surveillance program that collects communications from AT&amp;T's networks.\">FAIRVIEW<\/a>. AT&amp;T is the only company involved in FAIRVIEW, which was first established in 1985, according to NSA documents, and involves tapping into international telecommunications cables, routers, and switches.<\/p>\n<p>In 2003, the NSA launched new internet mass surveillance methods, which were pioneered under the FAIRVIEW program. The methods were used by the agency to collect \u2013 within a few months \u2013 some 400 billion records about people\u2019s internet communications and activity, the New York Times <a href=\"https:\/\/www.nytimes.com\/2015\/08\/16\/us\/politics\/att-helped-nsa-spy-on-an-array-of-internet-traffic.html\">previously reported<\/a>. FAIRVIEW was also forwarding more than 1 million emails every day to a \u201ckeyword selection system\u201d at the NSA\u2019s Fort Meade headquarters.<\/p>\n<p>Central to the internet spying are eight \u201cpeering link router complex\u201d sites, which are pinpointed on the top-secret NSA map. The locations of the sites mirror maps of AT&amp;T\u2019s networks, obtained by The Intercept from public records, which show \u201cbackbone node with peering\u201d facilities in Atlanta, Chicago, Dallas, Los Angeles, New York City, San Francisco, Seattle, and Washington, D.C.<\/p>\n<p>One of the AT&amp;T maps contains unique codes individually identifying the addresses of the facilities in each of the cities.<\/p>\n<p>Among the pinpointed buildings, there is a nuclear blast-resistant, windowless facility in New York City\u2019s Hell\u2019s Kitchen neighborhood; in Washington, D.C., a fortress-like, concrete structure less than half a mile south of the U.S. Capitol; in Chicago, an earthquake-resistant skyscraper in the West Loop Gate area; in Atlanta, a 429-foot art deco structure in the heart of the city\u2019s downtown district; and in Dallas, a cube-like building with narrow windows and large vents on its exterior, located in the Old East district.<\/p>\n<p>Elsewhere, on the west coast of the U.S., there are three more facilities: in downtown Los Angeles, a striking concrete tower near the Walt Disney Concert Hall and the Staples Center, two blocks from the most important internet exchange in the region; in Seattle, a 15-story building with blacked-out windows and reinforced concrete foundations, near the city\u2019s waterfront; and in San Francisco\u2019s South of Market neighborhood, a building where it was previously claimed that the NSA was monitoring internet traffic from a secure room on the sixth floor.<\/p>\n<p>The peering sites \u2013 otherwise known in AT&amp;T parlance as <a class=\"project-y\" data-tooltip=\"Major AT&amp;T internet hubs.\">\u201cService Node Routing Complexes,\u201d<\/a> or SNRCs \u2013 were developed following the internet boom in the mid- to late 1990s. By March 2009, the NSA\u2019s documents say it was tapping into \u201cpeering circuits at the eight SNRCs.\u201d<\/p>\n<p>The facilities\u2019 purpose was to bolster AT&amp;T\u2019s network, improving its reliability and enabling future growth. They were developed under the leadership of an Iranian-American innovator and engineer named Hossein Eslambolchi, who was formerly AT&amp;T\u2019s chief technology officer and president of AT&amp;T Labs, a division of the company that focuses on research and development.<\/p>\n<p>Eslambolchi told The Intercept that the project to set up the facilities began after AT&amp;T asked him to help create \u201cthe largest internet protocol network in the world.\u201d He obliged and began implementing his network design by placing large Cisco routers inside former AT&amp;T phone switching facilities across the U.S. When planning the project, he said he divided AT&amp;T\u2019s network into different regions, \u201cand in every quadrant I will have what I will call an SNRC.\u201d<\/p>\n<\/p><\/div>\n<div data-reactid=\"263\" readability=\"194.31941881919\">\n<p>During his employment with AT&amp;T, Eslambolchi said he had to take a polygraph test, and he obtained a government security clearance. \u201cI was involved in very, very top, heavy-duty projects for a few of these three-letter agencies,\u201d he said, in an apparent reference to U.S. intelligence agencies. \u201cThey all loved me.\u201d<\/p>\n<p>He would not confirm or deny the exact locations of the eight peering sites identified by The Intercept or discuss the classified work he carried out while with the company. \u201cYou put a gun to my head,\u201d he said, \u201cI\u2019m not going to tell you.\u201d<\/p>\n<p>Other former AT&amp;T employees, however, were more forthcoming.<\/p>\n<p>A former senior member of AT&amp;T\u2019s technical staff, who spoke on condition of anonymity due to the sensitivity of the subject, confirmed with \u201c100 percent\u201d certainty the locations of six of the eight peering facilities identified by The Intercept. The source, citing direct knowledge of the facilities and their function, verified the addresses of the buildings in Atlanta, Dallas, Los Angeles, New York City, Seattle, and Washington, D.C.<\/p>\n<p>A second former AT&amp;T employee confirmed the locations of the remaining two sites, in Chicago and San Francisco. \u201cI worked with all of them,\u201d said Philip Long, who was employed by AT&amp;T for more than two decades as a technician servicing its networks. Long\u2019s work with AT&amp;T was carried out mostly in California, but he said his job required him to be in contact with the company\u2019s other facilities across the U.S. In about 2005, Long recalled, he received orders to move \u201cevery internet backbone circuit I had in northern California\u201d through the San Francisco AT&amp;T building identified by The Intercept as one of the eight NSA spy hubs. Long said that, at the time, he felt suspicious of the changes, because they were unusual and unnecessary. \u201cWe thought we were routing our circuits so that they could grab all the data,\u201d he said. \u201cWe thought it was the government listening.\u201d He retired from his job with AT&amp;T in 2014.<\/p>\n<p>A third former AT&amp;T employee reviewed The Intercept\u2019s research and said he believed it accurately identified all eight of the facilities. \u201cThe site data certainly seems correct,\u201d said Thomas Saunders, who worked as a data networking consultant for AT&amp;T in New York City between 1995 and 2004. \u201cThose nodes aren\u2019t going to move.\u201d<\/p>\n<div class=\"img-wrap align-bleed full-bleed width-auto\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-193722\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-5-1528987907.jpg?auto=compress%2Cformat&amp;q=90\" alt=\"building-5-1528987907\"\/><\/p>\n<p class=\"caption source pullright\">Photo: Henrik Moltke<\/p>\n<\/div>\n<p><span data-shortcode-type=\"dropcap\" class=\"dropcap\">A<\/span><u class=\"project-y\">n estimated 99 percent<\/u> of the world\u2019s intercontinental internet traffic is transported through hundreds of giant fiber optic cables hidden beneath the world\u2019s oceans. A large portion of the data and communications that pass across the cables is routed at one point through the U.S., partly because of the country\u2019s location \u2013 situated between Europe, the Middle East, and Asia \u2013 and partly because of the pre-eminence of American internet companies, which provide services to people globally.<\/p>\n<p>The NSA calls this predicament \u201chome field advantage\u201d \u2013 a kind of geographic good fortune. \u201cA target\u2019s phone call, email, or chat will take the cheapest path, not the physically most direct path,\u201d one agency document <a href=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/direct-path-1529876697.png?auto=compress%2Cformat&amp;q=90\">explains<\/a>. \u201cYour target\u2019s communications could easily be flowing into and through the U.S.\u201d<\/p>\n<p>Once the internet traffic arrives on U.S. soil, it is processed by American companies. And that is why, for the NSA, AT&amp;T is so indispensable. The company claims it has one of the world\u2019s most powerful networks, the largest of its kind in the U.S. AT&amp;T routinely handles masses of emails, phone calls, and internet chats. As of March 2018, some 197 petabytes of data \u2013 the equivalent of more than 49 trillion pages of text, or 60 billion average-sized mp3 files \u2013 traveled across its networks every business day.<\/p>\n<p>The NSA documents, which come from the trove provided to The Intercept by the whistleblower Edward Snowden, describe AT&amp;T as having been \u201caggressively involved\u201d in aiding the agency\u2019s surveillance programs. One example of this appears to have taken place at the eight facilities under a classified initiative called <a class=\"project-y\" data-tooltip=\"An NSA surveillance operation that monitors internet data inside AT&amp;T facilities.\">SAGUARO<\/a>.<\/p>\n<p>As part of SAGUARO, AT&amp;T developed a strategy to help the NSA electronically eavesdrop on internet data from the \u201cpeering circuits\u201d at the eight sites, which were said to connect to the \u201ccommon backbone,\u201d major data routes carrying internet traffic.<\/p>\n<p>The company worked with the NSA to rank communications flowing through its networks on the basis of intelligence value, prioritizing data depending on which country it was derived from, according to a top-secret <a href=\"https:\/\/theintercept.com\/document\/2018\/06\/25\/sso-dictionary-relevant-entries\">agency document<\/a>.<\/p>\n<div class=\"img-wrap align-center width-fixed\"><img decoding=\"async\" class=\"aligncenter size-article-large wp-image-192005\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/diagram-5-1528310650.jpg?auto=compress%2Cformat&amp;q=90&amp;w=1000&amp;h=758\" alt=\"diagram-5-1528310650\"\/><\/p>\n<p class=\"caption source\">Graphic: NSA<\/p>\n<\/div>\n<p>NSA <a href=\"https:\/\/theintercept.com\/document\/2016\/11\/16\/fairview-dataflow-charts-apr-2012\/\">diagrams<\/a> reveal that after it collects data from AT&amp;T\u2019s \u201caccess links\u201d and \u201cpeering partners,\u201d it is sent to a \u201ccentralized processing facility\u201d code-named <a class=\"project-y\" data-tooltip=\"A New Jersey facility where AT&amp;T data is processed and sent to the NSA.\">PINECONE<\/a>, located somewhere in New Jersey. Inside the PINECONE facility, there is a secure space in which there is both NSA-controlled and AT&amp;T-controlled equipment. Internet traffic passes through an AT&amp;T \u201cdistribution box\u201d to two NSA systems. From there, the data is then transferred about 200 miles southwest to its final destination: NSA headquarters at Fort Meade in Maryland.<\/p>\n<p>At the Maryland compound, the communications collected from AT&amp;T\u2019s networks are integrated into powerful systems called <a class=\"project-y\" data-tooltip=\"An NSA database used to store and analyze records of phone communications, including cellphone, landline and internet-based Voice Over IP calls.\">MAINWAY<\/a> and <a class=\"project-y\" data-tooltip=\"An NSA database used to store and analyze internet metadata, including records about email correspondence.\">MARINA<\/a>, which the NSA uses to analyze metadata \u2013 such as the \u201cto\u201d and \u201cfrom\u201d parts of emails, and the times and dates they were sent. The communications obtained from AT&amp;T are also made accessible through a tool named <a class=\"project-y\" data-tooltip=\"A Google-like system NSA uses to search through the full written contents of internet communications, such as the bodies of emails.\">XKEYSCORE<\/a>, which NSA employees use to search through the full contents of emails, instant messenger chats, web-browsing histories, webcam photos, information about downloads from online services, and Skype sessions.<\/p>\n<div class=\"img-wrap align-bleed full-bleed width-auto\" readability=\"7\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-195641\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/grid-combine-01-1529695390.jpg?auto=compress%2Cformat&amp;q=90&amp;w=1024&amp;h=647\" alt=\"grid-combine-01-1529695390\"\/><\/p>\n<p class=\"caption source pullright\">Top left \/ right: Mike Osborne. Bottom left: Henrik Moltke. Bottom right: Frank Heath.<\/p>\n<\/div>\n<p><span data-shortcode-type=\"dropcap\" class=\"dropcap\">T<\/span><u class=\"project-y\">he NSA\u2019s primary<\/u> mission is to gather foreign intelligence. The agency has broad legal powers to monitor emails, phone calls, and other forms of correspondence as they are being transported across the U.S., and it can compel companies such as AT&amp;T to install surveillance equipment within their networks.<\/p>\n<p>Under a Ronald Reagan-era presidential directive \u2013 <a href=\"https:\/\/www.dni.gov\/index.php\/ic-legal-reference-book\/executive-order-12333\">Executive Order 12333<\/a> \u2013 the NSA has what it calls \u201ctransit authority,\u201d which it says enables it to eavesdrop on \u201ccommunications which originate and terminate in foreign countries, but traverse U.S. territory.\u201d That could include, for example, an email sent by a person in France to a person in Mexico, which on its way to its destination was routed through a server in California. According to the NSA\u2019s documents, it was using AT&amp;T\u2019s networks as of March 2013 to gather some 60 million foreign-to-foreign emails every day, 1.8 billion per month.<\/p>\n<p>Without an individualized court order, it is illegal for the NSA to spy on communications that are wholly domestic, such as emails sent back and forth between two Americans living in Texas. However, in the aftermath of the 9\/11 attacks, the agency began eavesdropping on Americans\u2019 international calls and emails that were passing between the U.S. and other countries. That practice was <a href=\"https:\/\/www.nytimes.com\/2005\/12\/16\/politics\/bush-lets-us-spy-on-callers-without-courts.html\">exposed by the New York Times<\/a> in 2005 and triggered what became known as the \u201cwarrantless wiretapping\u201d scandal.<\/p>\n<p>Critics argued that the surveillance of Americans\u2019 international communications was illegal, because the NSA had carried it out without obtaining warrants from a judge and had instead acted on the orders of President George W. Bush. In 2008, Congress weighed into the dispute and controversially authorized elements of the warrantless wiretapping program by enacting Section 702 of the Foreign Intelligence and Surveillance Act, or FISA. The new law allowed the NSA to continue sweeping up Americans\u2019 international communications without a warrant, so long as it did so \u201cincidentally\u201d while it was targeting foreigners overseas \u2013 for instance, if it was monitoring people in Pakistan, and they were talking with Americans in the U.S. by phone, email, or through an internet chat service.<\/p>\n<p>Within AT&amp;T\u2019s networks, there is filtering equipment designed to separate foreign and domestic internet data before it is passed to the NSA, the agency\u2019s documents show. Filtering technology is often used by internet providers for security reasons, enabling them to keep tabs on problems with their networks, block out spam, or monitor hacking attacks. But the same tools can be used for government surveillance.<\/p>\n<p>\u201cYou can essentially trick the routers into redirecting a small subset of traffic you really care about, which you can monitor in more detail,\u201d said Jennifer Rexford, a computer scientist who worked for AT&amp;T Labs between 1996 and 2005.<\/p>\n<\/p><\/div>\n<div data-reactid=\"270\" readability=\"79.123433345993\">\n<p>According to the NSA\u2019s <a href=\"https:\/\/theintercept.com\/document\/2018\/06\/25\/sso-news-relevant-entries\/\">documents<\/a>, it programs its surveillance systems to focus on particular IP addresses \u2013 a set of numbers that identify a computer \u2013 associated with foreign countries. A classified 2012 memo describes the agency\u2019s efforts to use IP addresses to home in on internet data passing between the U.S. and particular \u201cregions of interest,\u201d including Iran, Afghanistan, Israel, Nigeria, Pakistan, Yemen, Sudan, Tunisia, Libya, and Egypt. But this process is not an exact science, as people can use privacy or anonymity tools to change or spoof their IP addresses. A person in Israel could use privacy software to masquerade as if they were accessing the internet in the U.S. Likewise, an internet user in the U.S. could make it appear as if they were online in Israel. It is unclear how effective the NSA\u2019s systems are at detecting such anomalies.<\/p>\n<p>In October 2011, the Foreign Intelligence Surveillance Court, which approves the surveillance operations carried out under Section 702 of FISA, found that there were \u201ctechnological limitations\u201d with the agency\u2019s internet eavesdropping equipment. It was \u201cgenerally incapable of distinguishing\u201d between some kinds of data, the court stated. As a consequence, Judge John D. Bates <a href=\"https:\/\/www.documentcloud.org\/documents\/4522989-Fisc-Opinion-Oct-2011.html\">ruled<\/a>, the NSA had been intercepting the communications of \u201cnon-target United States persons and persons in the United States,\u201d violating Fourth Amendment protections against unreasonable searches and seizures. The ruling, which was declassified in August 2013, concluded that the agency had acquired some 13 million \u201cinternet transactions\u201d during one six-month period, and had unlawfully gathered \u201ctens of thousands of wholly domestic communications\u201d each year.<\/p>\n<p>The root of the issue was that the NSA\u2019s technology was not only targeting communications sent to and from specific surveillance targets. Instead, the agency was sweeping up people\u2019s emails if they had merely mentioned particular information <em>about<\/em> surveillance targets.<\/p>\n<p>A <a href=\"https:\/\/theintercept.com\/document\/2018\/06\/25\/faa702-comms-memo\">top-secret NSA memo<\/a> about the court\u2019s ruling, which has not been disclosed before, explained that the agency was collecting people\u2019s messages en masse if a single one were found to contain a \u201cselector\u201d \u2013 like an email address or phone number \u2013 that featured on a target list.<\/p>\n<p>\u201cOne example of this is when a user of a webmail service accesses her inbox; if the inbox contains one email message that contains an NSA tasked selector, NSA will acquire a copy of the entire inbox, not just the individual email message that contains the tasked selector,\u201d the memo stated.<\/p>\n<p>The court\u2019s ruling left the agency with two options: shut down the spying based on mentions of targets completely, or ensure that protections were put in place to stop the unlawfully collected communications from being reviewed. The NSA chose the latter option, and created a \u201ccautionary banner\u201d that warned its analysts not to read particular messages unless they could confirm that they had been lawfully obtained.<\/p>\n<p>But the cautionary banner did not solve the problem. The NSA\u2019s analysts continued to access the same data repositories to search, unlawfully, for information on Americans. In April 2017, the agency <a href=\"https:\/\/www.nsa.gov\/news-features\/press-room\/statements\/2017-04-28-702-statement.shtml\">publicly acknowledged<\/a> these violations, which it described as \u201cinadvertent compliance incidents.\u201d It said that it would no longer use surveillance programs authorized under Section 702 of FISA to harvest messages that mentioned its targets, citing \u201ctechnological constraints, United States person privacy interests, and certain difficulties in implementation.\u201d<\/p>\n<p>The messages that the NSA had unlawfully collected were swept up using a method of surveillance known as \u201cupstream,\u201d which the agency still deploys for other surveillance programs authorized under both Section 702 of FISA and Executive Order 12333. The upstream method involves tapping into communications as they are passing across internet networks \u2013 precisely the kind of electronic eavesdropping that appears to have taken place at the eight locations identified by The Intercept.<\/p>\n<div class=\"section section--with-background\" data-shortcode-type=\"section\">\n<div class=\"img-wrap align-bleed full-bleed width-auto\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-195107\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/DSC5709-SH-edit-1529525114.jpg?auto=compress%2Cformat&amp;q=90\" alt=\"DSC5709-SH-edit-1529525114\"\/><\/p>\n<p class=\"caption source pullright\">Photo: Frank Heath<\/p>\n<\/div>\n<p><\/p>\n<div class=\"columns columns--2-to-3\" data-shortcode=\"columns\" data-style=\"2:3\" readability=\"12.565406976744\">\n<div class=\"column\">\n<h3 id=\"atlanta\" class=\"chapter project-y\">Atlanta 51 Peachtree Center Avenue<\/h3>\n<div class=\"img-wrap align-center width-fixed\"><img decoding=\"async\" class=\"aligncenter size-pez-640 wp-image-192011\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/atlanta-1528311471.png?auto=compress%2Cformat&amp;q=90\" alt=\"\"\/><\/div>\n<\/div>\n<div class=\"column\" readability=\"20.260336906585\">The AT&amp;T building in Atlanta was originally constructed in the 1920s as the main telephone exchange for the city\u2019s downtown area. The art deco structure, made of limestone, was designed to be the largest in the city at the time at 25 stories tall. However, due to the Great Depression, plans were scaled back and at first, it only had six stories. Between 1947 and 1963, the building was upgraded to host 14 stories, and a large brown microwave tower \u2013 visible for miles \u2013 was also added. A profile of the building on the <a href=\"http:\/\/historyatlanta.com\/southern-bell-telephone-company-building\">History Atlanta website<\/a> notes that it contains \u201coperations, phone exchanges and other communications equipment for AT&amp;T.\u201d<\/div>\n<\/div>\n<p><\/p>\n<div class=\"img-wrap align-center width-fixed\"><a href=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-2-1528303742.jpg?auto=compress%2Cformat&amp;q=90\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-191908\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-2-1528303742.jpg?auto=compress%2Cformat&amp;q=90&amp;w=1024&amp;h=683\" alt=\"building-2-1528303742\"\/><\/a><\/p>\n<p class=\"caption source\">Photo: Frank Heath<\/p>\n<\/div>\n<p><\/p>\n<div class=\"columns columns--2-to-3\" data-shortcode=\"columns\" data-style=\"2:3\" readability=\"9.010989010989\">\n<div class=\"column\" readability=\"13.516483516484\">NSA and AT&amp;T maps point to the Atlanta facility as being one of eight \u201cpeering\u201d hubs that process internet traffic as part of the NSA surveillance program code-named <a class=\"project-y\" data-tooltip=\"An NSA surveillance program that collects communications from AT&amp;T's networks.\">FAIRVIEW<\/a>. One former AT&amp;T employee \u2013 who spoke on condition of anonymity \u2013 confirmed that the site was one of eight primary AT&amp;T <a class=\"project-y\" data-tooltip=\"Major AT&amp;T internet hubs.\">\u201cService Node Routing Complexes,\u201d<\/a> or SNRCs, in the U.S. NSA documents explicitly describe tapping into flows of data at all eight of these sites. <\/div>\n<\/div>\n<\/div>\n<\/div>\n<div data-reactid=\"277\">\n<div class=\"section section--with-background\" data-shortcode-type=\"section\" readability=\"7.3394077448747\"><\/p>\n<div class=\"columns columns--2-to-3\" data-shortcode=\"columns\" data-style=\"2:3\" readability=\"15\">\n<div class=\"column\" readability=\"25\">Information provided by a second former AT&amp;T employee adds to the evidence linking the Atlanta building to NSA surveillance. Mark Klein, a former AT&amp;T technician, alleged in 2006 that the company had allowed the NSA to install surveillance equipment in some of its network hubs. An AT&amp;T facility in Atlanta was one of the spy sites, according to documents Klein presented in a court case over the alleged spying. The Atlanta facility was equipped with \u201csplitter\u201d equipment, which was used to make copies of internet traffic as AT&amp;T\u2019s networks processed it. The copied data would then be diverted to \u201cSG3\u201d equipment \u2013 a reference to \u201cStudy Group 3\u201d \u2013 which was a code name AT&amp;T used for activities related to NSA surveillance, according to evidence in the Klein case.<\/p>\n<p>The Atlanta facility is likely of strategic importance for the NSA. The site is the closest major AT&amp;T internet routing center to Miami, according to the NSA and AT&amp;T maps. From undersea cables that come aground at Miami, huge flows of data pass between the U.S. and South America. It is probable that much of that data is routed through the Atlanta facility as it is being sent to and from the U.S. In recent years, the NSA has extensively targeted several Latin American countries \u2013 such as Mexico, Brazil, and Venezuela \u2013 for surveillance.<\/p>\n<\/div>\n<\/div>\n<div class=\"img-wrap align-bleed full-bleed width-auto\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-194129\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/026V2098-1529092644.jpg?auto=compress%2Cformat&amp;q=90\" alt=\"026V2098-1529092644\"\/><\/p>\n<p class=\"caption source pullright\">Photo: Henrik Moltke<\/p>\n<\/div>\n<p><\/p>\n<div class=\"columns columns--reverse columns--3-to-2\" data-shortcode=\"columns\" data-style=\"3:2\" readability=\"14.916897506925\">\n<div class=\"column\">\n<h3 id=\"chicago\" class=\"chapter project-y\">Chicago 10 South Canal Street<\/h3>\n<div class=\"img-wrap align-center width-fixed\"><img decoding=\"async\" class=\"aligncenter size-pez-640 wp-image-192050\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/chicago-1528315510.png?auto=compress%2Cformat&amp;q=90\" alt=\"\"\/><\/div>\n<\/div>\n<div class=\"column\" readability=\"24.85549132948\">Like many other major telecommunications hubs built during the late 1960s and early 1970s, the Chicago AT&amp;T building was designed amid the Cold War to withstand a nuclear attack. The 538-foot skyscraper, located in the West Loop Gate area of the city, was completed in 1971. There are windows at both the top and bottom of the vast concrete structure, but 18 of its 28 floors are windowless.<\/p>\n<p>According to the Chicago Sun-Times, the facility handles much of the city\u2019s phone and internet traffic and is equipped with banks of routers, servers, and switching systems. \u201cThis building touches every single resident of the city,\u201d Jim Wilson, an AT&amp;T area manager, <a href=\"https:\/\/chicago.suntimes.com\/columnists\/steinberg-the-technology-has-changed-quite-a-bit\/\">told<\/a> the newspaper in 2016.<\/p>\n<\/div>\n<\/div>\n<p><\/p>\n<div class=\"img-wrap align-center width-fixed\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-194130\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/026V2228-1529092700.jpg?auto=compress%2Cformat&amp;q=90&amp;w=1024&amp;h=682\" alt=\"\"\/><\/p>\n<p class=\"caption source\">Photo: Henrik Moltke<\/p>\n<\/div>\n<p><\/p>\n<div class=\"columns columns--reverse columns--3-to-2\" data-shortcode=\"columns\" data-style=\"3:2\" readability=\"15.25429326288\">\n<div class=\"column\" readability=\"25.58784676354\">One of the building\u2019s architects, John Augur Holabird, <a href=\"http:\/\/digital-libraries.saic.edu\/cdm\/singleitem\/collection\/caohp\/id\/26362\/rec\/1\">said<\/a> in a 1998 interview that it housed \u201ca big switchboard.\u201d He added: \u201cIn case the atomic bomb hits Milwaukee, you\u2019ll be happy to know your telephone line will still go through even though the rest of us are wiped out. And that\u2019s what that building was for.\u201d<\/p>\n<p>10 South Canal Street originally contained a million-gallon oil tank, turbine generators, and a water well, so that it could continue to function for more than two weeks without electricity or water from the city, according to Illinois broadcaster WBEZ. The building is \u201canchored in bedrock, which helps support the weight of the equipment inside, and gives it extra resistance to bomb blasts or earthquakes,\u201d WBEZ <a href=\"http:\/\/wglt.org\/post\/hidden-plain-sight-inside-downtown-chicagos-windowless-doorless-buildings\">reported<\/a>.<\/p>\n<\/div>\n<\/div>\n<div class=\"columns columns--reverse columns--3-to-2\" data-shortcode=\"columns\" data-style=\"3:2\" readability=\"14.437817258883\">\n<div class=\"column\" readability=\"24.218274111675\">Today, the facility contains six large V-16 yellow Caterpillar generators that can provide backup electricity in the event of a power failure, <a href=\"https:\/\/chicago.suntimes.com\/columnists\/steinberg-the-technology-has-changed-quite-a-bit\/\">according<\/a> to the Chicago Sun Times. Inside the skyscraper, AT&amp;T stores some 200,000 gallons of diesel fuel, enough to run the generators for 40 days.<\/p>\n<p>NSA and AT&amp;T maps point to the Chicago facility as being one of the \u201cpeering\u201d hubs, which process internet traffic as part of the NSA surveillance program code-named <a class=\"project-y\" data-tooltip=\"an NSA surveillance program that collects communications from AT&amp;T's networks.\">FAIRVIEW<\/a>. Philip Long, who was employed by AT&amp;T for more than two decades as a technician servicing its networks, confirmed that the Chicago site was one of eight primary AT&amp;T <a class=\"project-y\" data-tooltip=\"Major AT&amp;T internet hubs.\">\u201cService Node Routing Complexes,\u201d<\/a> or SNRCs, in the U.S. NSA documents explicitly describe tapping into flows of data at all eight of these sites.<\/p>\n<\/div>\n<\/div>\n<p><\/p>\n<div class=\"img-wrap align-bleed full-bleed width-fixed\"><a href=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-6-1528303991.jpg?auto=compress%2Cformat&amp;q=90\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-191914\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-6-1528303991.jpg?auto=compress%2Cformat&amp;q=90\" alt=\"building-6-1528303991\"\/><\/a><\/p>\n<p class=\"caption source pullright\">Photo: Mike Osborne<\/p>\n<\/div>\n<p><\/p>\n<div class=\"columns columns--2-to-3\" data-shortcode=\"columns\" data-style=\"2:3\" readability=\"13.905787348587\">\n<div class=\"column\">\n<h3 id=\"dallas\" class=\"chapter project-y\">Dallas 4211 Bryan Street<\/h3>\n<div class=\"img-wrap align-center width-fixed\"><img decoding=\"async\" class=\"aligncenter size-pez-640 wp-image-192051\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/dallas-1528315541.png?auto=compress%2Cformat&amp;q=90\" alt=\"\"\/><\/div>\n<\/div>\n<div class=\"column\" readability=\"22.839832869081\">This AT&amp;T building is a fortified, cube-like structure, located in the Old East area of Dallas, not far from Baylor University Medical Center. Built in 1961, it is a light yellow-brown color with a granite foundation. Large vents are visible on the exterior of the building, as are several narrow windows, many of which appear to have been blacked out or covered in a reflective privacy glass.<\/p>\n<p>The 4211 Bryan Street facility is located next to other AT&amp;T-owned buildings, including a towering telephone routing complex that was first built in 1904. A <a href=\"http:\/\/www.dallasobserver.com\/arts\/is-this-the-fugliest-building-in-dallas-7087129\">piece<\/a> about the telephone hub in the Dallas Observer described it as \u201can imposing, creepy building\u201d that is \u201cknown in some circles as The Great Wall of Beige.\u201d<\/p>\n<\/div>\n<\/div>\n<div class=\"img-wrap align-center width-fixed\"><a href=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-7-1528304068.jpg?auto=compress%2Cformat&amp;q=90\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-191915\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-7-1528304068.jpg?auto=compress%2Cformat&amp;q=90&amp;w=1024&amp;h=640\" alt=\"building-7-1528304068\"\/><\/a><\/p>\n<p class=\"caption source\">Photo: Mike Osborne<\/p>\n<\/div>\n<p><\/p>\n<div class=\"columns columns--2-to-3\" data-shortcode=\"columns\" data-style=\"2:3\" readability=\"16.372366790582\">\n<div class=\"column\" readability=\"28.066914498141\">According to the Central Office <a href=\"http:\/\/www.thecentraloffice.com\/texas\/dallas%20tandem\/dalltandem.htm\">website<\/a>, which profiles telecommunications buildings across the U.S., the Dallas telephone hub is \u201cthe main regional tandem and AT&amp;T for long distance and toll services in the Dallas Texas region.\u201d Today, the building also has \u201cmajor fiber connections to Plano, Irving, Tulsa, Oklahoma City, Ft. Worth, Abilene, Houston and Austin,\u201d the website adds.<\/p>\n<p>NSA and AT&amp;T maps point to the 4211 Bryan Street facility as being one of the \u201cpeering\u201d hubs, which process internet traffic as part of the NSA surveillance program code-named <a class=\"project-y\" data-tooltip=\"An NSA surveillance program that collects communications from AT&amp;T's networks.\">FAIRVIEW<\/a>. A former AT&amp;T employee confirmed that the site was one of eight primary AT&amp;T <a class=\"project-y\" data-tooltip=\"Major AT&amp;T internet hubs.\">\u201cService Node Routing Complexes,\u201d<\/a> or SNRCs, in the U.S. NSA documents explicitly describe tapping into flows of data at all eight of these sites.<\/p>\n<\/div>\n<\/div>\n<p><\/p>\n<div class=\"img-wrap align-bleed full-bleed width-auto\"><a href=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-8-1528304243.jpg?auto=compress%2Cformat&amp;q=90\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-191917\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-8-1528304243.jpg?auto=compress%2Cformat&amp;q=90\" alt=\"building-8-1528304243\"\/><\/a><\/p>\n<p class=\"caption source pullright\">Photo: Henrik Moltke<\/p>\n<\/div>\n<p><\/p>\n<div class=\"columns columns--reverse columns--3-to-2\" data-shortcode=\"columns\" data-style=\"3:2\" readability=\"11.267004341534\">\n<div class=\"column\">\n<h3 id=\"losangeles\" class=\"chapter project-y\">Los Angeles 420 South Grand Avenue<\/h3>\n<div class=\"img-wrap align-center width-fixed\"><img decoding=\"async\" class=\"aligncenter size-pez-640 wp-image-192052\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/la-1528315561.png?auto=compress%2Cformat&amp;q=90\" alt=\"\"\/><\/div>\n<\/div>\n<div class=\"column\" readability=\"17.615853658537\">At the time of its construction in 1961, the AT&amp;T building known as the Madison Complex was the tallest building in downtown Los Angeles. It has since been dwarfed by a number of corporate office skyscrapers in the surrounding Financial District.<\/p>\n<p>Located between Chinatown and the Staples Center, the fortress-like structure is one of the largest telephone central offices in the U.S. \u201cThe theoretical number of telephone lines that can be served from this office are 1.3 million and this office also serves as a foreign exchange carrier to neighboring area codes,\u201d according to the <a href=\"http:\/\/www.thecentraloffice.com\/calif\/la\/madison\/lamadison.htm\">Central Office<\/a>, a website that profiles U.S. telecommunications hubs.<\/p>\n<\/div>\n<\/div>\n<div class=\"img-wrap align-center width-fixed\" readability=\"10\"><a href=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-9-1528304318.jpg?auto=compress%2Cformat&amp;q=90\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-191919\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-9-1528304318.jpg?auto=compress%2Cformat&amp;q=90&amp;w=1024&amp;h=682\" alt=\"building-9-1528304318\"\/><\/a><\/p>\n<p class=\"caption\">\u201cUntitled, or Bell Communications Around the Globe\u201d. Mural by Anthony Heinsbergen (1961) on the West side of 420 South Grand Ave, La.<\/p>\n<p class=\"caption source\">Photo: Henrik Moltke<\/p>\n<\/div>\n<p><\/p>\n<div class=\"columns columns--reverse columns--3-to-2\" data-shortcode=\"columns\" data-style=\"3:2\" readability=\"11\">\n<div class=\"column\" readability=\"17\">The 448-foot, 17-story building is beige, rectangular, and mostly windowless. On its roof, there is a large microwave tower, which was originally used to transmit phone calls across a network of antennae. The tower\u2019s technology became obsolete in the early 1990s, and it ceased to operate. It remains in place today as a sort of monument to outdated methods of communication and stands in contrast to the more modern buildings in the vicinity, many of them owned by banks. <\/div>\n<\/div>\n<p><\/div>\n<\/div>\n<div data-reactid=\"284\">\n<div class=\"section section--with-background\" data-shortcode-type=\"section\" readability=\"8.1535662299854\">\n<div class=\"columns columns--3-to-2\" data-shortcode=\"columns\" data-style=\"3:2\" readability=\"16.608173076923\">\n<div class=\"column\" readability=\"28.471153846154\">The Madison Complex is located just two blocks from One Wilshire, which houses what is reportedly the most important internet exchange on the U.S. west coast. \u201cBillions of phone calls, emails and internet pages pass through One Wilshire every week,\u201d the Los Angeles Times <a href=\"http:\/\/articles.latimes.com\/2013\/jul\/18\/business\/la-fi-0718-property-report-20130718\">reported<\/a> in 2013, \u201cbecause it is the primary terminus for major fiber-optic cable routes between Asia and North America.\u201d<\/p>\n<p>Due to the close proximity of the Madison Complex and One Wilshire, and their shared role as telecommunications hubs, it is likely that the buildings process some of the same data as it is being routed across U.S. networks.<\/p>\n<p>NSA and AT&amp;T maps point to the Madison Complex facility as being one of the \u201cpeering\u201d hubs, which process internet traffic as part of the NSA surveillance program code-named <a class=\"project-y\" data-tooltip=\"An NSA surveillance program that collects communications from AT&amp;T's networks.\">FAIRVIEW<\/a>. A former AT&amp;T employee confirmed that the site was one of eight primary AT&amp;T <a class=\"project-y\" data-tooltip=\"Major AT&amp;T internet hubs.\">\u201cService Node Routing Complexes,\u201d<\/a> or SNRCs, in the U.S. NSA documents explicitly describe tapping into flows of data at all eight of these sites.<\/p>\n<\/div>\n<\/div>\n<div class=\"img-wrap align-bleed full-bleed width-auto\"><a href=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-10-1528304345.jpg?auto=compress%2Cformat&amp;q=90\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-191920\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-10-1528304345.jpg?auto=compress%2Cformat&amp;q=90\" alt=\"building-10-1528304345\"\/><\/a><\/p>\n<p class=\"caption source pullright\">Photo: Henrik Moltke<\/p>\n<\/div>\n<div class=\"columns columns--2-to-3\" data-shortcode=\"columns\" data-style=\"2:3\" readability=\"10.868376068376\">\n<div class=\"column\">\n<h3 id=\"nyc\" class=\"chapter project-y\">New York City 811 10th Avenue<\/h3>\n<div class=\"img-wrap align-center width-fixed\"><img decoding=\"async\" class=\"aligncenter size-pez-640 wp-image-192053\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/nyc-1528315583.png?auto=compress%2Cformat&amp;q=90\" alt=\"\"\/><\/div>\n<\/div>\n<div class=\"column\" readability=\"16.785585585586\">It was built in 1964 as New York City\u2019s first major telecommunications fortress. The striking concrete and granite AT&amp;T building \u2013 located in the Hell\u2019s Kitchen area about a 15-minute walk from Central Park \u2013 is 134 meters tall, with 21 floors, each one of them windowless and built to resist a nuclear blast.<\/p>\n<p>A New York Times <a href=\"https:\/\/www.nytimes.com\/1975\/12\/06\/archives\/when-building-for-future-means-a-step-backward.html\">article<\/a> published in 1975 noted that 811 10th Avenue was \u201cthe first of several windowless equipment buildings to be constructed\u201d in the city, and added that its design initially \u201ccaused considerable controversy.\u201d<\/p>\n<\/div>\n<\/div>\n<p><\/p>\n<div class=\"img-wrap align-center width-fixed\" readability=\"12\"><a href=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-11-1528304373.jpg?auto=compress%2Cformat&amp;q=90\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-191921\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-11-1528304373.jpg?auto=compress%2Cformat&amp;q=90&amp;w=1024&amp;h=682\" alt=\"building-11-1528304373\"\/><\/a><\/p>\n<p class=\"caption\">Aerial shot of 811 10th street, NYC, ca. 1965.<\/p>\n<p class=\"caption source\">Photo: courtesy of Avery Architectural &amp; Fine Arts Library, Columbia University<\/p>\n<\/div>\n<p><\/p>\n<div class=\"columns columns--2-to-3\" data-shortcode=\"columns\" data-style=\"2:3\" readability=\"11.349813432836\">\n<div class=\"column\" readability=\"17.764925373134\">According to AT&amp;T <a href=\"https:\/\/web.archive.org\/web\/20150226030013\/http:\/telehouse.com\/wp-content\/uploads\/2014\/07\/NY-City-Midtown-Spec-sheet.pdf\">records<\/a>, the building is a \u201chardened telco data center\u201d and was upgraded in 2000 to become an internet data center. Thomas Saunders, a former AT&amp;T engineer, told The Intercept that, in the 1970s, the building was considered to be \u201cthe biggest hub for transmission [of communications] in the country.\u201d Saunders also claimed that, had Bush been in Manhattan during the 9\/11 attacks, the Secret Service would have taken him to safety inside the AT&amp;T facility. \u201cIt\u2019s the strongest building in town,\u201d he said.<\/div>\n<\/div>\n<div class=\"img-wrap align-center width-fixed\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-194142\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/026V2356-1529093799.jpg?auto=compress%2Cformat&amp;q=90&amp;w=1024&amp;h=572\" alt=\"026V2356-1529093799\"\/><\/p>\n<p class=\"caption source\">Photo: Henrik Moltke<\/p>\n<\/div>\n<div class=\"columns columns--2-to-3\" data-shortcode=\"columns\" data-style=\"2:3\" readability=\"8.4698795180723\">\n<div class=\"column\" readability=\"12.481927710843\">NSA and AT&amp;T maps indicate that the 10th Avenue facility is one of eight \u201cpeering\u201d hubs that process internet traffic as part of the NSA surveillance program code-named <a class=\"project-y\" data-tooltip=\"An NSA surveillance program that collects communications from AT&amp;T's networks.\">FAIRVIEW<\/a>. Two former AT&amp;T employees confirmed that the site was one of eight primary AT&amp;T <a class=\"project-y\" data-tooltip=\"Major AT&amp;T internet hubs.\">\u201cService Node Routing Complexes,\u201d<\/a> or SNRCs, in the U.S. NSA documents explicitly describe tapping into flows of data at all eight of these sites. <\/div>\n<\/div>\n<\/div>\n<\/div>\n<div data-reactid=\"291\" readability=\"6.7452926208651\">\n<div class=\"section section--with-background\" data-shortcode-type=\"section\" readability=\"14.683676126009\"><\/p>\n<div class=\"columns columns--2-to-3\" data-shortcode=\"columns\" data-style=\"2:3\" readability=\"12.871287128713\">\n<div class=\"column\" readability=\"20.792079207921\">The design of the building bears some resemblance to another windowless building in New York City \u2013 AT&amp;T\u2019s towering skyscraper at 33 Thomas Street in lower Manhattan. As The Intercept <a href=\"https:\/\/theintercept.com\/2016\/11\/16\/the-nsas-spy-hub-in-new-york-hidden-in-plain-sight\/\">reported<\/a> in 2016, 33 Thomas Street is a major hub for routing international phone calls and appears to contain a secure NSA surveillance room \u2013 code-named TITANPOINTE \u2013 that has been used to tap into faxes and phone calls.<\/p>\n<p>NSA and AT&amp;T documents indicate that 10th Avenue building serves as the NSA\u2019s internet equivalent of 33 Thomas Street. While the NSA\u2019s surveillance at 33 Thomas Street mainly targets phone calls that pass through the building\u2019s international switching points, at the 10th Avenue site the agency appears to primarily collect emails, online chats, and data from internet browsing sessions.<\/p>\n<\/div>\n<\/div>\n<div class=\"img-wrap align-bleed full-bleed width-auto\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-191920\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-13-1528304435.jpg?auto=compress%2Cformat&amp;q=90\" alt=\"building-13-1528304435\"\/><\/p>\n<p class=\"caption source pullright\">Photo: Henrik Moltke<\/p>\n<\/div>\n<p><\/p>\n<div class=\"columns columns--reverse columns--3-to-2\" data-shortcode=\"columns\" data-style=\"3:2\" readability=\"12.322916666667\">\n<div class=\"column\">\n<h3 id=\"sanfrancisco\" class=\"chapter project-y\">San Francisco 611 Folsom Street<\/h3>\n<div class=\"img-wrap align-center width-fixed\"><img decoding=\"async\" class=\"aligncenter size-pez-640 wp-image-192054\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/sf-1528315600.png?auto=compress%2Cformat&amp;q=90\" alt=\"\"\/><\/div>\n<\/div>\n<div class=\"column\" readability=\"19.864182692308\">This San Francisco AT&amp;T building has been described as the city\u2019s telecommunications \u201cnerve center.\u201d It is about 256 feet tall, has nine floors, and its exterior is covered in silver-colored panels; there are a series of vents that can be seen at street level, but there are few windows.<\/p>\n<p>NSA and AT&amp;T maps obtained by The Intercept indicate that 611 Folsom Street is one of the eight \u201cpeering\u201d hubs in the U.S. that process internet traffic as part of the NSA surveillance program code-named <a class=\"project-y\" data-tooltip=\"An NSA surveillance program that collects communications from AT&amp;T's networks.\">FAIRVIEW<\/a>. Philip Long, who was employed by AT&amp;T for more than two decades as a technician servicing its networks, confirmed that the San Francisco site is one of eight primary AT&amp;T <a class=\"project-y\" data-tooltip=\"Major AT&amp;T internet hubs.\">\u201cService Node Routing Complexes,\u201d<\/a> or SNRCs, in the U.S. NSA documents explicitly describe tapping into flows of data at all eight of these sites.<\/p>\n<\/div>\n<\/div>\n<div class=\"img-wrap align-center width-fixed\"><a href=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-14-1528304462.jpg?auto=compress%2Cformat&amp;q=90\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-191927\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-14-1528304462.jpg?auto=compress%2Cformat&amp;q=90&amp;w=1024&amp;h=682\" alt=\"building-14-1528304462\"\/><\/a><\/p>\n<p class=\"caption source\">Photo: Henrik Moltke<\/p>\n<\/div>\n<p><\/p>\n<div class=\"columns columns--reverse columns--3-to-2\" data-shortcode=\"columns\" data-style=\"3:2\" readability=\"19.5\">\n<div class=\"column\" readability=\"34\">Long recalled that, in the early 2000s, he \u201cmoved every internet backbone circuit I had in northern California\u201d through the Folsom Street office. At the time, he said, he and his colleagues found it strange that they were asked to suddenly reroute all of the traffic, because \u201cthere was nothing wrong with the services, no facility problems.\u201d<\/p>\n<p>\u201cWe were getting orders to move backbones \u2026 and it just grabbed me,\u201d said Long. \u201cWe thought it was government stuff and that they were being intrusive. We thought we were routing our circuits so that they could grab all the data.\u201d<\/p>\n<p>It is not the first time the building has been implicated in revelations about electronic eavesdropping. In 2006, an AT&amp;T technician named Mark Klein alleged in a sworn court declaration that the NSA was tapping into internet traffic from a secure room on the sixth floor of the facility.<\/p>\n<p>Klein, who worked at 611 Folsom Street between October 2003 and May 2004, stated that employees from the agency had visited the building and recruited one of AT&amp;T\u2019s management level technicians to carry out a \u201cspecial job.\u201d The job involved installing a \u201csplitter cabinet\u201d that copied internet data as it was flowing into the building, before diverting it into the secure room.<\/p>\n<\/div>\n<\/div>\n<div class=\"img-wrap align-center width-fixed\" readability=\"7\"><a href=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-15-1528304523.jpg?auto=compress%2Cformat&amp;q=90\"><img decoding=\"async\" class=\"aligncenter size-article-large wp-image-191928\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-15-1528304523.jpg?auto=compress%2Cformat&amp;q=90&amp;w=1000&amp;h=750\" alt=\"building-15-1528304523\"\/><\/a><\/p>\n<p class=\"caption\">The room at AT&amp;T\u2019s Folsom St. facility that allegedly contained NSA surveillance equipment.<\/p>\n<p class=\"caption source\">Photo: Mark Klein<\/p>\n<\/div>\n<p><\/p>\n<div class=\"columns columns--reverse columns--3-to-2\" data-shortcode=\"columns\" data-style=\"3:2\" readability=\"12\">\n<p>He said equipment in the secure room included a \u201csemantic traffic analyzer\u201d \u2013 a tool that can be used to search large quantities of data for particular words or phrases contained in emails or online chats. Notably, Klein discovered that the NSA appeared to be specifically targeting internet \u201cpeering links,\u201d which is corroborated by the NSA and AT&amp;T documents obtained by The Intercept.<\/p>\n<\/div>\n<div class=\"columns columns--reverse columns--3-to-2\" data-shortcode=\"columns\" data-style=\"3:2\" readability=\"18\">\n<div class=\"column\" readability=\"31\">\u201cBy cutting into the peering links, they get not only AT&amp;T\u2019s data, they get all the data that\u2019s interchanged between AT&amp;T\u2019s network and other companies,\u201d Klein told The Intercept in a recent interview.<\/p>\n<p>According to documents provided by Klein, AT&amp;T\u2019s network at Folsom Street \u201cpeered\u201d with other companies like Sprint, Cable &amp; Wireless, and Qwest. It was also linked, he said, to an internet exchange named MAE West, a major data hub in San Jose, California, where other companies connect their networks together.<\/p>\n<p>Sprint did not respond to a request for comment. A spokesperson for Cable &amp; Wireless said the company only discloses data \u201cwhen legally required to do so as a result of a valid warrant or other legal process.\u201d In 2011, CenturyLink acquired Qwest as part of a $12.2 billion merger deal. A CenturyLink spokesperson said he could not discuss \u201cmatters of national security.\u201d<\/p>\n<\/div>\n<\/div>\n<div class=\"img-wrap align-bleed full-bleed width-auto\" readability=\"7\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-192488\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/seattle-1-1528469085.jpg?auto=compress%2Cformat&amp;q=90\" alt=\"The National Security Agency\u2019s Seattle facility, located in the city\u2019s downtown area, photographed on Wednesday, May 2, 2018, in Seattle, Wash. The 15-story gray building hosts the NSA, AT&amp;T and Qwest Corporation communications. NSA and AT&amp;T maps point to the Seattle facility as being of eight peering hubs that process internet traffic as part of the NSA surveillance program code-named FAIRVIEW. (Jovelle Tamayo for The Intercept)\"\/><\/p>\n<p class=\"caption source pullright\">Photo: Jovelle Tamayo for The Intercept<\/p>\n<\/div>\n<div class=\"columns columns--2-to-3\" data-shortcode=\"columns\" data-style=\"2:3\" readability=\"15.764127764128\">\n<div class=\"column\">\n<h3 id=\"seattle\" class=\"chapter project-y\">Seattle 1122 3rd Avenue<\/h3>\n<div class=\"img-wrap align-center width-fixed\"><img decoding=\"async\" class=\"aligncenter size-pez-640 wp-image-192055\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/seattle-1528315622.png?auto=compress%2Cformat&amp;q=90\" alt=\"\"\/><\/div>\n<\/div>\n<div class=\"column\" readability=\"26.589873417722\">The Seattle facility is located in the city\u2019s downtown area, not far from the waterfront. The gray building is 15 stories tall, with a dozen rows of narrow, blacked-out windows and vents that rise to its peak. According to public <a href=\"http:\/\/pcad.lib.washington.edu\/building\/8826\/\">records<\/a>, it was first constructed in 1955 and has reinforced concrete foundations and exterior walls that are supported by a steel frame.<\/p>\n<p>Historically, the facility was an important communications switching point in the northwest of the U.S., routing calls between places like Bellingham, Spokane, Yakima, and north to Canada and Alaska. Today, the building appears to be primarily <a href=\"http:\/\/blue.kingcounty.com\/Assessor\/eRealProperty\/Detail.aspx?ParcelNbr=2302700000\">owned<\/a> by the Qwest Corporation \u2013 a subsidiary of CenturyLink \u2013 but AT&amp;T has a presence within it. AT&amp;T\u2019s logo is emblazoned on a plaque outside the building\u2019s entrance.<\/p>\n<\/div>\n<\/div>\n<p><\/p>\n<div class=\"columns columns--2-to-3\" data-shortcode=\"columns\" data-style=\"2:3\" readability=\"12\">\n<p>Twenty-five miles north of Seattle, there is a major intercontinental undersea cable called Pacific Crossing-1, which routes communications between the U.S. and Japan; it is possible that the Seattle building processes some of these communications and others that pass between the U.S. west coast and Asia.<\/p>\n<\/div>\n<div class=\"img-wrap align-center width-fixed\" readability=\"7\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-192489\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/seattle-2-1528469087.jpg?auto=compress%2Cformat&amp;q=90&amp;w=1024&amp;h=682\" alt=\"The National Security Agency\u2019s Seattle facility, located in the city\u2019s downtown area, photographed on Wednesday, May 2, 2018, in Seattle, Wash. The 15-story gray building hosts the NSA, AT&amp;T and Qwest Corporation communications. NSA and AT&amp;T maps point to the Seattle facility as being of eight peering hubs that process internet traffic as part of the NSA surveillance program code-named FAIRVIEW. (Jovelle Tamayo for The Intercept)\"\/><\/p>\n<p class=\"caption source\">Photo: Jovelle Tamayo for The Intercept<\/p>\n<\/div>\n<p><\/p>\n<div class=\"columns columns--2-to-3\" data-shortcode=\"columns\" data-style=\"2:3\" readability=\"8.4365671641791\">\n<div class=\"column\" readability=\"12.432835820896\">NSA and AT&amp;T maps point to the Seattle facility as being of eight \u201cpeering\u201d hubs that process internet traffic as part of the NSA surveillance program code-named <a class=\"project-y\" data-tooltip=\"An NSA surveillance program that collects communications from AT&amp;T's networks.\">FAIRVIEW<\/a>. A former AT&amp;T employee confirmed that the site was one of eight primary AT&amp;T <a class=\"project-y\" data-tooltip=\"Major AT&amp;T internet hubs.\">\u201cService Node Routing Complexes,\u201d<\/a> or SNRCs, in the U.S. NSA documents explicitly describe tapping into flows of data at all eight of these sites.<\/div>\n<\/div>\n<div class=\"img-wrap align-bleed full-bleed width-auto\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-191920\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-18-1528304953.jpg?auto=compress%2Cformat&amp;q=90\" alt=\"building-18-1528304953\"\/><\/p>\n<p class=\"caption source pullright\">Photo: Henrik Moltke<\/p>\n<\/div>\n<p><\/p>\n<div class=\"columns columns--reverse columns--3-to-2\" data-shortcode=\"columns\" data-style=\"3:2\" readability=\"14.866920152091\">\n<div class=\"column\">\n<h3 id=\"washingtondc\" class=\"chapter project-y\">Washington, D.C. 30 E Street Southwest<\/h3>\n<div class=\"img-wrap align-center width-fixed\"><img decoding=\"async\" class=\"aligncenter size-pez-640 wp-image-192056\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/washington-1528315638.png?auto=compress%2Cformat&amp;q=90\" alt=\"\"\/><\/div>\n<\/div>\n<div class=\"column\" readability=\"24.766666666667\">The building is a large, concrete, rectangular-shaped facility with few windows, located less than a mile south of the U.S. Capitol. Property tax records show that Verizon owns the majority of the property (worth $26 million), while AT&amp;T owns a smaller part (worth $8.8 million). Plans of the building\u2019s internal layout show that AT&amp;T has space on the fourth, fifth, and sixth floors.<\/p>\n<p>Central Office Buildings, a <a href=\"http:\/\/www.co-buildings.com\/dc\/202\/\">website<\/a> that profiles telecommunications hubs in North America, describes the 30 E Street South West facility as \u201cthe granddaddy HQ of Verizon landline in Washington, DC.\u201d It adds that the building contains a \u201ca slew of switches of various types,\u201d including AT&amp;T equipment for routing long distance phone calls across networks.<\/p>\n<\/div>\n<\/div>\n<div class=\"img-wrap align-center width-fixed\"><a href=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-19-1528305177.jpg?auto=compress%2Cformat&amp;q=90\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-191940\" src=\"https:\/\/theintercept.imgix.net\/wp-uploads\/sites\/1\/2018\/06\/building-19-1528305177.jpg?auto=compress%2Cformat&amp;q=90&amp;w=1024&amp;h=574\" alt=\"building-19-1528305177\"\/><\/a><\/p>\n<p class=\"caption source\">Photo: Mike Osborne<\/p>\n<\/div>\n<div class=\"columns columns--reverse columns--3-to-2\" data-shortcode=\"columns\" data-style=\"3:2\" readability=\"13.251781472684\">\n<div class=\"column\" readability=\"21.770783847981\">Capitol Police has an office located opposite the telecommunications hub, and a large number of police vehicles are usually located around the site. When The Intercept visited the facility to take photographs earlier this year, within a few minutes, several armed police officers arrived on the scene with dogs. They questioned our reporter, searched his car, and said that the building was considered critical infrastructure.<\/p>\n<p>NSA and AT&amp;T maps point to the Washington, D.C. facility as being one of eight \u201cpeering\u201d hubs that process internet traffic as part of the NSA surveillance program code-named <a class=\"project-y\" data-tooltip=\"An NSA surveillance program that collects communications from AT&amp;T's networks.\">FAIRVIEW<\/a>. A former AT&amp;T employee confirmed that the site was one of eight primary AT&amp;T <a class=\"project-y\" data-tooltip=\"Major AT&amp;T internet hubs.\">\u201cService Node Routing Complexes,\u201d<\/a> or SNRCs, in the U.S. NSA documents explicitly describe tapping into flows of data at all eight of these sites.<\/p>\n<\/div>\n<\/div>\n<p><\/div>\n<h3>Documents<\/h3>\n<p>Documents published with this article:<\/p>\n<\/div>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/29073\/The-NSAs-Hidden-Spy-Hubs-In-Eight-U.S.-Cities.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":4305,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[1562],"class_list":["post-4304","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinegovernmentprivacyusaphonespywarensa"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>The NSA&#039;s Hidden Spy Hubs In Eight U.S. Cities 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The NSA&#039;s Hidden Spy Hubs In Eight U.S. Cities 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2018-06-25T16:09:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/06\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"520\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"34 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"The NSA&#8217;s Hidden Spy Hubs In Eight U.S. Cities\",\"datePublished\":\"2018-06-25T16:09:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\\\/\"},\"wordCount\":6831,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/06\\\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities.png\",\"keywords\":[\"headline,government,privacy,usa,phone,spyware,nsa\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\\\/\",\"name\":\"The NSA's Hidden Spy Hubs In Eight U.S. Cities 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/06\\\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities.png\",\"datePublished\":\"2018-06-25T16:09:10+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/06\\\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/06\\\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities.png\",\"width\":1200,\"height\":520},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,government,privacy,usa,phone,spyware,nsa\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinegovernmentprivacyusaphonespywarensa\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"The NSA&#8217;s Hidden Spy Hubs In Eight U.S. Cities\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The NSA's Hidden Spy Hubs In Eight U.S. Cities 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\/","og_locale":"en_US","og_type":"article","og_title":"The NSA's Hidden Spy Hubs In Eight U.S. Cities 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2018-06-25T16:09:10+00:00","og_image":[{"width":1200,"height":520,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/06\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"34 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"The NSA&#8217;s Hidden Spy Hubs In Eight U.S. Cities","datePublished":"2018-06-25T16:09:10+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\/"},"wordCount":6831,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/06\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities.png","keywords":["headline,government,privacy,usa,phone,spyware,nsa"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\/","url":"https:\/\/www.threatshub.org\/blog\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\/","name":"The NSA's Hidden Spy Hubs In Eight U.S. Cities 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/06\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities.png","datePublished":"2018-06-25T16:09:10+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/06\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/06\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities.png","width":1200,"height":520},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/the-nsas-hidden-spy-hubs-in-eight-u-s-cities\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,government,privacy,usa,phone,spyware,nsa","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinegovernmentprivacyusaphonespywarensa\/"},{"@type":"ListItem","position":3,"name":"The NSA&#8217;s Hidden Spy Hubs In Eight U.S. Cities"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/4304","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=4304"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/4304\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/4305"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=4304"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=4304"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=4304"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}