Talk:Tailored Access Operations
Add topic| Another article is currently slated for merging into this article. Equation Group has been nominated for merging. In the discussion, editors reached a consensus to merge its contents into this article. You can assist with the merge by following the merging instructions. (June 2026) Do not remove this template after completing the merge. A bot will replace it with {{afd-merged-from}}. |
| This article is rated C-class on Wikipedia's content assessment scale. It is of interest to the following WikiProjects: | |||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||
| Text or other creative content from this version of Office of Tailored Access Operations was copied or moved into Tailored Access Operations with this edit on 2013-12-31. The former page's history now serves to provide attribution for that content in the latter page, and it must not be deleted as long as the latter page exists. |
Tailored Access?
[edit]I've a question. "Tailored Access", what does it mean?--OnionBulb Talk ⁄ Contributions.- 18:24, 2 July 2013 (UTC)
- I guess, something like getting access in a careful and precise way, compare "tailor made". P2Peter (talk) 01:50, 25 July 2013 (UTC)
- An extremely polite way of saying hacking. --Paulmd199 (talk) 13:57, 6 August 2013 (UTC)
Recent refs
[edit]Sorry I don't have time to edit, but here are some refs from last few days:
- The Guardian, 12/29/13
- CNET, 12/29/13
- CNN, 12/31/13
- Info Security Magazine 1/3/14. Carolmooredc (Talkie-Talkie) 19:57, 5 January 2014 (UTC)
QUANTUM attacks
[edit]The list of "some FOXACID modules" contains links to the Wikipedia articles of legitimate websites, implying that these websites ARE FOXACID modules, rather than being potential targets. Is this correct?152.51.56.1 (talk) 15:02, 15 January 2014 (UTC)
- Eh, I think it's obvious those modules are used to attack users going to those specific sites. An example of how they used their linkedin module (which spoofs/mimics LinkedIn) is given here. Someone not using his real name (talk) 15:25, 15 January 2014 (UTC)
This page isn't quite right.
[edit]I feel like there is a lot of WP:SYNTH going on here, as well as an odd tone and style used throughout. There are also some pretty critical citations missing.
I think this article might need a lot of fixing.
External links modified
[edit]Hello fellow Wikipedians,
I have just modified one external link on Tailored Access Operations. Please take a moment to review my edit. If you have any questions, or need the bot to ignore the links, or the page altogether, please visit this simple FaQ for additional information. I made the following changes:
- Added archive https://web.archive.org/web/20140115014135/http://www.networkworld.com/news/2013/111113-british-spies-reportedly-spoofed-linkedin-275807.html to http://www.networkworld.com/news/2013/111113-british-spies-reportedly-spoofed-linkedin-275807.html
When you have finished reviewing my changes, you may follow the instructions on the template below to fix any issues with the URLs.
This message was posted before February 2018. After February 2018, "External links modified" talk page sections are no longer generated or monitored by InternetArchiveBot. No special action is required regarding these talk page notices, other than regular verification using the archive tool instructions below. Editors have permission to delete these "External links modified" talk page sections if they want to de-clutter talk pages, but see the RfC before doing mass systematic removals. This message is updated dynamically through the template {{source check}} (last update: 5 June 2024).
- If you have discovered URLs which were erroneously considered dead by the bot, you can report them with this tool.
- If you found an error with any archives or the URLs themselves, you can fix them with this tool.
Cheers.—InternetArchiveBot (Report bug) 21:03, 12 January 2018 (UTC)
Posting Classified Documents on Wikipedia
[edit]Hello.
There is currently a reference made in Tailored Access Operations which includes an image of what appears to be an alleged U.S. government classified document. I am new here, to Wikipedia, and would like clarification. Are we allowed to post classified documents on Wikipedia? This seems as though it may be an unwise practice, and there is an entirely separate wiki just for this type of stuff.
Also, assuming this type of "whistleblower"/"leaking"/"treason" is deemed acceptable on Wikipedia, how would one reference such documents? As they are, by design, guarded documents/images.
Specifically, I am asking about:

- This discussion might interest you. Brycehughes (talk) 04:53, 29 March 2020 (UTC)
"simbarid" -- What?
[edit]In the "QUANTUM attacks" section of this page, an expoitable "module" listed is "simbarid," a redlinked page. In the source cited, the list is clear, reading something called "simbarUuid". Any Google search returns this with no result. Is there any clarification on this whatsoever that we can provide? It almost seems like listing cited gibberish and expecting people to understand. Possibly a classified program? Thanks,NeuropolTalk 16:58, 9 May 2024 (UTC)
- Probably classified, feel free to remove stuff that cannot be cited with non-classified sources. Wikipedia sources do need to be 'published' at the very least, I don't think classified documents meet that threshold. PhotographyEdits (talk) 09:52, 10 May 2024 (UTC)
Shadow Brokers / leak
[edit]Why no mention of the leak involving Kaspersky and Shadow Brokers? I realise this is covered in the Equation Group article, but seeing as the link between TAO and EG is more than likely, I think it warrants a mention here as well.
https://www.nytimes.com/2017/11/12/us/nsa-shadow-brokers.html Transmogriff (talk) 12:39, 4 July 2025 (UTC)
Name
[edit]> The office is currently known as Office of Computer Network Operations (OCNO)
This is not named in the lead, neither it is the article title. Is the office currently known as TAO, or is this the old name? This is not clear. PhotographyEdits (talk) 13:27, 19 January 2026 (UTC)
Red Team
[edit]It was a precursor to TAO, assembled in 1997 to conduct operation "Eligible Receiver". "Founded" by M.V.Hayden, B.Marshall, B.Black, K.Minihan after the success of the said operation.Setenzatsu.2 (talk) 12:42, 5 May 2026 (UTC)
Other information
[edit]- base was at Information Operations Technology Center (IOTC)
- Equation group connections (some TAO employees (two I think) were charged for mishandling classified material at the time of the Shadow Brokers leaks, which were about the Equation group)
- Snowden's leak containes files that describe and name the hacking tools; then that information is used by Kaspersky Lab to track Equation Group's activities and the Shadow Brokers' leak contained tools that were described by Snowden
- leaked NSA operational notes and names of NSA hackers - Shadow Brokers' leak that was about Equation group
- Harold Thomas Martin III (Booz Allen Hamilton) and Nghia Hoang Pho leaks
- Stuxnet
- Operation Treasure Map
What the fuck? Everything ????
[edit]I spent days updating the page that clearly didn't contain the current information since 2019 with things that have been public for a while now, even here are people askiing why there aren't sections abt The Shadow Brokers when it is an stablished fact that it was the TAO.
English is my second language and I understand if you fix my spelling or syntaxis or even correcting me on data (eventhough everything I added has a reputable source btw), but deleting my whole shit just bc you had to correct my grammar in a phew paragraphs is insane; you can fact check all the shit I added and it goes through wtf. Conservadont (talk) 13:06, 3 June 2026 (UTC)
- You spent days turning the article into a poorly written, typo-ridden mess without prior discussion or consensus. Massive page rewrites like this, especially when controversial or contested, need to be discussed and gain consensus first precisely to avoid major wastes of time like this. Multiple editors have objected to this in edit summaries. Now's your opportunity to convince them of the merits of your edits. ⇒SWATJester Shoot Blues, Tell VileRat! 14:58, 3 June 2026 (UTC)
- poorly written bc of having to deal with this shitty language thats not my first? just 1 guy contested to my edits, with the corrections being grammar or maybe redaction.
- Like I said everything I modified has a reliable source to back my edits, the only one with could-be doubious is the structure one bc you have to crawl through the leaked files to generate the structure, which, the guy I referenced did. The Shadow Brokers leak is CONFIRMED to be TAO's, the Equaiton Group is also confirmed (by the Shadow Brokers) to be the TAO, Michael V. Hayden, the guy who founded the Red Team among 3 of his peers published his book with all the Red Team's origins. All the other stuff is literally sourced by leaked intel I REFERENCED, as well as Investigations or coverage of Snowden's TSB's leaks, and nothing else. That's why I'm pissed off, I sourced everything with minor grammar/syntaxis mistakes (common for ESL).
- Sure, I can talk before massive changes, dully noted, but when I started I didn't know I had to update the whole page with info it is now commonly accepted as a fact due to its extensive archival and reporting. Conservadont (talk) 15:22, 3 June 2026 (UTC)
- At least three people complained about it. Regardless, you didn't lose anything. It's all still there in the history. You can take it paragraph by paragraph and revise them, and bring it up here for discussion and consensus. ⇒SWATJester Shoot Blues, Tell VileRat! 15:33, 3 June 2026 (UTC)
@Jellysandwich0: and @WAVELANDSHIELDDROP:, you may be interested in helping fix up the issues section by section below. ⇒SWATJester Shoot Blues, Tell VileRat! 22:39, 4 June 2026 (UTC)
Initial section & History
[edit]The current initroductory section contains parts that could be in the section regarding the Red Team instead of being a comment about the organisation tself:
"The Office of Tailored Access Operations (TAO), structured as S32, is a cyberwarfare intelligence-gathering unit of the National Security Agency (NSA). It has been active since at least 1998, possibly 1997, but was not named or structured as TAO until "the last days of 2000," according to General Michael Hayden.
TAO identifies, monitors, infiltrates, and gathers intelligence on computer systems being used by entities foreign to the United States."
this is current, after that it skips straight into snowden, when theres a lot more info publicly available of the years of the TAO between that. Theres more information in Michael Hayden's book pertaining the Red Team and TAO's origins, so that could be used for its own separatee sections, both expanding the history and making the introductory section more short and concise, but its not out of the conversation also expanding the initial section to contain a summary of the contents of the page as it is custormary to do; leaving it the following way:
(initial)
The Office of Tailored Access Operations (TAO), also known as Equation Group by Kaspersky[1] or APT-C-40 by China,[2] structured as S32,[3] is an elite cyberwarfare intelligence-gathering unit of the National Security Agency (NSA).[4][5][6][7]
TAO identifies, monitors, infiltrates, and gathers intelligence on computer systems being used domestically and by entities foreign to the United States.[8][9][10][11]
History
[edit]Red Team
[edit]The Red Team was created in 1997, with the objective to carry out Operation Eligible Receiver, which was envisioned to see the most amount of damage a group of skilled hackers could do, during the operation the team thrashed the Cybersecurity of the Department of Defense; it was later stopped after four days following concerns of stalling the functionality of the american military. After this mission, four people, Michael V. Hayden, Bill Marshall, Bill Black and Ken Minihan seeked to make this group a permanent section within the NSA, after seeing the value it would bring to the agency. They put together a team with members of different NSA branches, but after 9/11 and a new influx of budget centered around intelligence and countermeasures.[5][12][13]
It also adds the Equation Group label given by kaspersky and the tag by Chinese intel, also adding a very important "elite" and "domestic" remarks that are missing from the original.
The sources used are MIchael Hayden's' book, a documentary on The Shadow brokers that cointains a research and interviews with some TAO employees and another book about the TAO's origins and function in the US' cyberwarfare context Conservadont (talk) 14:55, 4 June 2026 (UTC)
- The Youtube Cybernews source can't be used (see WP:RSPYT); the other two are fine. ⇒SWATJester Shoot Blues, Tell VileRat! 01:49, 7 July 2026 (UTC)
- None of the three sources listed for the claim that the TAO = Equation Group actually state that; they state that there was TAO involvement in the creation of the tools used by Equation Group, which is not the same thing. Further, per our MOS, the lede sentence of an article only includes *significant* alternative names, as determined by common usage by reliable sources. Neither Equation Group nor APT-C-40 have remotely near enough common usage by reliable sources to meet that bar; TAO is nearly always referred to as TAO. This wasn't an improvement; please don't revert it back in again, particularly while discussion is ongoing. ⇒SWATJester Shoot Blues, Tell VileRat! 02:29, 7 July 2026 (UTC)
Snowden leak info
[edit]Its very important to establish the importance of the Snowden leak as the precursor to the Equation group report, which in turn became the biggest light shed upon the TAO, it being the following section under "Snowden Leak":
Snowden Leak
[edit]Edward Snowden received an offer to be part of the TAO, but declined the offer.[14]instead working for the intelligence consulting agency Booz Allen Hamilton, that was being contracted by the NSA.
After seeing the level of surveillance by the NSA he decided to leak several files to The Guardian and The Washington Post on June 9th, 2013, where the global surveillance operations by the TAO were in the eye of the storm.[15]
A document leaked by Snowden describes the unit's work in the following way: "The TAO has software templates allowing it to break into commonly used hardware, including "routers, switches, and firewalls from multiple product vendor lines".[16]
The amount of information now available of its targets and methods was so abundant that several security companies seeked to catch and expose the TAO red handed, with only one succeeding, Kaspersky, with its 2015 report "Equation Group: Questions And Answers", in which they named the TAO Equation Group, given its proclivity to use complex algorithms to avoid detection in their methods, those being so exaggerated that it was more than obvious that a highly skilled, trained and select group of people with enough time and resources were the perpretators of these sophisticated attacks.[17][1] Conservadont (talk) 04:48, 29 June 2026 (UTC)
- Several issues. Grammar -- the period after offer should be a comma. Content: Booz Allen Hamilton isn't just an intelligence consulting agency; they're a general services consulting agency that also specializes in intelligence (among other sectors). They have private and governmental clients in finance, banking, life-sciences, healthcare, space, transportation/logistics, and utilities management, basically anything with big data. They're the type of company that Office Space was satirizing. "After seeing the level of surveillance by the NSA" -- you haven't established what that level is yet, so this makes no sense, it just jumps from Snowden -- who was certainly already aware at that point of what NSA did and what TAO was -- getting a job at BoozAllen to committing enormous federal crimes. "where the global surveillance operations by the TAO were in the eye of the storm" -- this is unencyclopedic in tone, and should be rewritten neutrally. What is "the storm" -- be specific, objective, and neutral. "A document leaked by Snowden describes the unit's work in the following way: "The TAO has software templates allowing it to break into commonly used hardware, including "routers, switches, and firewalls from multiple product vendor lines"." -- just going to be honest, anything that is formatted in the template of "A document/article/story described X in this way: <a quote you could have just directly written>" screams LLM generated, even if it isn't (which I don't think this is) people are going to think it is because that's how ChatGPT 5.5 writes. "The amount of information now available of its targets and methods was so abundant that several security companies seeked to catch and expose the TAO red handed..." this is riddled with grammar errors and the "in flagrante delicto" easter-egg wikilink is wholly unnecessary.
Regardless of the factual accuracy of the claims or the correct basis of their sourcing, the problem is, and I don't mean this to give offense, but the writing is so bad that putting it in would make the article objectively worse. ⇒SWATJester Shoot Blues, Tell VileRat! 02:17, 7 July 2026 (UTC)
- change it then lol. Idc if its *my* writing, I just want *the information* to be out there, idc abt how you perceive my writing, as I've said, English is not my first language, this page pretty much gave up on adding new info like 5 years ago, so go ahead and rewrite it if you're so invested in wanting to change my shit lmao, if not, leave it idk, but its very important information to not have on the page. Conservadont (talk) 03:47, 7 July 2026 (UTC)
Readding the rest of the History (The Shadow Brokers)
[edit]very long to paste here and dont want to clutter the talk page; also I'm adding the grammar-corrected-edit of WAVELANDSHIELDDROP ( https://en.wikipedia.org/w/index.php?title=Tailored_Access_Operations&oldid=1357455753 ) so yeah. Conservadont (talk) 00:53, 7 July 2026 (UTC)
- Grammar-corrected how? Did you run it through an LLM? ⇒SWATJester Shoot Blues, Tell VileRat! 02:32, 7 July 2026 (UTC)
- dude it says right there, its the corrections WAVELANDSHIELDDROP made before my edits got reverted, why do you keep insisting I use an LLM? lol, make up your mind, either I laughably suck at english or i have perfect redacting skills, it clearly cant be both. I dont use any form of LLM for any reason, and, as I've said before, why do you not bother on correcting the info rather than just deleting it? its all confirmed if you look it up elsewhere other than my sources, you have only come here to delete my shit and say it sucks, instead of actually correcting and updating the article. Conservadont (talk) 04:45, 16 July 2026 (UTC)
- 1 2 Lab, Kaspersky (February 2015). Equation Group: Questions and Answers (PDF). Kaspersky.
- ↑ Lau, Lina (2025-02-18). "An inside look at NSA (Equation Group) TTPs from China's lense". Retrieved 2026-05-30.
- ↑ Nakashima, Ellen (1 December 2017). "NSA employee who worked on hacking tools at home pleads guilty to spy charge". The Washington Post. Archived from the original on 16 April 2021. Retrieved 4 December 2017.
- ↑ Loleski, Steven (2018-10-18). "From cold to cyber warriors: the origins and expansion of NSA's Tailored Access Operations (TAO) to Shadow Brokers". Intelligence and National Security. 34 (1): 112–128. doi:10.1080/02684527.2018.1532627. ISSN 0268-4527. S2CID 158068358.
- 1 2 Hayden, Michael V. (23 February 2016). Playing to the Edge: American Intelligence in the Age of Terror. Penguin Press. ISBN 978-1594206566. Retrieved 1 April 2021.
- ↑ Aid, Matthew M. (10 June 2013). "Inside the NSA's Ultra-Secret China Hacking Group". Foreign Policy. Archived from the original on 12 February 2022. Retrieved 11 June 2013.
- ↑ Paterson, Andrea (30 August 2013). "The NSA has its own team of elite hackers". The Washington Post. Archived from the original on Oct 19, 2013. Retrieved 31 August 2013.
- ↑ Kingsbury, Alex (June 19, 2009). "The Secret History of the National Security Agency". U.S. News & World Report. Archived from the original on 1 July 2016. Retrieved 22 May 2013.
- ↑ Kingsbury, Alex; Mulrine, Anna (November 18, 2009). "U.S. is Striking Back in the Global Cyberwar". U.S. News & World Report. Archived from the original on 1 July 2016. Retrieved 22 May 2013.
- ↑ Riley, Michael (May 23, 2013). "How the U.S. Government Hacks the World". Bloomberg Businessweek. Archived from the original on May 25, 2013. Retrieved 23 May 2013.
- ↑ Aid, Matthew M. (8 June 2010). The Secret Sentry: The Untold History of the National Security Agency. Bloomsbury USA. p. 311. ISBN 978-1-60819-096-6. Retrieved 22 May 2013.
- ↑ Cybernews (2025-07-03). The Biggest Hacking Mystery of Our Time: Shadow Brokers. Retrieved 2026-05-28 – via YouTube.
- ↑ Sloan, Peter (2017-09-06). "The TAO of Cyber Warfare: Dark Territory". Information Bytes. Archived from the original on 2025-12-07. Retrieved 2026-05-28.
- ↑ Kaplan, Fred (2016-09-16). "The Leaky Myths of Snowden". Slate. ISSN 1091-2339. Retrieved 2026-05-28.
- ↑ Walters, Joanna (2013-12-29). "NSA 'hacking unit' infiltrates computers around the world – report". The Guardian. ISSN 0261-3077. Retrieved 2026-05-28.
- ↑ Gellman, Barton; Nakashima, Ellen (August 30, 2013). "U.S. spy agencies mounted 231 offensive cyber-operations in 2011, documents show". The Washington Post. Retrieved 7 September 2013.
Much more often, an implant is coded entirely in software by an NSA group called, Tailored Access Operations (TAO). As its name suggests, TAO builds attack tools that are custom-fitted to their targets. The NSA unit's software engineers would rather tap into networks than individual computers because there are usually many devices on each network. Tailored Access Operations has software templates to break into common brands and models of "routers, switches, and firewalls from multiple product vendor lines," according to one document describing its work. TAO engineers prefer to tap networks rather than isolated computers, because there are typically many devices on a single network.
- ↑ Goodin, Dan (2015-02-16). "How "omnipotent" hackers tied to NSA hid for 14 years—and were found at last". Ars Technica. Retrieved 2026-05-28.
- C-Class Espionage articles
- High-importance Espionage articles
- C-Class Computing articles
- High-importance Computing articles
- C-Class Computer security articles
- Unknown-importance Computer security articles
- C-Class Computer security articles of Unknown-importance
- All Computer security articles
- All Computing articles
- C-Class United States articles
- Mid-importance United States articles
- C-Class United States articles of Mid-importance
- WikiProject United States articles
- C-Class Mass surveillance articles
- High-importance Mass surveillance articles
