Skip to content

From Operation Condor to Pegasus – A History of Latin American Surveillance

This investigation tracks the evolution of state surveillance in Latin America. From 1970s cryptographic hardware to modern digital spyware, we examine how systemic blindness and data siloing repeatedly bypassed legal oversight.

Modern fibre-optic cables connected to a vintage military communications switchboard in a dark concrete room.

In October 2024, Colombia’s President Gustavo Petro revealed that 11 million US dollars in cash had been flown out of Bogotá in 2021 to pay for Israeli spyware. This modern surveillance architecture echoes the secret networks of Operation Condor, which once linked intelligence regimes across South America. Just as in that Cold War era, the procurement involved foreign funding and a president who claimed total ignorance of the transaction.

Data Manifest

  • Primary Investigation: The structural transmission and procurement of state surveillance systems in Latin America, spanning from Cold War cryptographic hardware to modern digital spyware.
  • Key Anomalies Documented: Parallel un-warranted surveillance platforms in Colombia; conflicting governmental accounts of 11 million US dollar spyware funding flights; preventative cyber patrolling decrees bypassing intelligence laws in Argentina.
  • Primary Sources Utilised: Declassified CIA cables (1975 to 1978); Privacy International investigations (2017); Boletín Oficial de la República Argentina; White House and Colombian presidential statements (2024).

Glossary

  • Cipher machine: A mechanical or electronic device that scrambles messages into code so only the intended recipient with the matching key can read them.
  • Zero-click exploit: A cyberattack that infects a phone or computer without the user clicking anything, often by sending a hidden message that triggers the install on arrival.
  • Judicial warrant: A written order signed by a judge that gives police or intelligence services formal legal permission to carry out a specific search, wiretap, or surveillance act.
  • End-User Licence Agreement (EULA): A contract between a software company and its buyer that sets out exactly how the software can and cannot be used.
  • OSINT (Open-Source Intelligence): Information gathered from publicly available sources, including social media posts, news articles, and online forums, rather than from secret informants or intercepted communications.
  • IMSI catcher: A portable device that imitates a mobile phone tower in order to trick nearby phones into connecting to it, allowing the operator to capture identifying data and sometimes calls or messages.

Legacy of the Hagelin Compromise in South America

In 1970, Boris Hagelin sold Crypto AG to West Germany’s foreign intelligence service, the BND. Shortly afterwards, the United States Central Intelligence Agency bought a covert share of the company. To the regimes that purchased its cipher machines (devices that scramble messages into code so only the holder of the matching key can read them), Crypto AG still presented itself as a neutral Swiss manufacturer.

The buyers, by the mid-1970s, included the military governments of Argentina, Chile, Uruguay, Paraguay and Bolivia.

On 28 November 1975, intelligence officers from those five regimes signed a document in Santiago titled the ‘Closing Statement of the First Inter-American Meeting of National Intelligence‘. That text formally founded Operation Condor. A facsimile of the signed Acta de Clausura now sits inside the National Security Archive’s Chile Documentation file.

Then came a CIA cable dated 25 June 1976. It described the creation of a ‘computerised data bank’ designed to centralise intelligence registries across the Condor regimes.

A second cable, dated 12 August 1976, set out Brazil’s role inside the cooperative arrangement and discussed the dedicated Condor communications channel.

The hardware feeding that channel arrived from inside the network. In February 1977, CIA agents reported that the Brazilian military had supplied Hagelin CX52 machines to the Condor states. Later that year, the United States Defense Intelligence Agency noted that Argentina had handed over Hagelin Crypto H-4605 teletype equipment for the same circuit.

Both models were already inside the product line that the CIA and BND were quietly reading at source.

On 20 October 1978, United States Ambassador to Paraguay Robert White sent a report describing how Condor intelligence chiefs kept in contact through United States communications infrastructure. Our research pack identifies that infrastructure as the United States installation in the Panama Canal Zone. The cable excerpt available to us does not specify whether American operators decoded the traffic or simply routed it onwards.

That question has been live in the public file for forty-eight years.

The Hagelin Compromise Chain

Ownership and Hardware Transmission (1970 to 1978)

The Compromised Source

Crypto AG

Acquired by West German BND in 1970. CIA subsequently buys a covert share of the company.

The Hardware Transfer

Condortel Network

Brazil supplies Hagelin CX52 machines (February 1977). Argentina supplies Hagelin H-4605 teletype equipment (late 1977).

The Terminating Node

Panama Canal Zone

United States communications infrastructure facilitates Condor intelligence chief contact (October 1978).

National Security Archive, 'The CIA's Minerva Secret' and declassified CIA cables (11 February 2020) .

Evolution of State Surveillance Infrastructure

By the time the Cold War surveillance networks had been formally dismantled, Colombia had a single lawful interception system called Esperanza, run by the Attorney General’s Office and supported by the United States Drug Enforcement Administration. Esperanza required a judicial warrant (a written order signed by a judge giving police formal legal permission to carry out a specific wiretap) for each target. That paperwork created friction.

In September 2005, Colombia’s Police Intelligence Directorate, known as DIPOL, began building a parallel platform called the Integrated Recording System using technology from the Israeli firm Verint Systems. By 2007, the police investigation unit DIJIN had set up its own equivalent, named PUMA, plugged directly into the backbone of Colombia’s telecommunications network.

Both new systems sat outside the warrant pipeline that governed Esperanza.

Privacy International’s 2017 ‘Shadow State’ report puts the collection capacity of the DIPOL Integrated Recording System at roughly 100 million call data records per day. That figure has never been confirmed by the Colombian government. Nor has it been formally denied.

Then came February 2009.

On 21 February, the Colombian newspaper El Espectador exposed the ‘chuzadas’ wiretapping scandal, revealing that the Administrative Department of Security (DAS) had illegally surveilled over 600 public figures using Esperanza. Among those public figures sat Supreme Court justices, opposition politicians and journalists.

Institutional response landed on DAS alone.

President Juan Manuel Santos dissolved the Administrative Department of Security through Decree 4179 of 3 November 2011. Decree 4179 did not touch DIPOL’s Integrated Recording System or DIJIN’s PUMA, both of which had already been operational for years.

Migration of Interception Capability

Baseline (Pre-2005)

DAS operates 'Esperanza'. A judicial warrant is strictly required for each target.

Parallel Infrastructure (2005 to 2007)

DIPOL builds 'Integrated Recording System' (2005). DIJIN sets up 'PUMA' platform (2007). Both systems operate completely outside the Esperanza warrant pipeline.

The Chuzadas Scandal (2009)

DAS exposed for illegally wiretapping over 600 public figures, including journalists and judges, using Esperanza.

Institutional Response (2011)

DAS is dissolved via Decree 4179. DIPOL and DIJIN parallel surveillance platforms remain untouched and operational.

Privacy International, 'Shadow State: Surveillance, Law and Order in Colombia' (December 2017).

Surveillance Technology and the Pegasus Deployment

On 22 October 2024, President Gustavo Petro held a press conference and stated that two private jets had carried 11 million US dollars in cash out of El Dorado International Airport in 2021. According to Petro, one flight left Bogotá on 26 June 2021 with 5.5 million US dollars on board. A second left on 18 September 2021 carrying an identical sum.

Petro named the destination as Tel Aviv and the recipient as the Israeli firm NSO Group, maker of the Pegasus spyware. Pegasus, in turn, runs through a ‘zero-click’ exploit (a method that infects a phone without the user clicking anything, usually delivered through a hidden message that triggers the install on arrival).

Petro’s statement gave the tail numbers M-ABGG and T7CPX, and the wire reporting that followed carried them forward. Neither shows up in the raw cable or court material available to us.

What is documented is the timing. Colombia’s National Police intelligence directorate, DIPOL, acquired and deployed Pegasus during the same months that mass protests were spreading across the country. Forensic analysis under the Pegasus Project investigation has subsequently shown that the spyware was used against journalists and opposition figures in several countries.

Petro went further. He alleged the cash was laundered money, possibly siphoned from drug-cartel seizures, and said NSO’s chief executive sat in the room when it changed hands. Washington tells the opposite story. White House officials confirmed in November 2024 that the cash came from authorised United States anti-narcotics assistance.

NSO supplies a buyer contract that permits use of Pegasus only for counter-terrorism and serious crime.

That permission did not match the operational record.

The most unusual feature of the 2021 procurement is the absent name at the top of it. Colombia’s sitting president, Iván Duque, has been confirmed through subsequent White House and ambassadorial statements to have had no knowledge of the purchase.

By the time the matter became public in October 2024, Pegasus had been operating inside Colombia for more than three years.

Priority Briefings

New investigations, evidence checks, and unresolved questions from Veriarch, sent directly to your inbox.

Divergent Accounts of Pegasus Funding

Two governments have given two completely different accounts of where the cash came from.

Petro spoke first. His October 2024 press conference framed the 11 million dollars as criminal cash, laundered through international channels and possibly siphoned from drug-cartel seizures. On Bogotá’s account, the 2021 procurement sits outside Colombia’s lawful budgetary process.

Washington answered the following month. White House officials said the funding had come from authorised anti-narcotics assistance, with the spending correctly logged on their side of the border.

Three years after the cash departed, neither side has produced a single document naming the federal agency that handed it over.

Divergent Accounts of Pegasus Funding

Claim Variable Bogotá Says (Petro, Oct 2024) Washington Says (White House, Nov 2024)
Funding Origin Criminal cash laundered through international channels, possibly siphoned from drug-cartel seizures. Legitimate and authorised United States anti-narcotics assistance funding.
Legal Characterisation Illegal procurement sitting outside Colombia's lawful budgetary process. Authorised spending correctly logged on the United States side.
Executive Awareness Procurement completed completely bypassing sitting President Iván Duque. Confirmed that Iván Duque had no knowledge of the purchase.
ColombiaOne and Latin America Reports (October to November 2024).

Regulatory Shifts in Argentine Intelligence

In Argentina, the friction comes from a different direction. National Intelligence Law 25.520 requires a judge’s signature before any state agency can gather intelligence on a citizen. That requirement was built specifically to prevent the political profiling that defined the dictatorship years.

Resolution 144/2020 hit the Boletín Oficial on 2 June 2020. Argentina’s Ministry of Security used it to authorise federal forces to carry out what they called ‘ciberpatrullaje’ (cyber patrolling) across open digital sources, including public social media accounts.

We knew it was near the end of May 2020, the Boletín Oficial’s stamp reads 2 June.

Relabelled as crime prevention rather than intelligence work, the activity now sat outside Law 25.520 entirely. On paper, the shift looked purely semantic. In operational reality, an algorithmic monitoring tool sitting inside the federal police could now run on civilian profiles without a judge signing anything.

Five years later, the decree itself arrived.

Decree 383/2025 appeared in the Boletín Oficial on 17 June 2025. It permits warrantless cyber patrolling and authorises identity-verification detentions of up to ten hours. A separate clause in the same decree bans profiling by political opinion or race. No enforcement language sits alongside that ban.

What ‘open source’ means in operational practice, and what ten hours of identity verification looks like at a police station, has yet to be reported in any public Argentine court filing.

Support the Archive

Help fund the retrieval, hosting, and preservation of Veriarch investigations.

DONATE >

Architecture of State Surveillance Networks

Two structural features carry across both eras.

In each case, the technical architecture came from outside the deploying state. Hagelin cipher machines arrived from Switzerland (where the brand was registered) via Brazil and Argentina in the 1970s. Verint Systems hardware and NSO Group spyware arrived from Israel from 2005 onwards.

End users never controlled the build of the platforms they were buying.

Across both eras, the elected executive lost sight of the operational reality. The Condor states believed they were transmitting through a neutral Swiss cipher; the records show their traffic was readable at source by Washington and Bonn. President Duque believed Colombian state procurement ran through his desk; an 11 million US dollar transaction completed without his signature.

No item in the documentary record proves that any supplier state or contractor intends the eventual diversion of these tools against political opponents. Crypto AG’s full project file remains classified above the level at which most cables cited in this investigation were declassified.

What we see in both eras is a structural pattern, not a directed one. Where the boundary of that finding sits, and what would push past it, is the subject of the next section.

Structural Pattern of State Surveillance

The Failure Chain Across Two Eras

1. Institutional Blindness

Cold War: Condor states believed they were transmitting through a neutral Swiss cipher.
Digital Era: Colombian executive branch bypassed entirely during the Pegasus spyware procurement.

2. Data Siloing

Cold War: BND and CIA read intercepted data at source, siloed from hardware buyers.
Digital Era: DIPOL and DIJIN operated parallel, non-warranted interception platforms completely separate from DAS.

3. Procedural Dogma

Cold War: Rigid reliance on acquired hardware despite clear foreign supply chains.
Digital Era: Reclassifying intelligence gathering as preventative 'cyber patrolling' to bypass warrant requirements in Argentina.

4. Official Record Anomalies

Cold War: Exact decryption operations at the Panama Canal Zone remain unconfirmed in public files.
Digital Era: Conflicting national accounts of the 11 million US dollar Pegasus transaction.

Synthesised from National Security Archive declassified cables (2020) and Privacy International country investigations (2017 to 2024).

Source

Sources include: declassified Central Intelligence Agency cables regarding the Condortel network (1976 to 1978); official statutory records from the ‘Boletín Oficial de la República Argentina’ (Decreto 383/2025 and Resolución 144/2020); civil society technical investigations from Privacy International including ‘Shadow State’ (2017); and public statements from the White House and Colombian President Gustavo Petro regarding the 2021 Pegasus spyware procurement.

Claim-Source Matrix

Core Finding Primary Source Document Status
Hagelin's 1970 transfer of Crypto AG to the BND. The CIA's 'Minerva' Secret Unclear/Unsupported (Specific date and sum unsupported in raw text)
CIA cable establishing a computerised data bank across Condor regimes. Operation Condor: A Network of Transnational Repression Confirmed (Date corrected to 25 June 1976)
Dissolution of DAS by President Santos via Decree 4179. National Intelligence Directorate (Colombia) Confirmed (Date corrected to 3 November 2011)
Pegasus purchased with 11 million US dollars in cash flights in 2021. President Gustavo Petro statements / ColombiaOne Confirmed (Attributed to Petro; tail numbers unverified in raw files)
Funds for Pegasus were legitimate US anti-narcotics assistance. White House Statements (November 2024) Confirmed
Cyber patrolling authorised outside Law 25.520 requirements. Resolución 144/2020 / Decreto 383/2025 Confirmed

What We Still Do Not Know

  • Whether the United States installation in the Panama Canal Zone actively decrypted Condor message traffic between 1975 and 1978, or simply relayed encrypted material to be read elsewhere later.
  • Which United States federal agency physically delivered the 11 million US dollars in cash to Colombian police intelligence in 2021, and under what statutory budget line that cash was released.
  • Where the data scraped by DIPOL's Integrated Recording System and DIJIN's PUMA platform is physically held, and what statutory retention period governs civilian communications collected without a judicial warrant.
  • What keyword lists, search parameters and open-source intelligence software contracts the Argentine Federal Police are running under Decree 383/2025.
  • Whether NSO Group has enforced any contractual sanction against state operators deploying Pegasus outside its End-User Licence Agreement in connection with the 2021 Colombian deployments.
  • Which commanding officer inside DIPOL authorised and signed the 2021 Pegasus targeting orders, and from which physical terminal the spyware was operated against journalists and opposition figures.
PRIORITY_NEWSLETTER_BRIEFINGS

Archive Updates

New Veriarch investigations and unresolved questions, sent directly to your inbox every other week.

CONNECTION SECURE. UNSUBSCRIBE AT ANY TIME.

Comments (0)

Leave a Reply

Your email address will not be published. Required fields are marked *

Back To Top