NSA Holds First-Ever Reunion to Refill TAO After DOGE Drained Its Hacker Ranks | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


The National Security Agency (NSA) headquarters at Fort Meade, Maryland, as seen from the air, January 29, 2010.
SAUL LOEB/AFP via Getty Images

On August 28, Fort Meade briefly resembled a college homecoming: potentially hundreds of former elite hackers filed back through the gates of the National Security Agency for an alumni recruitment reunion event that was, at its core, a recruiting pitch — a signal that the agency’s most feared offensive cyber unit is hurting for people. The event marked the first time in the history of Tailored Access Operations — the secretive NSA hacking division credited with co-creating Stuxnet and building the tools that would later fuel two of the most damaging cyberattacks in history — that the agency had opened its campus to its own alumni in a formal bid to win them back.

The timing was no accident. DOGE-era workforce cuts cost the NSA roughly 2,100 employees in 2025 — approximately 8% of its total workforce — driven by DOGE-linked NSA downsizing goals, and dozens of TAO operators were among those who left. The reunification is not a triumphant comeback for a unit operating at strength. It is a damage-control operation dressed in nostalgia.

The unit has a new standalone building on the Fort Meade campus, a restored name, and a deputy director personally invested in its revival. Whether any of that is enough to bring back the operators the agency needs — and whether those operators would accept the trade — is what August 28 was designed to test.

What Made TAO Different From Every Other NSA Office

TAO specializes in computer network exploitation capabilities: gaining access to foreign systems, planting persistent implants, and leaving intelligence-collection software behind that can remain active for months or years. Its technical architecture, documented in materials released by Edward Snowden and later by the Shadow Brokers group, included a suite of capabilities that distinguished it from conventional signals intelligence. The QUANTUM man-on-the-side framework, for instance, operated by routing duplicated internet traffic through compromised infrastructure so that NSA servers could inject exploits into a target’s browser before the legitimate destination could respond — a technique requiring backbone-level access. The Advanced Network Technology (ANT) division supplied hardware and software implants for routers, switches, and firewalls from Cisco, Dell, and others. Operators did not walk in and exploit zero-days; they followed a TAO persistence-focused hacking doctrine — mapping target networks methodically, securing persistent footholds, and gathering intelligence over extended timeframes.

That culture produced something the NSA’s broader bureaucratic structure could not: operational creativity and mission coherence at speed. TAO grew from several hundred personnel in its early years to more than 2,000 before the agency’s 2016 internal restructuring — dubbed NSA21 — made a NSA21 developer-operator separation decision that disbanded it as a standalone office and redistributed its capabilities across broader directorates. Former employees describe the reorganization as a mistake. “NSA21 was not looked at as a useful thing,” one former agency employee told The Record. “We were on a path to move developers and operators closer. They split them apart instead.”

Why the Tools TAO Built Became a Liability

The Shadow Brokers changed everything. Beginning in August 2016, the mysterious group — whose identities remain unknown and whose methods suggested state-level access — began Shadow Brokers exploitation toolkit releases of TAO’s capabilities. The most damaging release came in April 2017, when a dump titled “Lost in Translation” contained EternalBlue — an EternalBlue SMBv1 exploit release targeting a vulnerability in Microsoft’s file-sharing protocol. Microsoft had issued a patch 59 days before the release, but tens of thousands of organizations had not applied it.

The consequences were global and severe. On May 12, 2017, WannaCry — a ransomware worm built on EternalBlue — WannaCry infected global systems across more than 200,000 computers in 150 countries within a single day. The UK’s National Health Service was among the hardest hit, absorbing NHS 92 million recovery costs and canceling thousands of patient appointments. Global damages from WannaCry have been estimated as high as $4 billion, though that figure reflects a modeling projection rather than a measured sum. Six weeks later, in June 2017, the NotPetya data wiper — also built on EternalBlue — NotPetya caused 10 billion damage across Ukraine, Russia, Europe, and the United States.

The tools TAO built to penetrate foreign networks had become instruments of global disruption, deployed not by the agency but by the adversaries the agency was designed to counter. For a unit whose operational security doctrine depends on tools staying under its control, the Shadow Brokers episode was a foundational trauma — and a lesson in what is at stake when elite operators and the tools they build are not safeguarded.

DOGE Drains the Unit That Built Stuxnet

The NSA’s workforce did not shrink quietly. By December 2025, the agency had NSA met 2000-person reduction goal — roughly 8% of a total workforce that a Maryland state fact sheet had previously placed at around 39,000. The exact number of TAO-specific departures is classified, but a former NSA official speaking to The Record put it at employees in the “low dozens.”

The damage was not limited to headcount. In March 2025, Rob Joyce — who served as TAO’s chief from 2013 to 2017 and again as NSA’s director of cybersecurity from 2021 until his retirement in 2024 — warned Congress directly. Testifying before the House Select Committee on the Chinese Communist Party, Joyce delivered a Joyce devastating impact warning that the cuts would have a “devastating impact on cybersecurity and our national security.” He warned that eliminating probationary employees would “destroy pipeline of top talent, essential for hunting and eradicating PRC threats” — and added that even positions not formally eliminated would lose people, because the atmosphere of uncertainty drove skilled operators to seek employment outside government.

The structural problem TAO faces is not simply that operators left. It is that getting them back — or replacing them — takes time the agency does not have. The TAO certification pipeline takes one year to complete even for people already familiar with the classified environment, including both the security vetting more rigorous than the NSA’s standard top-secret clearance and a technical operator certification. “That’s to certify at the baseline level so that you can operate on your own right,” one former TAO operator told The Record. Every dozen operators who leave represent a dozen year-long pipelines the agency now has to run before it regains what it lost.

How DOGE Paradoxically Created TAO’s Fastest Shortcut

The reunion was not primarily about luring ex-operators back from the private sector. It was about luring them back from the contractor offices next door. A significant portion of former TAO government employees still work at Fort Meade — now wearing contractor badges rather than the blue credentials associated with direct government employment. This “blue/green split,” as a former NSA official described it to The Record, is the article’s central irony: the people TAO needs are often already on campus, doing adjacent work, holding active clearances, but contractually unable to work on the classified government-only projects that require “an inherently governmental body to do what it is.”

Converting contractors back to direct government employment bypasses both the extended certification pipeline and the top-secret vetting process — the two bottlenecks that make new TAO hires so slow to field. It is, as the agency clearly calculated, faster than recruiting and training someone new. Whether former operators will accept the trade — giving up contractor salaries that can exceed government pay significantly — is the variable the reunion was designed to test.

The Signal Problem

The logistical mechanics of the August 28 reunion revealed tensions the NSA would likely prefer not to publicize. The agency initially organized the event through the National Cryptologic Foundation — a preservation nonprofit organizationally separate from NSA — before eventually creating an invitation-only Signal group chat to communicate with prospective attendees. The channel, dubbed “Terminated Async Operations” — a double reference to the TAO acronym and the computing concept of a background process — grew to hundreds of former hackers, developers, and analysts sharing shift memories and inside jokes about past operations.

The use of Signal is unremarkable within the intelligence community’s day-to-day communications, but in the context of the second Trump administration, it carried unavoidable symbolic weight. Defense Secretary Pete Hegseth became the subject of a Hegseth Pentagon IG Signal report this year after sharing operational details of an impending military strike in Yemen on his personal phone — and inadvertently adding a journalist to the Signal thread. That same Defense Secretary had visited Fort Meade in early July 2026, was briefed on the revamped TAO structure, and posted a photo of a signed TAO hat to his official X account.

Former TAO members in the Signal group were direct about the risks. “To be clear, nobody’s gone classified because everybody’s too pretty for jail,” one participant told The Record. “But if internal security saw it? They’d have a fucking aneurysm.”

NSA Deputy Director Tim Kosiba and the Strategic Bet

The reunion was, by multiple accounts, the personal project of Tim Kosiba, who became Kosiba as NSA Deputy Director in January 2026. Kosiba is himself a TAO veteran who served as the unit’s technical director before ascending to the agency’s No. 2 role. He spearheaded the July 2026 renaming that restored the “Tailored Access Operations” brand, overturning NSA21’s decade-old decision to dissolve the office into broader directorates. He was an active participant in the Signal group chat organizing the reunion, and he delivered the recruitment pitch on August 28 personally, according to multiple attendees.

The argument Kosiba has been making internally, and which former personnel echo publicly, is that NSA21 made a fundamental error in separating TAO’s developers from its operators. Concentrating the two functions under one roof — literally, given that TAO now has a new standalone building on the Fort Meade campus — restores the creative and operational dynamic that made the unit effective. Former employees also argue that the TAO name itself carries weight with adversaries and with the talent market. The NSA said the TAO name restored powerful identity that has resonated deeply and that it is honoring the unit’s history of mission outcomes to propel it into the future.

The question the reunion leaves unanswered is whether brand equity is enough. Several former TAO operators told The Record they would not be returning to government service, regardless of the pitch. The structural pull in the other direction — contractor pay, private-sector flexibility, and the memory of the DOGE-era uncertainty that drove so many people out in the first place — does not disappear because the office has a famous name again.

Can a Reunion Fix a Structural Pay Gap?

The deeper challenge the NSA faces in rebuilding TAO has nothing to do with brand identity or certification pipelines. It is the same challenge that has defined government technical recruitment for decades: government salaries cannot compete with the private sector for elite offensive cyber talent. Former NSA officials have acknowledged publicly that skilled operators face pressure to seek employment elsewhere not because they lack mission commitment but because the uncertainty created by political interference in the workforce makes long-term government service an unreliable career bet. Joyce’s March 2025 testimony made this explicit: even positions that survived the DOGE cuts were hemorrhaging talent, because operators were watching colleagues get fired and concluding that no NSA badge was secure.

A reunion can reach alumni who still hold clearances and miss the mission. It cannot change the compensation structure that made them leave — or the political environment that could drive away whoever comes back.


Frequently Asked Questions

What is Tailored Access Operations, and why was it renamed twice?

TAO is the NSA’s elite offensive cyber unit, established in the late 1990s to penetrate foreign computer networks for intelligence collection. At its peak it had more than 2,000 personnel. In 2016, NSA Director Mike Rogers’s NSA21 restructuring disbanded it as a standalone office and renamed it the Office of Computer Network Operations, distributing its capabilities across broader directorates. Critics inside the agency later argued this fragmented the developer-operator collaboration that made TAO effective. In July 2026, NSA Deputy Director Tim Kosiba — a TAO veteran — reversed that decision, restoring TAO’s name and mission and reunifying the office’s technical and operational functions under a new standalone building at Fort Meade.

What is EternalBlue, and what does it have to do with TAO?

EternalBlue is a cyberweapon developed by TAO that exploited a vulnerability in Microsoft’s file-sharing protocol (SMBv1). It was stolen and released by the Shadow Brokers group in April 2017. North Korea’s Lazarus Group repurposed it for the WannaCry ransomware attack in May 2017, infecting more than 200,000 systems across 150 countries. Russia-linked actors then used it for NotPetya weeks later, causing an estimated $10 billion in global damage. EternalBlue illustrates the core risk of state-level offensive cyber development: a tool built to penetrate foreign networks can become a weapon of mass disruption if it leaves government control. For a deeper breakdown, see the WannaCry and EternalBlue analysis.

Will the TAO reunion actually solve the talent problem?

The reunion targets a specific and finite pool: former TAO operators who still hold active clearances and already work at Fort Meade as contractors. Recruiting them back to direct government employment bypasses the year-long certification pipeline and security vetting that make new TAO hires so slow to field. But the event cannot address the structural forces — government salary ceilings, career uncertainty, and the memory of the DOGE-era cuts themselves — that drove the attrition in the first place. Former TAO operators speaking to The Record were candid: several said they would not be returning to government service regardless of the pitch. A reunion can appeal to mission loyalty; it cannot legislate pay parity.

How does the DOGE-era NSA talent loss affect ordinary Americans?

TAO’s mission is to penetrate and monitor foreign government systems, infrastructure operators, and adversary military networks. Its intelligence products inform U.S. policymakers, military commanders, and diplomatic negotiators. A degraded TAO means slower intelligence on adversary plans — slower detection of the kind of Chinese infrastructure intrusion campaigns that Rob Joyce warned Congress about in March 2025, and slower deterrence signaling to adversaries who calculate U.S. offensive capability when deciding whether to escalate. For ordinary Americans, the connection is indirect but real: the NSA’s capacity to know what China’s cyber operators are doing inside U.S. telecommunications networks depends on having enough trained TAO operators to run the collection and analysis pipelines that produce that knowledge. Joyce’s congressional testimony on cyber talent laid out the stakes in precise terms.



Click Here For The Original Source.

——————————————————–

..........

.

.