In June 2021, the FBI and Australian Federal Police announced they had spent three years secretly running ANOM - an encrypted communications platform that criminal organizations believed was their most secure option. By the time law enforcement moved in, 9,000 devices were in active use across 100 countries, transmitting roughly 27 million messages from drug traffickers, money launderers, and organized crime groups. Agents had been reading every word in near-real-time.
The operation, codenamed Trojan Shield in the US and Greenlight in Australia, produced 800 arrests, the seizure of 8 tonnes of cocaine, 22 tonnes of cannabis, 250 firearms, and $48 million in various currencies and cryptocurrencies. It was described by Europol as "the largest operation against encrypted criminal communications" ever conducted. What made it extraordinary was not just the scale - it was that law enforcement had not cracked someone else's platform. They had built and operated the entire thing from scratch.
The Halo Device and Its Unexpected Opportunity
The story begins with an informant inside the criminal encrypted phone market and a device called Halo. Around 2018, a high-level distributor of Phantom Secure - a Canadian encrypted phone company dismantled by the FBI in March 2018 - found himself with a problem. Phantom Secure's CEO Vincent Ramos had just been arrested after a six-year FBI investigation demonstrated that his company knowingly provided encrypted Blackberry devices with tracking and camera functions removed, specifically sold to criminal networks. Ramos pleaded guilty and received a nine-year sentence.
With Phantom Secure gone, a gap opened in the criminal communications market. The FBI's informant, whose identity has not been publicly disclosed, had been developing an independent encrypted device called Halo and approached the bureau with a proposal: instead of trying to penetrate existing criminal communications platforms through legal process or hacking, why not become the platform? The FBI agreed.
The Technical Architecture
ANOM devices were modified Android phones - typically Sony Xperia handsets or Google Pixels - with all standard communication functions disabled. The camera, GPS, phone calls, and standard messaging were all stripped out. The only functionality was the ANOM encrypted messaging application, which presented as a calculator app to anyone who did not know the unlock code.
The encryption itself was real. Messages between ANOM users were genuinely end-to-end encrypted. But the FBI had designed a silent master key into the system. Every message was also encrypted to a third party key controlled by law enforcement, and the messages were routed through an ANOM-controlled server in a country with a mutual legal assistance treaty with the United States - initially reported to be a country in the Asia-Pacific region, later identified in court documents as ICLEF (an FBI-affiliated entity). Before reaching the recipient, every message was silently copied and forwarded to the FBI.
The architecture exploited a feature common to many encrypted messaging systems: the ability to add additional recipients to an encrypted conversation without the primary parties being aware. In PGP terms, this is equivalent to encrypting every message not just to the recipient's public key, but also to a silent third key. The recipient decrypts normally and sees a clean, unmodified message. Law enforcement decrypts the parallel copy with their master key and reads the same plaintext.
Building Credibility Through the Network
The FBI's strategy for distribution relied on criminal word-of-mouth rather than advertising. The informant seeded the initial devices through existing criminal networks, with early adopters including an Australian drug trafficking syndicate and Mexican cartel-connected distributors. The pitch emphasized that ANOM was new, uncompromised, and run by people "in the life" rather than legitimate tech companies that might cooperate with law enforcement.
This was the central irony of the operation: the criminal market's deep distrust of legitimate encrypted services - Signal, WhatsApp, even ProtonMail - because those companies might respond to legal process, made them eager for alternatives run by people outside the law. ANOM's criminal provenance, presented as a feature, was the very quality that made it an FBI operation. The informant's existing reputation within criminal networks served as social proof that could not be replicated through any official channel.
Growth was steady. Within two years, ANOM had spread to 300 criminal syndicates across more than 100 countries. The biggest concentrations were in Australia, Europe (particularly Germany, the Netherlands, and Spain), and organized crime networks in Southeast Asia and Latin America. Devices were sold through criminal distributors for roughly $1,700 to $2,000 each, with a monthly subscription fee of $100 to $150.
What Investigators Saw
The intelligence collected through ANOM was, by all accounts, overwhelming in both volume and operational significance. Investigators monitored discussions of drug shipments including the exact container numbers on cargo ships, planned murders (approximately 150 cases where ANOM intercepts were used to warn potential victims and prevent killings), corruption of police officers and customs officials, and the financial structures of money laundering operations.
In some cases, law enforcement's access was so complete that agents tracked shipments from production through transport to delivery. Australian Federal Police intercepts revealed conversations about tunneling cocaine under a house in Queensland. Spanish investigators identified a network coordinating multi-tonne cocaine shipments from Colombia to European ports. Dutch investigators found discussions of professional hit contracts.
Investigators faced a continuous dilemma about how much to act on. Every interdiction or arrest risked alerting the broader network that ANOM was compromised. For three years, agencies around the world made careful decisions about what intelligence to act on immediately and what to preserve by allowing to proceed, building toward the eventual synchronized takedown.
The Parallel Collapses: EncroChat and Sky ECC
ANOM did not operate in a vacuum. The same period saw two other major criminal encrypted phone networks compromised through different means, which may have accelerated ANOM's growth and simultaneously complicated law enforcement's timing.
EncroChat, which had approximately 60,000 users at its peak including an estimated 90% criminal clientele by the French Gendarmerie's analysis, was penetrated by French and Dutch authorities through a technical implant deployed to the platform's servers in 2020. The implant bypassed the device-level encryption by capturing messages on the server side before they were deleted, and collected approximately 100 million messages. The operation resulted in over 800 arrests across Europe. EncroChat's operators noticed the implant in July 2020 and shut down the network, warning users it had been "hacked by government entities."
Sky ECC, another platform used heavily by European criminal organizations, was compromised by Belgian and French authorities in early 2021. The takedown of Sky ECC, announced in March 2021, displaced another large population of criminal users looking for an alternative - users who found ANOM available and apparently untouched.
Law enforcement's challenge was that each collapse sent displaced users scrambling to alternatives, and those users would be particularly alert for signs of compromise. The timing required synchronized global action to prevent ANOM's users from learning about the operation before the arrests could be made.
Operation Day: June 7-8, 2021
After three years of intelligence collection, Operation Trojan Shield culminated in coordinated raids across 16 countries on June 7 and 8, 2021. The FBI, Australian Federal Police, Swedish Police Authority, Dutch National Police, German BKA, and dozens of other agencies moved simultaneously. The US Department of Justice unsealed an indictment against one Australian citizen, a primary distributor, along with RICO charges connecting ANOM to 12 specific criminal organizations.
In Australia, 224 people were arrested in early morning raids across New South Wales, Victoria, Queensland, South Australia, and Western Australia. In Europe, Germany arrested 70 people, Sweden 155, the Netherlands dozens more. In total, across all participating jurisdictions, approximately 800 people were arrested on the initial operation day with further arrests continuing for weeks as the full intelligence picture was analyzed.
The seized material included not just drugs and cash but extensive documentation of criminal network structure: the phones themselves, once in law enforcement hands, provided a directory of who was talking to whom, how organizations were structured, and who held leadership roles. The three years of message archives became evidence files.
The Legal Challenges
ANOM prosecutions have faced consistent legal challenges in multiple jurisdictions, centering on a few key issues.
The first is the question of whether the mass surveillance of device users - many of whom had not yet committed any prosecutable offense at the time of collection - violated constitutional or human rights protections. In Australia, defense lawyers argued that the ANOM warrant framework did not adequately authorize bulk surveillance of Australian citizens. Several cases were stayed or dismissed pending resolution of this question.
The second is what lawyers term "fruit of the poisonous tree" extended to the international context: if the evidence collection method was unlawful under EU law (as some courts found for EncroChat evidence), does that taint the prosecutions built on it? The European Court of Human Rights has seen challenges from EncroChat defendants, with implications for ANOM.
The third challenge is specific to the FBI's use of a confidential informant as the platform's operator. Defense attorneys have argued that law enforcement's intimate involvement in building and operating the platform that their clients were using amounted to entrapment, and that the informant's financial compensation - reported to include a commission on each device sold - created perverse incentives.
The Informant's Fate and the Market After ANOM
The FBI's informant, referred to in court documents only as CHS (Confidential Human Source), received an undisclosed financial arrangement for their role in building and seeding the platform. Court documents revealed the informant received a total of approximately $120,000 and a boat - compensation that defense attorneys characterized as grossly inadequate given the scale of the operation and the informant's central role, and that prosecutors described as appropriate for a cooperating witness arrangement.
Following ANOM's exposure, the criminal encrypted phone market did not collapse - it fragmented. Smaller, harder-to-infiltrate services proliferated. Some organizations moved toward fully self-hosted solutions running on standard hardware. Others shifted to legitimate but pseudonymous services like Signal, accepting that while Signal is genuinely encrypted, the metadata (who is talking to whom, when) remains potentially visible. Some moved toward decentralized, blockchain-based messaging protocols where there is no central operator to compromise.
Law enforcement's assessment, expressed in various post-operation briefings, is that ANOM demonstrated the utility of supply-side interdiction: rather than trying to crack encryption after the fact, controlling the platform from inception provides indefinite access. But the operation's exposure also educated criminal operators about exactly this vulnerability, accelerating adoption of decentralized and open-source tools that are harder to backdoor.
Implications for Cryptographic Trust
ANOM is a case study in why cryptographic security cannot be separated from institutional trust. The encryption was real. The problem was that users trusted a platform operator who was working for the FBI. This is not a theoretical attack - it is exactly the attack that cryptographers have warned about for decades when governments propose "lawful intercept" mandates or key escrow systems.
The architectural backdoor in ANOM - a silent master key added to every message encryption - is structurally identical to what law enforcement has periodically proposed as a solution to "going dark" in legitimate commercial communications. The argument against such mandates is precisely what ANOM demonstrates: a system designed so that a third party can always read your messages is a system that will eventually be compromised by adversaries who are not the intended authorized third party. The question is not whether the backdoor will be used against criminals. It will. The question is what happens to everyone else's messages when the platform, the key, or the people with access are themselves compromised.
The operation also illuminated the global coordination challenges of modern law enforcement intelligence operations. The FBI was collecting intelligence that was simultaneously relevant to drug trafficking investigations in Australia, murder plots in the Netherlands, money laundering in Germany, and cartel operations in Mexico. Each jurisdiction had different legal frameworks, different evidentiary standards, and different risk tolerances for when to act. The three-year window required maintaining extraordinary operational security within multiple law enforcement agencies simultaneously - a feat that, based on the outcome, appears to have been successful.
Whether Operation Trojan Shield represents a model for future law enforcement strategy or an unrepeatable historical anomaly depends partly on whether criminal organizations have learned the lesson clearly enough. The lesson is not "don't use encrypted phones." The lesson is that any encrypted communications platform whose key management is controlled by a party you cannot independently verify is a platform you should treat as compromised. In practice, this means open-source software, self-hosted infrastructure, and cryptographic verification of your own key management - capabilities that sophisticated criminal organizations are now, slowly, building.