Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit
A top U.S. spy agency will resemble a college for a while on Friday, as it hosts a first-of-its-kind reunion for alumni of its most secretive hacking unit.
The National Security Agency will welcome back to campus potentially hundreds of former members of the elite group known as Tailored Access Operations (TAO) to celebrate the division’s recent rebranding and attempt to lure alums to come back inside the fence line at Fort Meade, Maryland.
The get-together is the latest unconventional outreach by the NSA, whose very existence was once a government secret.
The agency has made a push to build public trust in recent years. It created a Cybersecurity Directorate in 2019 to protect the U.S. by providing the private sector and other federal agencies more insights about specific foreign digital threats. In 2024, the agency launched its own podcast, with the inaugural episode featuring former NSA officers discussing in detail their roles in the hunt for Osama bin Laden.
While an invitation-only reunion won’t move the spy service further out of the shadows, the event does show a willingness to try an unorthodox recruitment approach, especially for TAO. The group, which was often described as an “NSA inside the NSA,” is responsible for breaking into foreign computer systems as part of U.S. covert operations, often leaving spy software behind that collects data for the agency for months or even years.
This week’s get-together has been in the works since the spring and largely spearheaded by NSA Deputy Director Tim Kosiba, according to multiple sources who spoke on the condition of anonymity to discuss the upcoming event. Kosiba, who previously worked in TAO and served as its technical director, has made revitalizing the organization a priority since he returned to take the No. 2 job earlier this year, these people said.
The NSA declined to comment.
The day’s agenda will feature a tour of the brand-new TAO building and a pitch to return to the agency from Kosiba, attendees said. The full agenda is not public. The gathering has also inspired plenty of unofficial meetups around the visit, according to attendees, at favorite local haunts like Jailbreak Foodworks & Brewing Company.
The homecoming also has been organized in a non-traditional way, leaving some participants questioning whether the agency has taken unnecessary risks to draw attention to the event.
NSA initially tried to corral the group through the National Cryptologic Foundation, an education and preservation nonprofit organization that is not a part of the spy agency, before eventually creating an invitation-only Signal group chat to connect members and promote the event.
The channel, dubbed “Terminated Async Operations” — a nod to their former organization’s acronym and an asynchronous operation, where a computer command runs in the background without stopping the main program — quickly ballooned to hundreds of former hackers, developers and analysts reminiscing about past operations, albeit vaguely and discreetly.
“To be clear, nobody's gone classified because everybody’s too pretty for jail,” one former TAO employee, who is a member of the group, told Recorded Future News. “But if internal security saw it? They’d have a fucking aneurysm.”
A second former TAO hacker in the group described the chat as “mostly benign” with topics ranging from “stupid inside jokes from when they were working shifts on the floor to how training went into the results of an operation. You’re talking to over 250 people and 10 of them get it.”
That said: “If I gave you access, you’d write 20 stories off it.”
Multiple sources shared screenshots of the Signal group chat, on condition that they not be published, that showed Kosiba himself was an active contributor at one point, though he later left. Other notable participants include previous TAO technical directors, at least one former head of the NSA Cyber Directorate and operators who eventually joined Project Maven, the Defense Department’s high-profile AI effort.
While Signal is commonplace throughout the NSA and the U.S. clandestine community, the encrypted messaging app has gained a certain notoriety during the second Trump administration.
Defense Secretary Pete Hegseth put U.S. troops at risk by sharing plans about an upcoming military strike in Yemen on his personal phone, according to a Pentagon inspector general's report that criticized the use of unapproved messaging apps and devices across the Pentagon. His use of the app came to light after a journalist was inadvertently added to a Signal text chain by then-national security adviser Mike Waltz. Signal group administrators can vet group members and delete content.
A return to its heyday?
TAO dates back to the early 1990s and eventually developed an entirely separate culture from the rest of NSA. With a mission to break into foreign computer networks to gather intelligence, its members were considered a different breed and more closely aligned with the military, rather than the electronic eavesdropping the agency is now known for.
“You didn’t walk down the hallway to borrow a cup of sugar from these guys. Usually because you didn’t know where they worked on campus,” a former NSA official said, adding that in the often buttoned-up agency culture, TAO hackers usually wore flip-flops or sweatpants to work.
Still, “it was a far more operational office than most others,” meaning more capable of carrying out real-world missions.
TAO’s coding savants helped craft the digital weapon known as Stuxnet. The unit grew from several hundred to over 2,000 personnel before it was renamed Computer Network Operations roughly a decade ago and reorganized. The recent reshuffle undid some of those changes.
Its high operational tempo has caused the outfit to have a higher turnover rate than the rest of the NSA. That churn was magnified last year when NSA lost about 2,100 people or 8 percent of its workforce, as part of the Trump administration’s push to shrink the federal government.
The exact number of TAO personnel is classified, but the former NSA official said employees in the “low dozens” exited the select group.
The upcoming reunion could be a way to replenish its ranks, including with past employees who still work at Fort Meade but as contractors.
“A lot of these people still have active clearances. But maybe they don’t like their contractor. Or they're not able to work on certain projects because it requires an inherently government body to do what it is,” the former agency official said, dubbing it the “blue/green split” with blue security badges associated with the U.S. intelligence community and green for contractors.
It would also short-circuit security screening, which traditionally has been more rigorous than the NSA’s standard top secret vetting, and an operator certification process that current and former hackers claim can take more than a year to complete.
“That's to certify at the baseline level so that you can operate on your own right,” the first previous TAO employee said. “I'm positive it wouldn't take me a year to certify again. I’m not going back. But I'm sure the pitches are coming because the NSA is hurting.”
Martin Matishak
is the senior cybersecurity reporter for The Record. Prior to joining Recorded Future News in 2021, he spent more than five years at Politico, where he covered digital and national security developments across Capitol Hill, the Pentagon and the U.S. intelligence community. He previously was a reporter at The Hill, National Journal Group and Inside Washington Publishers.



