A cyber-security researcher has exploited a glitch on the CIA's official Twitter account, to hijack a channel used for recruiting spies.
The US Central Intelligence Agency (CIA) account on X, formerly known as Twitter, displays a link to a Telegram channel for informants.
But Kevin McSheehan was able to redirect potential CIA contacts to his own Telegram channel.
"The CIA really dropped the ball here," the ethical hacker said.
The CIA is a US government organisation known for gathering secret intelligence information, often over the internet, from a vast network of spies and tipsters around the world
Its official X account, with nearly 3.5 million followers, is used to promote the agency and encourage people to get in touch to protect US national security.
Biggest fear
Mr McSheehan, 37, who lives in Maine, in the US, said he had discovered the security mistake earlier on Tuesday.
"My immediate thought was panic," he said.
"I saw that the official Telegram link they were sharing could be hijacked - and my biggest fear was that a country like Russia, China or North Korea could easily intercept Western intelligence."
At some point after 27 September, the CIA had added to its X profile page a link - https://t.me/securelycontactingcia - to its Telegram channel containing information about contacting the organisation on the dark net and through other secretive means.
The channel said, in Russian: "Our global mission demands that individuals be able to reach out to CIA securely from anywhere," while warning potential recruits to "be wary of any channels that claim to represent the CIA".
But a flaw in how X displays some links meant the full web address had been truncated to https://t.me/securelycont - an unused Telegram username.
As soon as Mr McSheehan noticed the issue, he registered the username so anyone clicking on the link was directed to his own channel, which warned them not to share any secret or sensitive information.
"I did it as a security precaution," he said.
"It's a problem with the X site that I've seen before - but I was amazed to see the CIA hadn't noticed."
The CIA did not reply to a BBC News request for comment - but within an hour of the request, the mistake had been corrected.
Latest Stories
-
GJA lifts media blackout on Yendi MP Farouk Aliu Mahama
2 mins -
Do you want to become the EC? – Nana B asks NDC over missing BVRs saga
11 mins -
I almost regretted sharing videos – Real Warri Pikin on backlash after weight loss surgery
29 mins -
Recording BVR kit serial numbers will help trace and match data – NDC justifies demand from EC
38 mins -
Real Warri Pikin reveals she had to refund contractual fees due to ill-health
40 mins -
Book prices to go up by 60% in September due to escalating taxes – GNAAP announces
43 mins -
Lack of toilet forces suspect to defecate on himself at Bole magistrate court
50 mins -
Otumfuo@25: Golden Stool to be on display at grand durbar of Asantehene’s silver jubilee
53 mins -
‘Magnificent’ Kumasi International Airport ready for commissioning
1 hour -
Cocoa beverage reduces BP, hypertension in older adults – KNUST research
1 hour -
Over 1,300 die yearly from drowning; septic tanks major child-killer – KNUST study reveals
2 hours -
Hearts of Oak lineup like army; every player in the squad can come in – Aboubakar Ouattara
2 hours -
Puzuri Group partners with NSS to drive agricultural innovation and youth employment
2 hours -
GFA sign three-year partnership deal with LeLe Foods Ghana Ltd
2 hours -
NDC raises more concerns over EC’s integrity over missing BVR kits
2 hours