KASPERSKY

The antivirus that sees everything on a billion machines — banned by a government that never published its evidence, denied by a company that can't prove a negative.

OPERATION
Antivirus — kernel-level access plus cloud sample upload, on consumer and enterprise machines worldwide
ORIGIN
Founded 1997 by Eugene Kaspersky, educated at a KGB-backed cryptography institute — a biography he has never hidden FACT
EVENT
USED AS A SEARCH ENGINE FOR SECRETS — per 2017 reporting, Russian state hackers used Kaspersky AV to hunt U.S. classified tools; Israeli intelligence, inside Kaspersky's network, watched it happen ATTRIBUTED
PATTERN
Its own AV pulled NSA attack code, with classified markings, off an NSA worker's home PC — per the company's own investigation FACT (SELF-DISCLOSED)
DISPOSITION
Federal ban 2017 (BOD 17-01, then statute); full U.S. sales-and-updates prohibition 2024 (Commerce Final Determination) ADJUDICATED

Here is the immune cell of the personal computer — an organism that must be allowed to touch everything in order to protect anything — observed carrying, in one documented instance, the crown jewels of American signals intelligence in its mouth. Whether it was a retriever or a courier is the whole dispute, and nine years of government action have never publicly settled it.

Official channels: x.com/@kaspersky (company) and x.com/@e_kaspersky (Eugene Kaspersky). FIRST-PARTY

"Kaspersky does not engage in activities which threaten U.S. national security and, in fact, has made significant contributions with its reporting and protection from a variety of threat actors that targeted U.S. interests and allies… Kaspersky believes that the Department of Commerce made its decision based on the present geopolitical climate and theoretical concerns, rather than on a comprehensive evaluation of the integrity of Kaspersky's products and services." — Kaspersky, statement on the U.S. Commerce Department determination, June 2024.

Every file in this drawer asks what a vendor did. This one asks something harder: what a vendor is. An antivirus with a Moscow headquarters is either the best-positioned Russia-watcher in the industry — Kaspersky's researchers have burned more Russian-speaking APTs than most Western firms — or the best-positioned collection asset the FSB never had to build. The public record supports the capability and documents the fear. It has never documented the complicity.

Hold both facts at once: the U.S. government spent nine years, three mechanisms, and real money removing this software — and in all that time never published a receipt showing the company was a witting participant. One of those facts is a costly signal. So is the other.

the drama timeline

ACT I — THE SCHOOL AND THE FIRM (1987–2015)

The founder's biography is not a secret, an accusation, or a smoking gun. It is the first line of the file, because everyone — including him — starts there.

  1. 1987–1997

    The KGB-backed institute

    At sixteen, Eugene Kaspersky enters a five-year program at the KGB-backed Institute of Cryptography, Telecommunications, and Computer Science; he later works as a Soviet military software engineer before founding Kaspersky Lab in 1997. He has never concealed any of this. Wired's 2012 profile adds the characterization — "deep ties to the KGB's successors in Moscow" — which is Wired's, and which he has always contested.

  2. 2014–2015

    The home PC, and the watcher watched

    An NSA Tailored Access Operations developer, Nghia Hoang Pho, takes classified tools home over several years — a felony he later admits. His home PC runs Kaspersky AV, which automatically uploads an archive containing Equation Group source code and classified-marked documents to Moscow for analysis. Separately, in 2015, Kaspersky itself discloses that its own corporate network was penetrated by the sophisticated Duqu 2.0 platform — an intrusion later reported to be Israeli.

    Note who disclosed what: the company announced its own compromise, and later published the archive incident. The habit of self-disclosure is on the record either way you read the rest of the file.

ACT II — THE REPORTING AND THE FIRST BAN (2017)

Washington moves first and explains later; the newspapers explain more than Washington ever does.

  1. SEP 13, 2017

    BOD 17-01: off every federal system

    DHS issues Binding Operational Directive 17-01, ordering all federal civilian agencies to identify and remove Kaspersky products within 90 days — citing the access the products enjoy, and the requirements of Russian law that could compel cooperation with Russian intelligence. It is a risk determination, and DHS frames it as one; no evidence of actual misconduct is published with it.

  2. OCT 10, 2017

    The Washington Post: Israel watched it happen

    The Post reports that Israeli intelligence, having penetrated Kaspersky's network, observed Russian government hackers using Kaspersky antivirus scans to search the world's computers for American intelligence material — and tipped the NSA, leading to the discovery that classified tools had left an employee's home machine via the AV. The story's sources are unnamed officials; its central claim about the company itself is capability and exploitation, not witting complicity.

  3. NOV 2017 – DEC 2017

    The company opens its books; Congress closes the door

    Kaspersky publishes its internal investigation of the 2014 incident — the archive, the classified markings, the deletion order — answering "did you share it?" with "No, we didn't," and announces a Global Transparency Initiative: source-code review centers and third-party audits, with data processing later moved to Switzerland. Congress is unmoved: the FY2018 NDAA (§1634) writes the government-wide ban into statute. Kaspersky sues; the courts uphold the ban — ruling on Congress's power, not on any espionage finding.

ACT III — THE FULL BAN (2024)

Seven years after the federal ban, the other shoe: not just the government's machines — everyone's.

  1. JUN 2024

    Commerce prohibits the product; Treasury names the executives

    The Commerce Department's ICTS Final Determination prohibits Kaspersky from providing its software and, after September 29, 2024, security updates to any U.S. person — the first company-wide prohibition under the supply-chain authority. The same week, OFAC sanctions twelve Kaspersky executives. It does not sanction the company. It does not sanction Eugene Kaspersky.

    Read the sanctions list as carefully as the ban: a government willing to prohibit the product across its entire market still declined to name the founder or the firm. Both choices are evidence of something; the file declines to tell you of what.

  2. JUL 2024

    The wind-down

    Kaspersky announces it will comply, stops U.S. sales ahead of the deadline, and winds down its U.S. business — while stating it "intends to pursue all legally available options" and continuing to deny, as it has since 2017, that it ever engaged in activities threatening U.S. national security.

both sides, on the record

The access is total and the jurisdiction is Moscow. Kernel privileges plus cloud upload, from a company subject to Russian law — the architecture DHS, Congress, and Commerce each independently judged unacceptable [1] [2] [3].

The exploitation was reported by three major outlets. The Post's account — Russian hackers searching through the AV, Israel watching from inside Kaspersky's own network — has stood since 2017 [6].

The one documented pickup is admitted. By the company's own account, its AV lifted Equation Group source code and classified-marked documents off an NSA developer's home PC and moved them to Moscow [8] [5].

No public evidence of complicity — ever. In nine years of directives, statutes, and determinations, no U.S. agency has published proof that Kaspersky knowingly assisted any intelligence service. The bans are risk rulings; the courts that upheld them ruled on process and power, not espionage [1] [3].

The company's conduct cuts its way. It disclosed its own Duqu 2.0 compromise, published the archive investigation ("Did we share it with a third party? No, we didn't"), offered independent third-party code review, and moved data processing to Switzerland — and its researchers have repeatedly exposed Russian-speaking APTs, plus the NSA's own Equation Group [8] [9].

Its position, in its own words: the Commerce decision rests on "the present geopolitical climate and theoretical concerns, rather than on a comprehensive evaluation of the integrity of Kaspersky's products" — and it proposed, it says, an independently verified security framework that was never taken up [9].

YOU DECIDE

Scoped to the claims. The bans are adjudicated fact. The 2014 pickup is admitted fact. The espionage-through-the-product account is reporting — consistent, multi-outlet, and never publicly evidenced by any government in nine years. Whether "we cannot prove they helped" ends the question, or is exactly what you'd expect either way, is the part you get to weigh.

The archive does not judge. It keeps the file open in two languages.

evidence locker

GOVERNMENT RECORD

  1. DHS/CISA — Binding Operational Directive 17-01, "Removal of Kaspersky-Branded Products" (Sep 13, 2017) FACT — the federal removal order and its stated rationale. cisa.gov/news-events/directives/bod-17-01-removal-kaspersky-branded-products
  2. FY2018 NDAA, Public Law 115-91, §1634 — the statutory government-wide ban FACT govinfo.gov/content/pkg/PLAW-115publ91/html/PLAW-115publ91.htm
  3. Federal Register — "Final Determination: Case No. ICTS-2021-002, Kaspersky Lab, Inc." (Jun 24, 2024) FACT — the full U.S. prohibition, in the administrative record. federalregister.gov/documents/2024/06/24/2024-13532/…
  4. U.S. Treasury — OFAC designations of twelve Kaspersky Lab executives (Jun 21, 2024) FACT — note whom it names, and whom it does not. home.treasury.gov/news/press-releases/jy2420
  5. DOJ — Nghia Hoang Pho guilty plea, willful retention of national defense information (Dec 2017) FACT — the home PC, prosecuted. justice.gov/archives/opa/pr/maryland-man-pleads-guilty-…

PRESS & INVESTIGATIVE

  1. The Washington Post — "Israel hacked Kaspersky, then tipped the NSA that its tools had been breached" (Oct 10, 2017; archived) ATTRIBUTED — the central espionage account, from unnamed officials. web.archive.org/web/2017/…washingtonpost.com…d48ce774-aa95-11e7-850e-2bdd1236be5d_story.html
  2. Wired — "Russia's Top Cyber Sleuth Foils US Spies, Helps Kremlin Pals" (Jul 2012) ATTRIBUTED — the KGB-institute biography and the "deep ties" characterization, as Wired's. wired.com/2012/07/ff-kaspersky/

SUBJECT'S OWN CHANNELS

  1. Kaspersky — "Preliminary results of the internal investigation into alleged incidents reported by US media" (Oct/Nov 2017) SELF-PUBLISHED — the archive, the classification markings, the deletion order, the denials, in the company's own words. kaspersky.com/blog/internal-investigation-preliminary-results/19894/
  2. Kaspersky — statement on the U.S. Commerce Department determination (Jun 2024) SELF-PUBLISHED — the full denial and the "geopolitical climate" characterization. usa.kaspersky.com/about/press-releases/kaspersky-statement-on-the-us-commerce-department-determination
  3. Kaspersky — statement on U.S. compliance following the ICTS Final Determination (Jul 2024) SELF-PUBLISHED — the wind-down. usa.kaspersky.com/about/press-releases/kaspersky-statement-on-compliance-…
  4. Eugene Kaspersky — personal bio, eugene.kaspersky.com SELF-PUBLISHED — the biography, from the man himself. eugene.kaspersky.com/about/
  5. X — @kaspersky and @e_kaspersky (official accounts) FIRST-PARTY — account-level links only; no fabricated permalinks. x.com/e_kaspersky
The standard. The bans are sourced to the directives, the statute, and the Federal Register. The espionage account is stated as the Washington Post's reporting from unnamed officials, and every appearance of it carries the two facts that bound it: no government has published evidence of witting complicity, and the company has always denied it. The one admitted incident is sourced to the company's own investigation and the DOJ's prosecution of the NSA employee. The founder's biography is stated as he himself states it. No complicity is asserted, no motive diagnosed. The burden of proof is on us, not the subject. If it couldn't survive a defamation challenge, it wouldn't be on this page.