FOIA Cases
EPIC v. DHS – Defense Contractor Monitoring
Background
On June 16, 2011, the Washington Post reported that the NSA had implemented a new program designed to monitor all traffic flowing through certain ISPs to a select number of defense contractors. The goal of this pilot program is the “thwarting [of] cyberattacks against defense firms,” although Deputy Secretary of Defense William J. Lynn III stated that “[w]e hope the . . . cyber pilot can be the beginning something bigger.” The NSA pilot program is to serve as a model that can be “transported to other critical infrastructure sectors, under the leadership of the Department of Homeland Security.”
Although no public name has been given to this new program, it is known that the NSA has partnered with AT&T, Verizon and CenturyLink to filter the traffic of fifteen defense contractors, including Lockheed Martin, CSC, SAIC and Northrop Grumman. The NSA claims that it will not be “direct[ly] monitoring the contractors’ networks.” Instead, it has developed “signatures” of malicious code as well as sequences of suspicious network behavior that it will apply to filter all Internet traffic on those ISPs that flows to these defense contractors. By applying these signatures and filtering suspicious behavior, the NSA will be able to “disable the threats before an attack can penetrate a contractor’s servers.”
Individuals within the Department of Justice expressed misgivings that the program would “run afoul of privacy laws forbidding government surveillance of private Internet traffic.” The Electronic Communications Privacy Act (“ECPA”), 18 U.S.C. ยง 2510, prohibits the interception of electronic communications without a court order or consent from one of the parties. The NSA has alleged that the Agency “will not directly filter the traffic or receive the malicious code captured by Internet providers.” It is unclear how the program can detect malicious code and prevent its execution without “captur[ing]” it in violation of federal law.
Deputy Secretary of Defense William J. Lynn III publicly spoke about the program and provided a rough outline of its scope. He stated that it is currently run by the NSA, and that DHS is a partner.
EPIC’s Freedom of Information Act Request and Subsequent Lawsuit
In July 2011, EPIC submitted a FOIA request to DHS asking for:
- All contracts and communications with Lockheed Martin, CSC, SAIC, Northop Grumman, or any other defense contractors regarding the new NSA pilot program;
- All contracts and communications with AT&T, Verizon, and CenturyLink or any other ISPs regarding the new NSA pilot program;
- All analyses, legal memoranda, and related records regarding the new NSA pilot program;
- Any memoranda of understanding between NSA and DHS or any other government agencies or corporations regarding the new NSA pilot program;
- Any Privacy Impact Assessment performed as part of the development of the new NSA pilot program.
DHS referred EPIC’s FOIA Request to the National Protection and Programs Directorate. The Directorate is charged with risk-reduction activities associated with the mission of DHS. The National Protection and Programs Directorate failed to provide any documents, and EPIC filed an Administrative Appeal in January 2012.
On March 1, 2012, EPIC filed a lawsuit against the DHS based on that Agency’s non-responsiveness to EPIC’s request and in order to compel the disclosure of documents relating to the monitoring program.
Legal Documents
EPIC v. Department of Homeland Security, Case No. 12-00333 (GK) (D.D.C. filed Mar. 1, 2012)
- EPIC’s Complaint (Mar. 1, 2012) (pdf)
- DHS’ Answer to EPIC’s Complaint (May 1, 2012) (pdf)
- Joint Meet and Confer Statement (May 21, 2012) (pdf)
- Joint Meet and Confer Statement – DHS’ Proposed Order (May 21, 2012) (pdf)
- Joint Meet and Confer Statement – EPIC’s Proposed Order (May 21, 2012) (pdf)
- Scheduling Order (May 24, 2012) (pdf)
- DHS’ Motion to Stay Proceedings for 10 Days (August 24, 2012) (pdf)
- DHS’ Motion to Stay Proceedings for 10 Additional Days (September 5, 2012) (pdf)
- EPIC’s Opposition to DHS’ Motion to Stay Proceedings for 10 Additional Days (September 5, 2012) (pdf)
- Order Granting DHS’ Motion to Stay Proceedings for 10 Additional Days – Final Stay (September 5, 2012) (pdf)
- DHS’ Motion to Modify the Scheduling Order (September 14, 2012) (pdf)
- EPIC’s Opposition to DHS’ Motion to Modify the Scheduling Order and Cross-Motion to Show Cause (September 19, 2012) (pdf)
- DHS’ Reply to DHS’ Motion to Modify the Scheduling Order and Opposition to EPIC’s Cross-Motion to Show Cause (September 28, 2012) (pdf)
- EPIC’s Reply to EPIC’s Motion to Show Cause (October 5, 2012) (pdf)
- Modified Scheduling Order (October 16, 2012) (pdf)
- EPIC’s Motion for Reconsideration (November 7, 2012) (pdf)
- DHS’ November 2012 Status Report (November 15, 2012) (pdf)
- DHS’ Opposition to EPIC’s Motion for Reconsideration and Cross-Motion to Modify the Scheduling Order (November 30, 2012) (pdf)
- EPIC’s Reply to EPIC’s Motion for Reconsideration and Opposition to DHS’ Cross-Motion to Modify the Scheduling Order (December 7, 2012) (pdf)
- DHS’s Reply to DHS’ Cross-Motion to Modify the Scheduling Order (December 14, 2012) (pdf)
- DHS’ December 2012 Status Report (December 17, 2012) (pdf)
- Final Order Granting EPIC’s Motion for Reconsideration in Part (January 8, 2013) (pdf)
- DHS’ February 2013 Status Report (February 1, 2013) (pdf)
- DHS’ March 2013 Status Report (March 1, 2013) (pdf)
- DHS’ April 2013 Status Report (April 15, 2013) (pdf)
- DHS Motion for Summary Judgment (August 30, 2013) (pdf)
- EPIC Motion for Summary Judgment (September 27, 2013) (pdf)
- DHS Opposition and Reply (November 4, 2013) (pdf)
- EPIC Reply (November 25, 2013) (pdf)
- Memorandum Opinion (August 4, 2015)
- EPIC Motion for Attorneys’ Fees and Costs (Feb. 5, 2016) (pdf), Exhibits
- DHS Opposition to EPIC’s Motion for Fees (Mar. 9, 2016) (pdf), Exhibits
- EPIC’s Reply Motion for Fees (Mar. 22, 2016)
- Fees Opinion (Nov. 21, 2016)
- Fees Order (Nov. 21, 2016)
Freedom of Information Act Documents
- EPIC’s FOIA Request (July 26, 2011) (pdf)
- DHS’ Acknowledgement and Referral to the National Protection and Programs Directorate (Aug. 3, 2011) (pdf)
- EPIC’s Administrative Appeal (Jan. 5, 2012) (pdf)
Released Documents
- DHS Final Production Cover Letter (pdf)
- DHS Final Production Part 1 (pdf)
- DHS Final Production Part 2 (pdf)
- DHS Final Production Part 3 (pdf)
- DHS Final Production Part 4 (pdf)
- DHS Final Production Part 5 (pdf)
- DHS Final Production Part 6 (pdf)
- DHS Final Production Part 7 (pdf)
- DHS Final Production Part 8 (pdf)
- DHS Final Production Part 9 (pdf)
- DHS Supplemental Production Part 1 (pdf)
- DHS Supplemental Production Part 2 (pdf)
- DHS Supplemental Production Part 3 (pdf)
- DHS Supplemental Production Part 4 (pdf)
- DHS Supplemental Production Part 5 (pdf)
News Items
- U.S. gives big, secret push to Internet surveillance, CNET, Apr. 24, 2013.
- Notebook: NSA Seeks Tighter Info Security for Agencies, Contractors, Defense News, Mar. 22, 2012.
- Prepare to Have Your Email Read by the NSA, the Atlantic, June 17, 2011.
- NSA Allies with Internet Carriers to Thwart Cyber Attacks Against Defense Firms, Washington Post, June 16, 2011.
Support Our Work
EPIC's work is funded by the support of individuals like you, who allow us to continue to protect privacy, open government, and democratic values in the information age.
Donate