
On April 14, the Senior Analysts of the Chanticleer Intelligence Brief’s Applied Intelligence Project (AIP) presented the findings of their semester-long research project before an audience of over 100 members of US government agencies, academics, students, and members of the public.
The AIP project was titled “Assessment of Non-Official Cover (NOC) Passport and Identity Utilization by Russian Intelligence Services“. It examined the acquisition, maintenance, and operational use of passports, identities, and other elements of non-official covers by Russian intelligence officers operating outside formal diplomatic accreditation.
This open-source effort was intended to enhance the understanding of contemporary Russian non-official cover (NOC) tradecraft and to identify repeatable patterns that illuminate current tactics, techniques, and procedures (TTPs). The findings are meant to support operational planning, counterintelligence posture, and risk mitigation in permissive, semi-permissive, and denied environments. The AIP team’s findings have been shared with the US Intelligence Community.
Utilizing OSINT methods, the AIP Senior Analysts compiled comprehensive case files for 50 known Russian NOCs, whose operational presence spans the years 1975 to 2025. They used these case files to assemble a database showing patterns of operational activity across time. They categorized documents used by Russian NOCs into three types: (a) lawfully issued passports—genuine passports issued by the Russian government, which may support a NOC officer’s genuine or notional identity; (b) fraudulently obtained passports—real passports issued by a country other than Russia, which are acquired through deception, corruption, or exploiting weaknesses in a country’s civil registry system; (c) altered passports—genuine passports that are modified following issuance, by altering the holder’s photograph, personal details, or entry stamps.
The AIP’s research findings show that most Russian NOC officers fraudulently obtain their travel documents, frequently from countries other than their target country. In most cases, the cover occupations of Russian NOCs closely match their operational goals, ensuring that they have access to human assets or information that are relevant to their mission. Moreover, Russian NOCs take their time to build their covers over long periods before acquiring the necessary travel documentation; this allows them to integrate into their environments and presents them with opportunities to operate in professional areas, or in higher education and adjacent fields.
Within the timeframe assessed in the AIP research, the researchers found no significant variation in Russian NOCs’ operational risk tolerance, logistical support structures, or observed limitations. These tend to vary widely by case. This demonstrates that the risk levels of Russian NOCs have probably remained relatively constant over time. However, it is possible that NOCs who are currently operating in the field are facing a higher degree of constraints than in the past.
The presentation concluded with proposed best practices for counterintelligence mitigation. Among them was a proposal for expanded international cooperation with partner services, which, alongside targeted training within critical infrastructure sectors, would most likely improve the US and partner nations’ capabilities for the detection, attribution, and disruption of Russian NOC networks.
This AIP effort was led by Directors Savannah Bennett, Jack Goldberg, Ryan Campbell, and Olivia Connell. They were assisted by Deputy Directors Ethan McWaters, Kevin Taber, Madison Bunting, and Abigail Gross and by Support Officers Sophia Batchelder, Anna Howard, Charlie Kaminskas, Brendan Minett, Aaron Roecklein, Henry Patterson, Ramon Morales, Anna Smith, Lani Hoeft, Ayden Dunn, Daniel McGill, Destin Countryman, Ellie Kreiser, Eva Hodges, Halle Brown, and Daniella Desimone.