25 years after 9/11, spy agencies face old lessons and new threats9·11事件25年后,间谍机构面临着旧的经验教训和新的威胁
Former intelligence officials describe a nation better equipped to disrupt terrorist plots, but still wrestling with the costs.

The 'Tribute in Light' public art installation commemorating the September 11, 2001 attacks shines up from the skyline of lower Manhattan, as seen from Jersey City, New Jersey, on September 10, 2026. Leonardo MUNOZ / AFP via Getty Images
Former intelligence officials describe a nation better equipped to disrupt terrorist plots, but still wrestling with the costs.
As Air Force One returned to Washington, D.C., on the night of Sept. 11, 2001, Michael Morell looked out a window and saw an F-16 off the aircraft’s wingtip. Beyond it, the Pentagon was smoldering.
Morell, then-President George W. Bush’s intelligence briefer, had spent the day answering the president’s questions and relaying intelligence as the country tried to understand the attacks that had hit the Pentagon and the World Trade Center in New York City. A quarter-century later, that view from the window remains one of his most vivid memories.
At the National Security Agency, Rick Ledgett recalled colleagues weeping in the hallways as the agency shifted into crisis mode. Within a month, it had transferred 3,000 analysts to counterterrorism work, he said.
“Personally, it was shattering,” Ledgett, who later served as NSA deputy director, told Nextgov/FCW in an email, adding that he “saw people step up and perform in ways they hadn’t before.”
The response to the worst terrorist attack in modern history would transform the government they served. The efforts involved reorganizing intelligence agencies, expanding surveillance powers and drawing spies deeper into a global campaign to capture or kill suspected terrorists. It also produced longstanding debates over torture policies, targeted killings, mass surveillance, prolonged wars, and disputes over presidential power that became inseparable from efforts made to keep Americans safe from another catastrophe.
Twenty-five years later, former officials describe a country better prepared to disrupt terrorist organizations, but facing a broader mix of threats from foreign governments, hackers, and extremists able to reach Americans online.
“I think we’re much safer than we were on September 10, 2001, from the threat of terrorism,” Morell, who later served as CIA deputy director and acting director, told Nextgov/FCW in an interview. But threats from nation-states like China or Russia, he said, are the most significant the country has faced since the Cold War.
The 9/11 Commission — chartered by Congress and the White House in late 2002 to present a full accounting of the attacks and response — described in its final report failures spanning imagination, policy, capabilities and management. Agencies held pieces of information that did not come together, and domestic defenses were not effectively mobilized despite mounting warnings about al Qaeda.
Just over a month before the attacks, Morell briefed Bush on a landmark intelligence report titled “Bin Ladin Determined To Strike in US” that flagged “patterns of suspicious activity in this country” consistent with preparations for hijackings and other attacks. He told Nextgov/FCW it outlined al Qaeda’s intent to attack the country but did not specifically identify when, where or how a specific plot would unfold.
Getting agencies to work together
The transformation that followed 9/11 sought to make cooperation a standing responsibility. Congress created the Office of the Director of National Intelligence in late 2004, establishing a lead unit responsible for integrating intelligence across agencies that collect data from human informants, satellite imagery, intercepted phone calls and other clandestine sources. The Department of Homeland Security was also stood up in late 2002 to drive domestic defense efforts.
The expansion also deepened agencies’ reliance on contractors. After years of workforce drawdowns following the Cold War, the federal government turned to private companies to meet demands for intelligence collection, analysis and technology support, according to a 2015 report from the Congressional Research Service . Today, they play a ubiquitous, outsized role in America’s national security missions.
Lauren Goldman, a former official in ODNI’s Cyber Threat Intelligence Integration Center and National Intelligence Council, recalled a major shift in the basic expectations that governed intelligence-sharing across government and the private sector.
“The burden became on why you shouldn’t share versus why you should share,” she said. That culture has permeated many categories of today’s national security landscape, especially cybersecurity.
ODNI sought to help ensure information reached people who needed it, including officials who might otherwise have been left outside an agency’s reporting channels, Goldman said. Because the office does not collect intelligence itself, it can assess reporting without the same institutional or cultural attachment to a particular collection method, she added.
James Clapper, who served as director of national intelligence for more than six years under the Obama administration, said that coordination requires a “full-time champion.” Under pre-9/11 arrangements, the CIA director also headed the intelligence community, but agency demands often consumed the attention needed for that broader role, he said.
Clapper said the DNI position was created to coordinate intelligence agencies but was not given full authority over them. Entities like the State Department or the Pentagon, for instance, retained control of their own intelligence shops. Still, the DNI could influence their priorities through oversight of intelligence funding and a direct advisory role to the president, he said.
“I do think there’s a need for an overall champion of collaboration and integration,” Clapper told Nextgov/FCW . His remarks come as the Trump administration has sought to shrink ODNI’s workforce and consolidate its functions, on grounds that the office has become bloated and duplicates work performed elsewhere in the intelligence community.
Ledgett credited ODNI with promoting cooperation, as well as running the National Counterterrorism Center and other hubs. But he said it had struggled to take power from individual agencies, particularly the CIA, and secure the president’s attention.
Morell said the CIA knew al Qaeda wanted to attack the United States but failed to uncover the 9/11 plot. He blamed that failure largely on a shortage of resources to gather intelligence, rather than agencies failing to share what they knew. That view differs in emphasis from the commission’s account, which identified missed opportunities to share or act on information.
Clapper said mistaken assessments about Iraq’s weapons of mass destruction programs also reshaped how spy agencies worked. The Bush administration cited those assessments in making its case for its 2003 invasion. Clapper, who has involvement in a key flawed assessment of Iraq’s WMDs, said the failure pushed agencies to scrutinize their sources and challenge assumptions more rigorously. U.S. analysts, in particular, had relied heavily on an Iraqi informant whose claims came through German intelligence, without direct access to question him.
The limits of intelligence powers
Global surveillance became one of the defining disputes of the post-9/11 era. The NSA’s bulk collection of domestic telephone records , exposed in Edward Snowden’s 2013 disclosures, drew scrutiny over both its intrusions into Americans’ lives and its value as a counterterrorism tool.
In 2014, the Privacy and Civil Liberties Oversight Board recommended ending that collection program, and a federal appeals court ruled in 2015 that it exceeded what Congress had authorized under Section 215 of the Patriot Act. But other surveillance programs exposed by Snowden — including those operating under the contentious Section 702 authority — have remained central to U.S. intelligence-gathering.
Ledgett, who led the NSA’s assessment of the damage from Snowden’s disclosures, defended the post-9/11 surveillance effort as “legal and authorized,” though he noted the intelligence community could have done better at public relations.
The incident forever changed how lawmakers and journalists examine spy agencies’ collection activities and whether Americans’ privacy is adequately protected. Contemporary mass surveillance debates have taken on new forms, including spy agencies’ purchases of sensitive data from commercial brokers and police use of artificial intelligence-powered tools to search vast networks of information about people’s movements and activities.
The CIA’s detention, interrogation and torture practices produced another reckoning. The Senate Intelligence Committee’s 2014 investigation concluded that the agency’s coercive interrogation techniques were ineffective in obtaining intelligence or cooperation and that the CIA impeded oversight and misrepresented aspects of the program.
Morell, who has previously disputed the Senate report’s conclusions, argued that responsibility also belonged to the president and other authorizing officials, and he rejected the idea that the agencies had acted entirely on their own.
Asked whether the country went too far in its broader response in the War on Terror, Morell said that “as a nation, we overreacted,” pointing mainly to the Iraq War and the length of the war in Afghanistan.
Intelligence agencies also helped identify and track suspected terrorists for controversial targeted killings, including those carried out through U.S. drone strikes. The debate reached American citizenship itself when the government targeted Anwar al-Awlaki, an American and al Qaeda operative, in a lethal strike. Defending the action in 2013, then-President Barack Obama argued that citizenship could not shield an operative plotting attacks when capture was not feasible.
Today, drones have become a battlefield mainstay in Russia’s war against Ukraine, and Western militaries are studying how to build, deploy and counter them. Weapons that drew scrutiny for their role in U.S. counterterrorism operations are now also held up as examples of military innovation, with NATO learning directly from Ukrainian drone operators. But questions about whom they kill and how they are used persist, as the United Nations documents their growing toll on civilians .
The fight over intelligence powers also became increasingly partisan. President Donald Trump’s disputes with intelligence officials over Russia’s interference in the 2016 election helped fuel his accusations that agencies were being used against him. A bipartisan Senate investigation upheld the intelligence community’s finding that Moscow sought to help him win. But allegations of political “weaponization” became a recurring theme in Trump’s criticism of intelligence and law enforcement agencies.
A changing threat landscape
Intelligence agencies now face a wider range of threats, including foreign hackers with access to fast-evolving AI tools.
Morell said the United States learned how to degrade terrorist organizations by denying them safe havens where they could train, raise money and prepare attacks. But the growing reach of digital networks has created other ways to threaten the U.S. without physically entering it.
Goldman pointed to critical infrastructure, where connected systems can allow the effects of an intrusion to spread beyond a single building or city, as a target of such threats. Hardening airports and other physical targets has value, she said, but does not eliminate vulnerabilities created by that cyber interconnectedness.
State-backed hacking illustrates the stakes. About six years ago, Russian cyber operatives compromised SolarWinds software as part of an espionage campaign that infiltrated multiple federal agencies and some 100 private companies. China-linked Salt Typhoon hackers later penetrated major telecommunications networks, targeting senior officials’ communications and accessing systems used for court-authorized wiretaps. And another Chinese campaign, Volt Typhoon , embedded hackers in American critical infrastructure, with U.S. officials warning that the access could enable disruption during a future conflict.
Terrorist groups have also found new ways to spread propaganda and reach potential recruits online. The Digital Citizens Alliance and cybersecurity firm risk3sixty recently examined 25 piracy-based internet television services and identified terrorist-linked broadcasters on 17 of them. Hezbollah’s Al-Manar satellite television station appeared on all 17, according to their analysis.
Some terrorism-prevention measures have also lapsed. A Sept. 8 Government Accountability Office report found that the 2023 expiration of the Chemical Facility Anti-Terrorism Standards program ended continuous screening of roughly 500,000 people for possible terrorist ties. The program covered about 3,200 high-risk chemical facilities, whose owners cannot independently access federal terrorist watchlist information.
As officials who lived through 9/11 reflect on their time in government, they want the next generation to remember how warnings were missed and what it took to get agencies working together.
Goldman said analysts need to keep questioning their conclusions, examining blind spots and sharing information, despite the demands of daily work. Clapper emphasized the difficulty of persuading policymakers to act on a danger the public has not yet experienced.
Ledgett expressed confidence in those who will take their place.
“Everyone eventually retires, and organizations continue,” he said. “The next generation steps up and delivers when needed.”
The U.S. is skilled at responding once a crisis arrives, but has struggled to prepare before it does, Morell said.
“Becoming a nation, a White House, a Congress, an American people that is proactive in preventing things — preventing bad things — is much better than only being reactive to them,” he said.
NEXT STORY: China is trying to steal US AI models' secrets, intel agencies warn
2026年9月10日,从新泽西州泽西市拍摄的照片显示,为纪念2001年9月11日恐怖袭击事件而设立的公共艺术装置“光之纪念”(Tribute in Light)在曼哈顿下城的天际线上熠熠生辉。(图片来源:Leonardo MUNOZ / AFP via Getty Images)
前情报官员表示,美国现在更有能力挫败恐怖袭击阴谋,但仍在努力应对由此带来的成本。
2001年9月11日晚,空军一号返回华盛顿特区时,迈克尔·莫雷尔向窗外望去,看到一架F-16战斗机的翼尖离飞机不远。在它更远处,五角大楼正在冒着浓烟。
时任总统乔治·W·布什的情报简报员莫雷尔,当天忙于回答总统的提问并传递情报,当时全国上下都在试图了解五角大楼和纽约世贸中心遭受的袭击事件。四分之一世纪过去了,从窗户望出去的景象仍然是他最鲜明的记忆之一。
里克·莱杰特回忆说,国家安全局进入危机应对模式时,同事们在走廊里哭泣。他说,不到一个月,该机构就将3000名分析人员调往反恐部门工作。
“对我个人而言,这令人心碎,”后来担任美国国家安全局副局长的莱杰特在给 Nextgov/FCW 的一封电子邮件中说道,并补充说他“看到人们挺身而出,以他们以前从未有过的方式表现出色”。
对现代史上最严重恐怖袭击的应对措施彻底改变了政府的运作模式。这些措施包括重组情报机构、扩大监控权力,以及让间谍更深入地参与到抓捕或击毙恐怖嫌疑人的全球行动中。此外,它还引发了关于酷刑政策、定点清除、大规模监控、旷日持久的战争以及总统权力之争的长期辩论,而这些辩论与旨在保护美国人民免遭另一场灾难的努力密不可分。
25 年后,前官员们表示,美国在打击恐怖组织方面准备得更加充分,但却面临着来自外国政府、黑客和极端分子等更广泛的威胁,这些威胁能够通过网络接触到美国人。
“我认为,与2001年9月10日相比,我们现在面临的恐怖主义威胁要小得多,”莫雷尔在接受Nextgov/FCW采访时表示。他后来曾担任中央情报局副局长和代理局长。但他指出,来自中国或俄罗斯等民族国家的威胁,是美国自冷战以来面临的最严峻挑战。
9/11委员会——由国会和白宫于2002年底成立,旨在全面调查袭击事件和应对措施——在其最终报告中指出,应对措施在想象力、政策、能力和管理等方面都存在缺陷。各机构掌握的信息零散不全,未能整合起来;尽管对基地组织的警告日益增多,但国内防御力量并未得到有效调动。
在袭击发生前一个多月,莫雷尔向布什总统汇报了一份具有里程碑意义的情报报告,题为《本·拉登决心袭击美国》。该报告指出,美国境内存在“可疑活动模式”,与劫机和其他袭击的准备工作相符。他告诉Nextgov/FCW,该报告概述了基地组织袭击美国的意图,但并未具体说明某个阴谋何时、何地以及如何实施。
促使各机构协同合作
9·11事件后的变革旨在将合作确立为一项常态化的责任。国会于2004年底设立了国家情报总监办公室,建立了一个牵头机构,负责整合各机构的情报,这些情报来自线人、卫星图像、截获的电话和其他秘密渠道。国土安全部也于2002年底成立,旨在推动国内防御工作。
此次扩张也加深了各机构对承包商的依赖。据国会研究服务处2015年的一份报告显示,冷战结束后,联邦政府经历了多年的人员缩减,之后便转向私营公司来满足情报收集、分析和技术支持方面的需求。如今,这些公司在美国的国家安全任务中扮演着无处不在、举足轻重的角色。
劳伦·戈德曼曾是美国国家情报总监办公室网络威胁情报整合中心和国家情报委员会的官员,她回忆起政府和私营部门之间情报共享的基本预期发生了重大转变。
“问题变成了:为什么不应该分享?为什么应该分享?”她说道。这种风气已经渗透到当今国家安全领域的诸多方面,尤其是在网络安全领域。
高盛表示,国家情报总监办公室(ODNI)致力于确保信息能够传递给需要的人,包括那些原本可能被排除在机构报告渠道之外的官员。她补充说,由于该办公室本身并不收集情报,因此它可以评估报告,而不会像其他机构那样对特定的情报收集方法抱有机构或文化上的依附性。
曾在奥巴马政府担任国家情报总监六年多的詹姆斯·克拉珀表示,协调工作需要一位“全职负责人”。他指出,在9·11事件之前的安排下,中央情报局局长也负责领导整个情报界,但机构的日常事务往往分散了局长履行这一更广泛职责所需的精力。
克拉珀表示,设立国家情报总监一职的目的是协调各情报机构,但并未赋予其对所有情报机构的完全控制权。例如,国务院或五角大楼等机构仍然保留着各自情报部门的控制权。不过,他指出,国家情报总监可以通过监督情报经费以及直接向总统提供咨询来影响这些机构的优先事项。
克拉珀告诉Nextgov/FCW:“我确实认为我们需要一位能够全面推动合作与整合的倡导者。” 此前,特朗普政府曾试图缩减国家情报总监办公室(ODNI)的人员规模并整合其职能,理由是该办公室机构臃肿,且与情报界其他部门的工作存在重复。
莱杰特赞扬了国家情报总监办公室在促进合作以及运营国家反恐中心和其他枢纽方面所做的工作。但他表示,该办公室一直难以从各个机构(尤其是中央情报局)手中夺取权力,也难以获得总统的关注。
莫雷尔表示,中央情报局明明知道基地组织想要袭击美国,却未能发现9·11阴谋。他将这一失误主要归咎于情报收集资源不足,而非各机构未能共享信息。这一观点与委员会的调查报告侧重点不同,委员会的报告指出,错失了共享信息或利用信息的机会。
克拉珀表示,对伊拉克大规模杀伤性武器计划的错误评估也改变了情报机构的工作方式。布什政府在2003年入侵伊拉克时就引用了这些评估。克拉珀曾参与一项对伊拉克大规模杀伤性武器的关键性错误评估,他表示,这一失误促使情报机构更加严格地审查信息来源并质疑既有假设。特别是美国分析人员,他们严重依赖一名伊拉克线人,而该线人的信息是通过德国情报部门提供的,他们无法直接与该线人进行质询。
智力的局限性
全球监控成为9/11事件后时代最具争议的问题之一。爱德华·斯诺登在2013年披露了美国国家安全局大规模收集国内电话记录的行为,这引发了人们对该行为侵犯美国民众生活及其作为反恐工具价值的审查。
2014年,隐私与公民自由监督委员会建议终止该数据收集项目;2015年,联邦上诉法院裁定该项目超出了国会根据《爱国者法案》第215条授权的范围。但斯诺登曝光的其他监控项目——包括那些依据备受争议的第702条授权开展的项目——仍然是美国情报收集的核心。
莱杰特曾领导美国国家安全局评估斯诺登泄密事件造成的损害,他为9/11事件后的监控行动辩护,称其“合法且获得授权”,但他指出,情报界在公共关系方面本可以做得更好。
这一事件彻底改变了立法者和记者审视间谍机构数据收集活动以及美国公民隐私是否得到充分保护的方式。当代的大规模监控辩论呈现出新的形式,包括间谍机构从商业经纪人处购买敏感数据,以及警方利用人工智能工具搜索庞大的信息网络,追踪民众的行踪和活动。
中央情报局的拘留、审讯和酷刑做法引发了另一次反思。参议院情报委员会2014年的调查得出结论,该机构的强制审讯手段未能有效获取情报或合作,而且中央情报局还阻碍了监督,并歪曲了该计划的某些方面。
莫雷尔此前曾对参议院报告的结论提出异议,他认为总统和其他授权官员也负有责任,并驳斥了各机构完全自行采取行动的说法。
当被问及该国在反恐战争中的更广泛应对措施是否矫枉过正时,莫雷尔表示,“作为一个国家,我们反应过度了”,他主要指的是伊拉克战争和阿富汗战争的持续时间。
情报机构还协助识别和追踪恐怖嫌疑人,以实施备受争议的定点清除行动,包括美国无人机袭击。当美国政府对美国公民、基地组织成员安瓦尔·奥拉基发动致命打击时,这场辩论甚至触及了美国公民身份本身。2013年,时任总统奥巴马为此次行动辩护时指出,公民身份不能保护策划袭击且无法抓捕的恐怖分子。
如今,无人机已成为俄罗斯对乌克兰战争中战场上的主力武器,西方各国军队正在研究如何制造、部署和应对无人机。这些武器曾因其在美国反恐行动中的作用而备受关注,如今却被视为军事创新的典范,北约甚至直接向乌克兰无人机操作员学习。然而,关于无人机杀伤对象和使用方式的问题依然存在,联合国也一直在记录无人机对平民造成的日益严重的伤害。
围绕情报权力的斗争也日益党派化。唐纳德·特朗普总统与情报官员就俄罗斯干预2016年大选一事发生的争执,加剧了他关于情报机构被利用来对付他的指责。参议院一项由两党组成的调查证实了情报界的结论,即莫斯科试图帮助他赢得大选。但有关情报机构被政治“武器化”的指控,却成为特朗普批评情报和执法机构时反复出现的主题。
不断变化的威胁形势
情报机构现在面临着更广泛的威胁,包括能够接触到快速发展的人工智能工具的外国黑客。
莫雷尔表示,美国通过剥夺恐怖组织进行训练、筹集资金和策划袭击的安全庇护所,学会了如何削弱这些组织。但数字网络的日益普及,使得恐怖分子无需实际入侵美国,也能以其他方式威胁美国。
高盛指出,关键基础设施是此类威胁的主要目标,因为互联系统可能导致入侵的影响扩散到单个建筑物或城市之外。她表示,加强机场和其他实体目标的防御固然重要,但并不能消除网络互联带来的漏洞。
国家支持的黑客攻击凸显了其中的利害关系。大约六年前,俄罗斯网络特工入侵了SolarWinds公司的软件,这是其间谍活动的一部分,该活动渗透了多个联邦机构和约100家私营企业。与中国有关联的“盐台风”黑客组织随后入侵了主要的电信网络,以高级官员的通信为目标,并访问了用于法院授权窃听的系统。另一起名为“伏特台风”的中国黑客行动则将黑客植入了美国的关键基础设施,美国官员警告称,这种入侵可能在未来的冲突中造成破坏。
恐怖组织也找到了新的途径,通过网络传播宣传并招募潜在成员。数字公民联盟(Digital Citizens Alliance)和网络安全公司risk3sixty近期对25个盗版网络电视服务进行了调查,并在其中17个平台上发现了与恐怖组织有关联的广播公司。他们的分析显示,真主党的“灯塔电视台”(Al-Manar)出现在所有这17个平台上。
一些反恐措施也已失效。美国政府问责局9月8日发布的一份报告指出,2023年“化学设施反恐标准”计划的到期终止了对约50万人进行持续的恐怖主义关联筛查。该计划涵盖约3200家高风险化学设施,这些设施的所有者无法独立获取联邦恐怖分子监视名单信息。
经历过 9/11 事件的官员们在回顾他们的政府生涯时,希望下一代能够记住当时是如何错过预警的,以及让各个机构协同工作需要付出怎样的努力。
高盛表示,尽管日常工作繁忙,分析师仍需不断质疑自己的结论,审视盲点并分享信息。克拉珀强调,要说服政策制定者对公众尚未感受到的危险采取行动,难度极大。
莱杰特对接替他的人表示了信心。
“每个人最终都会退休,但组织机构会继续运转,”他说。“下一代会在需要的时候挺身而出,承担起责任。”
莫雷尔说,美国擅长在危机发生后做出反应,但在危机发生前做好准备方面却做得不够好。
他说:“让美国国家、白宫、国会、美国人民积极主动地预防坏事发生,远比被动地应对坏事要好得多。”
下一篇报道:情报机构警告称,中国正试图窃取美国人工智能模型的秘密