Project SHAMROCK: How the NSA Read America’s Mail for Thirty Years, and Why It Still Matters

This piece draws on primary Church Committee findings, Wikipedia’s sourced entries on Project SHAMROCK and Project MINARET, Citizen Lab’s July 2026 forensic report, and current EFF and court reporting on FISA Section 702 and the NSO Group litigation, cross-checked directly against each original source rather than taken on trust.

For thirty years, the United States government copied and read millions of private messages. Not just from Americans. From anyone whose telegram happened to pass through an American wire. No warrant. No court order. No public knowledge that it was happening at all. This is not a conspiracy theory. It is a matter of Congressional record, and it has a direct line to the spyware scandals making headlines right now.

Prefer to watch this instead? I cover the same story, with the same sources, in this week’s video.

What Was Project SHAMROCK?

Project SHAMROCK was a domestic intelligence programme in which three of America’s biggest telegram companies, Western Union, RCA, and ITT, quietly handed the government daily copies of international telegrams passing through the country. The arrangement began informally during the Second World War and continued for three decades under the Armed Forces Security Agency and, later, its successor, the National Security Agency.

Nobody voted on this. No court signed off on it. The companies involved were nervous about the legal exposure, so in the late 1940s Attorney General Tom Clark quietly promised them immunity from prosecution. That promise, not a law, is what kept the programme running.

At its peak in the 1960s and 1970s, roughly 150,000 messages a month passed across analysts’ desks. The operation had a sister programme, Project MINARET, which used SHAMROCK’s raw intercepts to search for the communications of people on government watch lists. Between 1967 and 1973, MINARET’s watch lists named 1,650 US citizens directly, including Martin Luther King Jr, Muhammad Ali, and, in a detail that later became relevant, Senator Frank Church himself. Separately, and on a far larger scale, the NSA’s broader Watch List files, the so-called “Rhyming Dictionary”, are commonly cited as having eventually touched tens of thousands of Americans, a figure often given as around 75,000. That wider number describes the government’s general intelligence files rather than MINARET’s own targeted list, and it is worth reading with that distinction in mind rather than treating the two figures as interchangeable.

The Reckoning: Frank Church and the Committee That Exposed It

In May 1975, with Congressional investigators closing in, NSA Director Lew Allen shut Project SHAMROCK down on his own authority, before Congress had even confirmed what it was looking at. The full scale only became public months later, through the Senate Select Committee to Study Governmental Operations with Respect to Intelligence Activities, chaired by Idaho Senator Frank Church and known ever since simply as the Church Committee.

On 17 August 1975, before his committee’s final report had even been published, Church went on NBC’s Meet the Press and, without naming the NSA directly, described what the agency’s technology made possible:

“We must know, at the same time, that capability at any time could be turned around on the American people, and no American would have any privacy left: such is the capability to monitor everything, telephone conversations, telegrams, it doesn’t matter. There would be no place to hide.”

He went further, warning that in the wrong hands the same capability “could enable it to impose total tyranny, and there would be no way to fight back,” closing with the line that has outlived him: a warning against crossing into “the abyss from which there is no return.”

The Church Committee’s findings, published in six volumes in April 1976, led directly to the Foreign Intelligence Surveillance Act of 1978, the law that created a warrant process for exactly this kind of surveillance. That was the promise Congress made to the country. Read that again, because the next part of this story is about how thoroughly that promise has been tested since.

From Telegrams to Zero-Click Spyware

Fifty years on, the tool has changed beyond recognition, but the instinct has not. Modern end-to-end encryption has made intercepting a message mid-transit, the SHAMROCK method, largely useless. So surveillance moved to the other end of the pipe: the device itself. Commercial spyware such as NSO Group’s Pegasus can infect a phone with zero clicks from the target, no link, no download, nothing to give it away, and once inside it can read messages, activate the microphone and camera, and track location in real time.

This is a genuinely serious, high-stakes area of law and human rights, so it deserves a careful reading rather than a viral one; treat the summary below as a starting point and follow the links to the primary reports and court filings rather than taking any single account, including this one, as the final word.

In May 2025, a US federal jury ordered NSO Group to pay Meta nearly $168 million in damages, $444,719 in compensatory damages plus more than $167 million in punitive damages, over a 2019 campaign that used a WhatsApp vulnerability to install Pegasus on more than 1,400 phones belonging to journalists, activists, and diplomats. NSO has said it will appeal.

Then, in July 2026, Citizen Lab published forensic evidence that former Greek MEP Stelios Kouloglou had been hacked with Pegasus, not once but twice, in October 2022 and again in March 2023, while he was a substitute member of the European Parliament’s own committee investigating Pegasus abuse. The infections lined up precisely with sensitive committee hearings and draft report deliberations. Citizen Lab has not attributed the attack to a specific government, but the technical fingerprint overlaps with a previously identified operation against Russian and Belarusian dissidents in Europe. Whoever was behind it, the message is uncomfortable: the body built to investigate spyware abuse was, itself, spied on.

The Current Battleground: FISA Section 702

There is a live legislative fight running right now that traces its lineage straight back to SHAMROCK. Section 702 of FISA, the modern authority that lets US agencies collect foreigners’ communications and routinely sweeps in Americans’ messages along the way, expired at midnight on 12 June 2026, after a standoff in Congress over an unrelated intelligence-community nomination. According to the Electronic Frontier Foundation, the authority remains lapsed for now, though the underlying pressure to renew it has not gone away.

Two further reforms are moving through Congress: the Fourth Amendment Is Not For Sale Act, which passed the House in 2024 and would close the loophole letting agencies simply buy Americans’ location and communications data from data brokers instead of getting a warrant, and the bipartisan SAFE Act, introduced by Senators Mike Lee and Dick Durbin, which would require a warrant before the FBI can read the content of Americans’ communications collected under Section 702. Neither has cleared the Senate as of this writing.

The Line From 1945 to Now

Project SHAMROCK ran because three companies agreed to a quiet arrangement and nobody outside a small circle knew to object. FISA was supposed to close that door. What the last year of headlines shows is not that the door reopened in the same place, but that the same instinct, watch first, ask permission never, keeps finding a new door. A telegram wire in 1945. A data broker’s marketplace or a zero-click exploit in 2026. The mechanism changes. The justification, protecting national security, protecting children, catching criminals, rarely does.

FAQ

What was Project SHAMROCK? Project SHAMROCK was a US government programme, run from the 1940s to 1975, in which major telegram companies handed the NSA and its predecessor daily copies of international telegrams without a warrant.

How is Project SHAMROCK different from Project MINARET? SHAMROCK collected the raw telegram traffic. MINARET was the targeted programme that searched those intercepts against government watch lists, directly naming 1,650 US citizens between 1967 and 1973.

Who exposed Project SHAMROCK? The Senate’s Church Committee, chaired by Senator Frank Church, publicly exposed the programme’s scale in 1975, leading to the Foreign Intelligence Surveillance Act of 1978.

What is the modern equivalent of Project SHAMROCK? Commercial spyware such as NSO Group’s Pegasus, which can infect a phone with no user interaction, is the closest modern parallel, alongside the growing practice of government agencies buying communications data from commercial brokers instead of seeking a warrant.

Is FISA Section 702 still active? As of this writing, Section 702 lapsed on 12 June 2026 after a Congressional standoff and has not been reauthorised, though renewal efforts continue.


Want the full story every week instead of chasing it yourself? Subscribe on Substack for the next deep dive as soon as it goes up.

Want more? Get the real story. Get Monday Influencer® — real education from real experts. Expert audio, a weekly digest, and a mentor bot, so you can trust what you learn again. $19.95/mo → https://mondayinfluencer.com

Sources

Historical record (Project SHAMROCK, MINARET, Church Committee)

Present-day parallel: NSO Group and Pegasus

Current legislation: FISA Section 702


Get More Guidance Like This, 100% Ad-Free.

This is a classic blog from my public archive. If you loved it, MONDAY INFLUENCER insiders get real education from real experts, delivered every single week, so you can trust what you learn again. When you join, you unlock:

  • A library of downloadable audios, templates and cheat sheets.
  • A new curated classic from the 500+ episode archive every week
  • A mentor bot trained on real expert insight, a straight answer instead of another AI guess.
  • A weekly digest that cuts through copy-paste headlines and algorithm noise.
  • Exclusive Members-Only Workshops and live Q&A sessions.
Join MONDAY INFLUENCER for Full Access

Your Edge. Every Thursday.

One email. No noise. Just the moves that keep you ahead of the machine — from ex-IBM Futurist Nat Schooler.