Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Project Indigo: What the Bank–Cyber Command Pilot Did—and Didn’t Do

Project Indigo linked FSARC with U.S. Cyber Command for limited financial-sector training and anonymized threat sharing. Here’s what is known—and what isn’t.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Project Indigo was a limited pilot that connected the Financial Systemic Analysis & Resilience Center (FSARC) with U.S. Cyber Command. Beginning in 2017, it combined financial-sector training and exercises with the sharing of selected, consolidated, anonymized cyber-threat information. It was not a network linking every bank to the military, and public reporting does not establish that the pilot conducted a retaliatory cyberattack.

Project Indigo in brief

  • Started: October 2017, according to a later Defense Department history.
  • Industry interface: FSARC, a restricted consortium focused on systemic financial-sector risks.
  • Government participants: U.S. Cyber Command and Cyber National Mission Force personnel, with DHS, Treasury, and Defense Department involvement or coordination described in later accounts.
  • What moved: Selected technical threat information, consolidated and anonymized before sharing—not a documented transfer of raw customer records or unrestricted bank-network data.
  • Later trajectory: A later Defense Department account described Indigo as maturing into the broader DOD/DHS Pathfinder initiative.
  • Confirmed offensive operation: None is established in the public accounts cited here.

Why banks and Cyber Command worked together

Financial institutions can see activity inside their own systems; government agencies may have foreign intelligence and operational capabilities that individual companies lack. Project Indigo sought to connect those partial views so officials could better understand nation-state threats to the financial sector and, where appropriate, provide useful insight back to industry. CyberScoop’s 2018 account describes the pilot’s purpose and information-sharing arrangement (CyberScoop).

This was more than a data channel. It was also an attempt to help military cyber personnel understand how financial systems work, which failures could spread beyond one firm, and what recovery would require. The strategic innovation was the translation between financial-sector risk and government cyber analysis—not evidence of a large volume of data exchanged.

The organizations behind the name

FS-ISAC and FSARC

FS-ISAC is the broader financial-services information-sharing organization. FSARC, the Financial Systemic Analysis & Resilience Center, is a more restricted consortium focused on threats to critical financial firms and systemic risks to the U.S. financial system. Put simply, FS-ISAC serves the wider sector, while FSARC concentrates on risks that could affect the system as a whole. Carnegie’s analysis discusses FSARC’s role in this government-industry model (Carnegie Endowment).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The original public announcement of FSARC in 2016 identified Treasury, DHS, and the FBI as government partners, but did not publicly name Cyber Command. Project Indigo emerged through a more sensitive channel than the consortium’s public description suggested.

Cyber Command, CNMF, DHS, and Treasury

U.S. Cyber Command is a military command, not itself an intelligence agency. Cyber National Mission Force (CNMF) personnel were among those involved in the pilot’s training and exercise activities. DHS and Treasury already had critical-infrastructure and financial-sector relationships; the accounts describe them as part of the broader coordination and information pathway. A Defense Department historical account says Cyber Command analysis produced intelligence products for Treasury, which could then share relevant information with industry (Defense Department history at GovInfo).

Which financial institutions were involved?

CyberScoop reported in 2018 that FSARC then included eight financial institutions: Bank of America, BNY Mellon, Citigroup, Goldman Sachs, JPMorgan Chase, Morgan Stanley, State Street, and Wells Fargo. That is a reported FSARC membership list at the time, not proof that each bank publicly confirmed direct participation in Project Indigo. The report noted that several institutions did not respond to requests for comment.

What happened during the pilot

The Defense Department’s later history dates the project’s start to October 2017. CNMF personnel received FSARC training on risks affecting important financial systems, then observed an exercise in which nine major financial institutions stress-tested a key financial system against a realistic risk-mitigation scenario. The training and exercise were intended to give military personnel context about payment-system dependencies, concentration risk, recovery priorities, and the difference between a localized incident and a threat to the broader system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In 2017–2018, FSARC also shared selected cyber-threat information with Cyber Command. CyberScoop reported that Cyber Command’s spokesperson described two anonymized samples shared during the pilot. A source familiar with the effort separately characterized one package as combining open-source indicators with indicators observed by financial institutions and associated with North Korean activity. That North Korea detail comes from an anonymous source, not a public official confirmation.

What information was shared—and what was not established

Public descriptions characterize the material as consolidated, scrubbed or anonymized technical threat information connected to network defense, including malware-related artifacts and indicators associated with state-sponsored activity. An indicator of compromise is a technical clue—such as a file hash, domain, or other observable—that may help identify malicious activity. A malware sample or threat product can provide additional technical context, but the public accounts do not inventory every item exchanged.

CyberScoop reported statements from Cyber Command and FS-ISAC that the shared material did not contain personally identifiable information or customer information. Those are attributed assurances, not the result of a publicly documented independent audit. The available evidence does not support claims that banks handed over raw customer records, all incident-response data, or unrestricted network telemetry.

The reported process was an intermediary one: participating institutions’ observations were consolidated and anonymized through FSARC before selected information reached government personnel. It was not a direct connection between every FS-ISAC member and Cyber Command.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Did Project Indigo let banks “hack back”?

No. Project Indigo did not give financial institutions authority to break into attackers’ systems. Sharing an indicator with government, analyzing it, and conducting a cyber operation are distinct actions.

  • Threat sharing: A company or consortium passes technical observations to government.
  • Analysis and attribution: Government personnel assess what the information may indicate and how it fits with other intelligence.
  • Defensive support: Agencies may provide warnings or relevant insight to affected organizations.
  • Disruption: The government may consider action against adversary infrastructure under separate authorities, approvals, and operational judgments.

Contemporary reporting said Cyber Command might use its capabilities to support disruptive action if appropriate. That possibility is not proof that Indigo triggered or carried out an operation. The public record cited here does not establish a Project Indigo hack-back mission. IISS likewise distinguishes banks’ sharing of scrubbed information from possible government offensive action (IISS).

The legal and institutional context

A later Defense Department account situated the collaboration in a policy environment that included Section 1642 of the National Defense Authorization Act. As described in that account, the provision allowed the president to authorize the secretary of defense to take appropriate and proportional action in foreign cyberspace and contemplated voluntary arrangements with private-sector entities to share threat information about malicious cyber actors and related infrastructure.

That reference does not mean Section 1642 specifically created Project Indigo. Nor did the existence of an information-sharing arrangement mean that Cyber Command automatically acted on each indicator. Any government operation would involve separate authorities and approvals. Depending on the incident, relevant actors could include Cyber Command, Treasury, DHS, the FBI, the intelligence community, and senior executive decision-makers; the public material does not lay out a complete chain of command for Indigo.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why cooperation appealed—and why it could fall short

Potential benefits

  • More useful sector context: Training and exercises can help analysts understand the operational consequences of an intrusion in payment systems and other critical financial infrastructure.
  • Recognition of cross-firm patterns: A consortium focused on systemic risk can see connections that an individual bank might treat as an isolated incident.
  • Government capabilities: Government agencies may have intelligence, attribution, diplomatic tools, or cyber-operation capabilities that a private firm cannot access or use.
  • Joint preparation: Exercises can reveal dependencies and recovery challenges before a crisis affects multiple institutions.

Constraints and risks

  • Trust and competition: Banks may hesitate to expose vulnerabilities, proprietary detection methods, or operational weaknesses to peers or government. Academic analysis of financial-sector cooperation describes trust as a barrier to timely, comprehensive exchange (Journal of Cybersecurity).
  • Sanitization can remove context: Anonymization can protect institutions and customers but may make attribution or rapid response harder. CyberScoop reported concern that the information shared was not yet as useful as some officials wanted.
  • Privacy and confidentiality: Even when customer information is said not to be included, institutions need confidence about what is collected, how it is handled, and who can access it.
  • Escalation and collateral effects: Disrupting infrastructure can affect third parties, expose intelligence sources, or intensify a conflict. Sharing threat data is not itself a risk-free authorization to act.
  • Accountability and measurement: The arrangement was not fully transparent, and public accounts do not establish data volumes, operational outcomes, or measurable reductions in financial-sector risk.

From Project Indigo to Pathfinder

A later Defense Department account described Project Indigo as having matured into Pathfinder, a broader DOD/DHS effort to facilitate cyber collaboration between government and private-sector entities. Finance was described as Pathfinder’s first implementation, with energy-sector collaboration contemplated. This is evidence of a reported evolution, not a publicly established rename date or proof that Project Indigo remains the current operating name.

Carnegie’s later discussion also places FSARC, Indigo, and Pathfinder in the broader development of financial-system cyber cooperation (Carnegie Endowment). A SIPRI review likewise notes the FSARC–Cyber Command channel and the limited public disclosure surrounding it (SIPRI).

What the public record still does not show

  • The complete participant list and each institution’s specific role in Project Indigo.
  • The exact legal agreements, oversight arrangements, and safeguards used for every exchange.
  • The volume and frequency of data shared beyond the reported two anonymized samples.
  • Whether Cyber Command conducted any operation based on information shared through the pilot.
  • Whether Pathfinder continues in the same form, and the initiative’s current status under that name.
  • Whether the model produced measurable improvements in the security or resilience of the financial system.

These limits matter: the public evidence supports the existence and basic mechanics of a small pilot, but not a full accounting of its outcomes.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.