“The secret that needed a cover story”

Breaking an encrypted message is not always the difficult part.
Sometimes the difficult part begins afterwards.
Once you have recovered an adversary’s secret, you face an awkward choice.
Images in this article are generated by

EU AI Act Regulation 2024/1689
Act upon it too obviously and you may reveal that their communications are compromised. Keep it hidden and the intelligence achieves nothing except making a few carefully selected people feel extraordinarily well informed.
The Zimmermann Telegram is one of history’s clearest examples of this problem. It was not merely an exercise in reading an enciphered message. It was an operation in deciding how to use a secret without exposing how the secret had been obtained.
That distinction would become fundamental to modern signals intelligence.
It remains fundamental now.
A remarkably impolite proposal
By January 1917, the First World War had been grinding on for two and a half years. The United States remained formally neutral, while Britain hoped that American money, supplies and eventually military power might be drawn more directly into the Allied cause.
Germany, meanwhile, was preparing to resume unrestricted submarine warfare. German leaders knew this might bring the United States into the war, so Foreign Secretary Arthur Zimmermann arranged a contingency plan. On 16 January he sent an enciphered telegram to the German ambassador in Washington, Johann von Bernstorff, for onward transmission to Heinrich von Eckardt, Germany’s ambassador in Mexico.
If the United States entered the war against Germany, Mexico was to be offered an alliance. Germany promised financial support and proposed that Mexico might recover territories lost to the United States: Texas, New Mexico and Arizona. Mexico was also encouraged to bring Japan into the arrangement.
It was ambitious.
It was diplomatically explosive.
It also asked Mexico to begin a war with a much larger neighbour while Germany remained safely on another continent, which is the sort of strategic generosity nations usually reserve for other nations’ soldiers.
The message travelled to Washington through a diplomatic cable channel that President Woodrow Wilson’s government had allowed Germany to use in support of peace negotiations. Germany therefore used an American diplomatic facility to transmit a proposal for a possible war against America.[1][2][3]
There is cheek, and then there is filing the invasion plan through the proposed victim’s communications department.
Room 40 is listening
Germany’s own transatlantic cables had been cut early in the war. Much of its international diplomatic traffic was therefore forced through neutral cable systems, and telegraph traffic between Europe and North America commonly passed through Britain.
This brought the telegram within reach of Room 40, the British Admiralty’s secret codebreaking organisation and an ancestor of GCHQ. British cryptanalysts had acquired German code material through captured documents and earlier intelligence work. A team including Nigel de Grey recognised and recovered the meaning of Zimmermann’s message shortly after it was intercepted.[1][5][6]
The British now possessed intelligence of enormous potential value.
They also possessed an enormous problem.
The message could help change American public opinion. But revealing it might disclose two secrets of Britain’s own:
- Britain was reading German diplomatic codes.
- Britain was intercepting traffic carried through American diplomatic channels.
The first could cause Germany to change its cryptographic systems.
The second could infuriate the neutral country Britain was hoping to bring into the war.
This is the peculiar cruelty of successful intelligence work. Failure leaves you ignorant. Success gives you something valuable that may be dangerous even to touch.
Intelligence has two secrets
An intercepted message contains at least two kinds of protected information.
The first is the content: What does the adversary intend to do?
The second is the provenance: How did we learn that they intended to do it?
The content may be valuable once.
The method may continue producing intelligence for months or years.
This means that an intelligence service cannot judge a disclosure solely by asking whether today’s information is important. It must also consider the future information that may be lost if the adversary discovers the source.
A compromised cipher system is not merely a window into one message. It is a continuing collection capability. Smashing the window to retrieve one particularly interesting envelope may alert everyone inside that the window was never secure.
The outline for this series describes the Zimmermann Telegram through the whole intelligence lifecycle: interception, decryption, source protection, disclosure strategy and political effect. That is precisely why it belongs in a cybersecurity history rather than being left as an entertaining diplomatic anecdote.
Admiral Hall’s dilemma
Admiral William “Blinker” Hall, Britain’s Director of Naval Intelligence and the official responsible for Room 40, could not simply place the decrypt on the desk of the American ambassador with a note saying: “We read this while secretly monitoring your diplomatic cable. Hope that is all right.”[1][4][5]
He needed a second, plausible route by which Britain might have obtained the telegram.
Hall knew that Bernstorff in Washington would have forwarded the message to the German embassy in Mexico using the commercial telegraph system. That onward transmission should have left another copy in Mexico City, separate from the original interception of the American diplomatic cable.
A British source in Mexico, described in some accounts as “Mr H”, obtained a copy from the telegraph office, reportedly by bribing an employee.
This Mexican copy gave Britain a usable cover story: the telegram could appear to have been acquired somewhere on its journey between Washington and Mexico rather than from Britain’s monitoring of American diplomatic communications.[2][4][5]
The second copy did not create the intelligence.
It made the intelligence disclosable.
That is an important difference.
Modern organisations sometimes call this sanitisation, corroboration or source protection. Less formally, it is laundering the intelligence until it can appear in public wearing respectable trousers which will arouse no suspicion.
Making the secret independently believable
There remained another difficulty.
The Americans had to believe the telegram was genuine.
Britain had an obvious interest in pulling the United States into the war. An extraordinary document conveniently discovered by British intelligence might therefore be dismissed as forgery or propaganda.
The British showed the telegram to the American ambassador in London, Walter Page, in February. American officials were subsequently able to compare it with the encoded message that had passed through their own systems and carry out their own decoding work using code material supplied by Britain. This helped establish that the document was authentic rather than an inventive piece of British political theatre.
The telegram was released to the American press and appeared prominently on 1 March 1917. Some politicians and members of the public initially suspected a British fabrication, but Zimmermann himself then acknowledged that the message was genuine, rather inconveniently collapsing the most useful defence available to Germany.[1][2][3]
There are occasions when honesty is admirable.
There are others when a brief period of strategic vagueness might serve one’s government rather better.
Did it bring America into the war?
The Zimmermann Telegram did not, by itself, cause the United States to enter the First World War.[1][2]
Germany’s renewed unrestricted submarine campaign, attacks on shipping, economic interests and the steady deterioration of German-American relations were already pushing the United States away from neutrality. GCHQ’s own account is careful not to turn the telegram into a single magical cause.
But the message had extraordinary political force.
It transformed a distant European conflict into a direct and intelligible threat. Germany was no longer merely sinking ships in the Atlantic or fighting old empires across the ocean. Its foreign secretary had proposed helping Mexico wage war upon the United States and recover American territory.
The United States declared war on Germany on 6 April 1917. The telegram was not the only reason, but it substantially influenced public and political perceptions at a decisive moment.
The intelligence therefore achieved its purpose.
Britain used the message.
America believed it.
Germany did not discover that Britain had originally recovered it through the interception and reading of diplomatic traffic.
Room 40 retained its deeper secret.
The intelligence gain-and-loss account
The Zimmermann operation can be viewed as a balance sheet.
Using the telegram offered a potential gain:
- changing American opinion;
- strengthening the case against Germany;
- exposing a direct threat;
- possibly accelerating American entry into the war.
Using it carelessly risked losses:
- exposing British interception of American communications;
- revealing that German diplomatic codes were readable;
- causing Germany to replace its systems and procedures;
- damaging relations with the United States;
- making future intelligence collection harder.
Not using it also carried risks:
- allowing a politically powerful revelation to go to waste;
- leaving American decision-makers ignorant;
- preserving a source while losing the opportunity for which the source existed.
This is the same pattern encountered throughout cybersecurity assurance. There is rarely a safe option and a risky option. There are several options carrying different risks, costs, consequences, and uncertainties.
Doing nothing merely chooses one of them without admitting that a choice has been made, and accepts the associated risk whilst pretending that no risk has been accepted.
Sources and methods in the modern world
The technologies have changed, but the problem has not.
A security team may know that an account is compromised because of a classified intelligence report, covert access to criminal infrastructure, sensitive commercial telemetry, a confidential researcher or surveillance that cannot lawfully or safely be disclosed.
Blocking the account immediately may warn the attacker.
Leaving it active may expose the organisation.
Confronting the attacker may burn the collection source.
Inventing an unrelated explanation may preserve the source but complicate evidential handling and trust.
The question is no longer simply: What do we know?
It becomes: What can we safely do that is consistent with knowing it?
Possible answers include seeking corroboration from another source, delaying action, restricting the number of people briefed, producing a sanitised intelligence report, or arranging an intervention that looks as though it arose from routine monitoring.
None is perfect.
That is rather the point.
Information does not become operationally useful merely because it is true. It must also be usable, timely, credible, lawful, and protected.
Looking towards Enigma
The Zimmermann Telegram was one dramatic message.
During the Second World War, the same dilemma would occur at industrial scale as Britain read traffic protected by the German Enigma system.
Bletchley Park had to exploit decrypted intelligence without allowing German commanders to conclude that Enigma itself was compromised. Intelligence sometimes needed corroboration from reconnaissance or another visible source. Action might be delayed, disguised or limited. A perfect operational response to every decrypted message would itself become evidence that the messages were being read.
Alan Turing also helped give wartime cryptanalysis a formal probabilistic language. With Jack Good and others, he developed Bayesian methods for weighing evidence, expressed in units known as bans and decibans. These techniques helped analysts judge competing hypotheses and reduce the work required to attack Enigma traffic.[7]
That mathematical problem and the source-protection problem are closely related, but they are not quite the same:
- How strongly does the evidence support this conclusion?
- How openly dare we behave as though the conclusion is true?
The first concerns knowledge.
The second concerns exposure.
Together, they turn decrypted text into usable intelligence.
We shall return to both in Artefact 012.
The message behind the message
The Zimmermann Telegram is often presented as a triumph of codebreaking, and it was.
But deciphering it was only the opening move.
The larger achievement was constructing a path by which the intelligence could influence events without revealing the continuing British capability behind it. Room 40 did not merely recover the message. It obtained corroboration, protected its source, established credibility, shaped disclosure and produced political effect.
That is not simply cryptanalysis.
That is intelligence engineering.
A secret may be too valuable to reveal and too important to ignore. The art lies in finding a way to use it without explaining why or how you know it.
The telegram was dangerous.
The knowledge of the telegram was more dangerous still.
And so Britain concealed one secret by revealing another.

00001011 VT
REFERENCES
[1] GCHQ. Real World Impact: How GCHQ’s predecessors contributed to the US entering World War I.
GCHQ historical account of Room 40 and the Zimmermann Telegram. Particularly useful for the interception route, President Wilson’s diplomatic channel, Nigel de Grey and Room 40 reading the message, Admiral Hall’s source-protection problem, acquisition of the second copy in Mexico City, publication on 1 March 1917, Zimmermann’s admission, and the important qualification that the telegram contributed to American entry into the war rather than causing it single-handedly. It also explicitly notes that Germany did not discover that its diplomatic codes were readable.
gchq.gov.uk
[2] Jay Bellamy. The Zimmermann Telegram: And Other Events Leading to America’s Entry into World War I.
US National Archives, Prologue, Winter 2016, Vol. 48 No. 4. Covers the German decision to resume unrestricted submarine warfare; Wilson allowing German diplomatic use of the State Department cable; transmission from Berlin through Copenhagen and Britain to Washington; the onward message to Mexico; Room 40; Hall’s dilemma; the Mexico City copy; the agent described as “Mr H”; authentication from American telegraph records; publication; Zimmermann’s admission; and the wider political context leading to the declaration of war.
archives.gov
[3] US National Archives. Zimmermann Telegram (1917).
Primary-document presentation from Record Group 59, General Records of the Department of State, including the coded telegram, decoded version, worksheet, and full English transcript. Best source for the actual proposal: unrestricted submarine warfare; alliance with Mexico; German financial support; proposed recovery of Texas, New Mexico, and Arizona; and the invitation for Mexico to approach Japan.
archives.gov
[4] Walter Hines Page to the US Secretary of State, 24 February 1917. Foreign Relations of the United States, 1917, Supplement 1, The World War, File No. 862.20212/69.
This is the particularly delicious primary source. Page reports Balfour handing him the telegram and explicitly asks that Britain’s source and method be kept “profoundly secret”, while placing no restriction on publication of the telegram itself. It also gives the cover explanation that copies of Bernstorff’s telegrams had been “bought in Mexico”. In other words, the contemporary diplomatic record documents almost exactly the distinction between revealing the intelligence and protecting how it was obtained.
history.state.gov
[5] National Security Agency. The Zimmermann Telegram.
Declassified Cryptologic Quarterly historical study. Particularly useful for the technical and intelligence-management detail: Room 40’s access to German codes, the two different code systems used in the original and forwarded versions, why the Mexico City copy solved the authentication and source-protection problems, American retrieval of the Western Union copy, and the subsequent German investigation which wrongly concluded that its codes had not been broken. It is an excellent supporting source for the “content versus provenance” argument.
media.defense.gov
[6] GCHQ. Nigel de Grey.
Biographical account of the Room 40 cryptanalyst. GCHQ credits de Grey, Alfred “Dilly” Knox, and William Montgomery with breaking the Zimmermann Telegram and records de Grey’s recollection of taking the partially recovered message to Admiral Hall because he immediately understood its political significance. Useful for properly attributing the cryptanalytic work rather than allowing Room 40 to become one amorphous institutional brain.
gchq.gov.uk
[7] GCHQ. Codes, chess and Kubrick: the life of Jack Good; and Director GCHQ, Speech in tribute to Alan Turing.
Useful specifically for bridging into Artefact 012. GCHQ describes Turing and Jack Good developing Bayesian approaches to cryptanalysis and their application to Banburismus, while the Director’s Turing tribute explicitly identifies the ban as a unit devised by Turing and Good for weighing evidence for a hypothesis and notes GCHQ’s continued use of that statistical tradition.
gvhq.gov.uk
