Nation-State Activity

State-sponsored cyber operations, espionage campaigns, and geopolitical cyber conflict.

The New Hire Who Never Existed

For three years, a woman in Arizona kept company laptops running in her spare bedroom for North Korean operators she'd never met. Three hundred and nine US companies hired the people on the other end. None of them noticed.

The New Privateers Won't Know Whose Ship They're Boarding

North Korea's hacking units funded roughly $2.84 billion of the regime's nuclear and missile programs through cryptocurrency theft between January 2024 and September 2025, according to the Multilateral Sanctions Monitoring Team, the eleven-nation coalition that took over UN sanctions monitoring after the original UN Panel of Experts was disbanded. No toolkit built for ordinary criminals has stopped it, and the broader losses Congress itself cites, billions lost to Americans annually through crypto scams, ransomware, and fraud, are real. Indictments against people who never see a US courtroom genuinely are losing that fight. Congress and the White House are now moving on separate tracks to close the gap by commissioning the private sector to hit back, and they're not alone.

Moscow Is Writing the Legal Brief Against Starlink

Call this what it is: foreshadowing, not analysis. When a government publishes a legal case for striking something it hasn't struck yet, that's usually a sign of what comes next, not academic commentary.

A Recurring AI Dispute Just Became a Government-to-Government Fight

Chinese firms distilling capability out of Western frontier models isn't news. It's happened at least three times this year. What's new this time is who is doing the arguing: for the first time, a named US government official made the accusation and opened a formal investigation, and China's government answered with an on-the-record retaliation threat, not researchers and company statements trading claims in the background.

The Modem Nobody Put on the Asset List

Water pressure dropped and some plants flooded in Minnesota last week, when a coordinated attack cut operators off from the equipment that runs their own treatment systems. US investigators think Iran is probably behind it.

Washington shut three doors on China's patent-challenge playbook

Chongqing Yanmei Technology, a Chinese company, challenged a small Ohio inventor's patent at the Patent Trial and Appeal Board, the venue that lets anyone challenge a US patent's validity without a jury trial. The patent covered a dissolvable magnesium alloy Terves LLC had developed to plug oil and gas wells during fracking. In August 2024, the board sided with Chongqing Yanmei and found key claims in Terves' patent unpatentable; Terves salvaged some protection only by amending its claims mid-proceeding. Whatever the merits of that specific case, the pattern behind it is what should worry other small patent holders: a challenge like this is cheap to file and expensive to defend, and the cost of defending one, win or lose, is often enough on its own to force a settlement or bankrupt a small inventor.

Iran's PLC campaign widened to Schneider and Siemens, and the target list now looks like everyone's plant floor

The Iran-linked campaign against US industrial control systems that surfaced this spring got worse on July 22. CISA (the federal cybersecurity agency), the FBI, and the EPA updated their joint advisory on Iran-affiliated hackers who have been breaking into the small industrial computers that run pumps, valves, and production lines, across water, energy, and government facilities, since at least March. Two things changed. The list of affected equipment grew to include Schneider Electric and Siemens controllers, on top of the vendors named in the spring, and some intrusions went further than disruption, modifying or deleting the controller logic itself and disabling safety shutoffs and alarms without alerting operators. NERC, the body that oversees grid reliability, said in the spring it was watching the grid closely, and nothing since suggests that's changed.

The Clean Shell Game

On July 15, the Treasury's sanctions office, OFAC, blacklisted seven people and companies for buying weapons on behalf of Iran's Revolutionary Guard, the branch of Iran's military that runs its operations abroad. It is the same force that killed US troops in Jordan this week, which is why the case surfaced when it did. The war connection is the reason it made the news. What makes it worth reading is how the network was built to look: nothing like Iran.

The Vault Updates From Moscow

An investigation by OCCRP deserves a place on your security radar, because it lands on the single most sensitive tool most companies run: the password manager, the vault that holds the keys to everything else. This is not a story you will catch in your regular feeds.

China Caught a Rocket, and a Ten-Year Lead

On July 10, a Chinese rocket booster dropped out of the sky over the South China Sea and flew into a net. Four hooks on the booster snagged a net strung across a ship. It worked on the first try.

The Cranes at Your Port Answer to Beijing

A study out this month put a number on a supply-chain dependency few companies think to check. Chinese firms own, finance, or operate 78 of Africa's 231 commercial ports, and the control does not stop at the water's edge. It reaches into the software, the automation, and the artificial-intelligence systems that actually run them.

Your Cloud Provider Reset the Quantum Clock

Last month the government set the quantum deadline. This month the companies that run your systems moved it closer, and the money moving underneath tells you why.

The Attack That Hasn't Happened Yet

The head of ASIO, Australia's domestic intelligence agency, used his annual threat assessment this month to describe a kind of breach that should change how you read the word. A foreign government's hackers had been inside an Australian critical infrastructure provider for months. They had not stolen data or sent a ransom note. They had taken the login credentials of the network's active users, including the IT staff guarding it, mapped the entire system, and quietly held on to their access. The purpose, ASIO concluded, was sabotage: "mapping out the network and maintaining access so they could cripple it at a time of their choosing."

Every Vendor Is Rushing AI Out the Door. Nobody Is Checking What's Underneath.

In the time it takes to read this paragraph, a software company somewhere shipped an AI feature built on components nobody reviewed. The competitive pressure to add artificial intelligence to every product, every platform, and every internal tool has created a supply chain problem that most companies have not recognized yet, because it sits one layer below the product they actually bought.

They Lived on the Firewall for Eighteen Months

The security hardware meant to keep attackers out, and the outside firm hired to run a company's technology, are the two places monitoring rarely reaches. They are also where a patient intruder settles in for a year or more.

The Headhunter on LinkedIn Is a Chinese Intelligence Officer

On June 4, the Five Eyes intelligence alliance published its first-ever joint bulletin titled "Safeguarding Our Secrets," warning that China's military intelligence services are systematically impersonating headhunters on LinkedIn to recruit sources inside government, defense, media, and any organization with access to trade secrets or sensitive technology. The fake recruiters operate through front companies with storefronts in Singapore and New York. They offer cash for "articles" and "market insights," requests that sound like consulting work until the questions narrow to classified programs, proprietary processes, or deal timelines. Payments arrive through PayPal, Wise, Zelle, and cryptocurrency.

The One Country That Could End This Has Less Reason To Try

China was the last credible pressure point on Iran. Beijing buys Iranian crude. Beijing has diplomatic channels. Beijing has economic leverage. For eleven weeks, the assumption in Western capitals has been that China would eventually lean on Tehran because the Hormuz closure hurts Chinese energy imports too. OPEC (the oil exporters' cartel) already fractured when the UAE exited last month. China was supposed to be the remaining lever.

The Summit That Settled Nothing

The Trump-Xi summit in Beijing closed May 15 with a verbal framework both sides described as "constructive, strategic, and stable." No formal joint statement was issued. No chip export relief was announced. No rare earth supply framework was agreed. Jensen Huang attended as one of seventeen CEOs in the delegation and left without a semiconductor deal.

Your Supply Chain Runs Through a Summit

China controls roughly 60 percent of global rare earth mining, 90 percent of processing, and a significant share of the base chemicals other countries need to do their own processing. The materials go into motors, batteries, medical devices, defense systems, and the electronics on every desk in your office. Diversifying away from Chinese rare earths runs into a Chinese dependency one layer down. On Wednesday, President Trump meets President Xi in Beijing for a two-day summit where rare earth supply commitments and semiconductor export controls are both on the table.

Two Adversaries, One Water System

Poland's internal security agency warned in early May that Russian-linked hackers breached the control systems at five municipal water treatment facilities and gained the ability to change how the equipment operates. In April, Sweden attributed a cyberattack against a thermal power plant to actors connected to Russian intelligence. Two NATO members, two types of critical infrastructure, the same adversary, within weeks of each other.

Your Office Router Is Someone Else's Infrastructure

Nearly a dozen governments and their intelligence agencies published a joint advisory on April 23 naming what they found inside consumer-grade network equipment worldwide. The answer was the Chinese military.

The Arsonist Owns the Fire Department

In March 2026, HMN Technologies (the successor to Huawei Marine, now owned by Hengtong Group) finished splicing 6,300 kilometers of new submarine cable across the Indian Ocean, extending the Pakistan-Egypt-Marseille PEACE system into Singapore. Three weeks later, on April 11, Chinese state-backed researchers tested a deep-water cable cutter rated to 3,500 meters. Same actor. Same body of water. Same month.

Tony, Danny, and Eighty People Who Were Not There

State of the Threat readers have followed this story all year. February 21: we covered the shift from fake LinkedIn profiles to stolen real identities. March 8: nearly every Fortune 500 CISO admitting they had unknowingly hired at least one DPRK IT worker. March 22: Treasury sanctions on the facilitators. This week, the prosecutions arrive.

Three Things You Trust That You Shouldn't

Your security perimeter protects your network. The problem is how much of your business runs on infrastructure that isn't your network. Three stories this week exposed three versions of the same blind spot.

Iran Declared Your Vendors Military Targets. Then It Followed Through.

On March 31, the Islamic Revolutionary Guard Corps published a list of 18 companies it designated as "legitimate military targets." The list included the companies that run most of American business technology: Microsoft, Google, Apple, Meta, Nvidia, Intel, Cisco, Oracle, Dell, HP, IBM, and Palantir. It also included JPMorgan Chase, Tesla, General Electric, Boeing, Abu Dhabi AI firm G42, and Dubai cybersecurity firm Spire Solutions, broadening the threat beyond tech to American financial, industrial, and regional partners. Amazon was not on the list. Its data centers had already been hit. The IRGC gave an 8 PM Tehran time deadline and warned employees to evacuate immediately.

The AI Inside Your Software May Already Report to Beijing

Chinese AI models now handle roughly 45% of workloads on major AI routing platforms, up from 1.2% in late 2024. In one week in February, they hit 61%. The reason is cost. DeepSeek charges roughly a tenth of what comparable American models cost. Alibaba's Qwen family has been downloaded 700 million times. Developers have created 180,000 derivative versions built on top of those models. This isn't a consumer app trend. It's a shift in the infrastructure layer that software companies build on.

The Government Just Published Its Threat Model. Your Board Should Read It.

On March 18, the Office of the Director of National Intelligence released the 2026 Annual Threat Assessment before the Senate Select Committee on Intelligence. Director of National Intelligence Tulsi Gabbard presented the findings. The document is the intelligence community's annual public accounting of who threatens the United States and how.

CISA, FBI, and the Lawyers All Came for Stryker This Week

Last week we covered Handala's wiper attack on Stryker Corporation, the medical device manufacturer that initially reported 200,000 systems destroyed across 79 countries. This week, three separate forces closed in on the company at once.

Latin America Is Splitting in Half

On March 13, Brazilian President Luiz Inácio Lula da Silva revoked the visa of Darren Beattie, a State Department official serving as senior advisor for Brazil policy, after Beattie attempted to visit former Brazilian President Jair Bolsonaro in prison. Bolsonaro is serving a 27-year sentence for his role in a coup plot. The move was reciprocal. The Trump administration had denied a visa to Brazil's health minister weeks earlier. US-Brazil relations are at their lowest point in decades.

Iran Wiped 200,000 Systems at a Medical Device Company That Serves Your Hospital

On March 11, a group called Handala deployed wiper malware across Stryker Corporation's global network. Within hours, 200,000 systems, servers, and mobile devices were erased across 79 countries. Stryker's 56,000 employees were told to power down everything. Order processing, manufacturing, and shipping stopped. In its 8-K filing with the Securities and Exchange Commission, Stryker said it found "no indication of ransomware or malware" and believed the incident was contained, but acknowledged the timeline for full restoration is unknown and has not yet determined whether the incident is "reasonably likely to have a material impact."

China Collects Against Its Allies. Your Vendor Agreement Won't Stop Them.

A leaked FSB document calls China "the enemy." A Chinese APT spent five months in a Russian defense contractor's build systems. Russia stayed quiet because it can't afford not to. Most businesses operating with Chinese partners are making the same calculation without realizing it.

China's Kill Chain Is 15 Years Long

A Chinese businessman stole F-35 blueprints in 2008. A former F-35 instructor was just arrested for training the pilots who will fly against them.