This website uses cookies

Read our Privacy policy and Terms of use for more information.

In partnership with

Weekly Intelligence for a Digital World

INTELLIGENCE BRIEF // DECLASSIFIED

Briefing No. 0XX
DATE, 2026

Title Story: How governments are quietly turning cybercriminals into the spies of the digital age.

Breach of the Week: Why your health records have become one of the most valuable commodities on the Dark Web.

Tip of the Week: The forgotten accounts lurking inside your network may be your greatest security risk.

AI Watch: The internet’s newest AI craze shows how easily authenticity itself can be forged.

Think Like a Spy: The most successful deception begins with a story that’s mostly true.

From the Field: I joined Chris Vogt to discuss how AI is reshaping trust, cybercrime, and high-value business transactions.

Note From Eric

Editor’s Note

If you followed the news this week, you’ve probably seen the release of newly declassified documents concerning Chinese activity targeting elements of U.S. election infrastructure. I’ve spent time reviewing the available material, and one conclusion stands out.

The documents reinforce that China had both the capability and the intelligence interest to collect voter data and probe weaknesses in election-related systems. Furthermore, it is clear that our election infrastructure is both vulnerable and highly targeted by foreign threat actors. However, the documents also underscore something equally important: based on the material currently available, they do not establish that ballot-casting or vote-counting systems were successfully compromised or that certified election results were altered. Next week, after more information is available and I have additional time for analysis of the declassified intelligence documentation, I’ll write a more robust opinion.

In the meantime, as a former counterintelligence investigator, I’ve learned that espionage is rarely about dramatic moments. More often, it’s about patiently collecting access, identities, and influence long before they’re ever needed.

That idea is at the heart of this week’s newsletter. Whether we’re talking about Russian cyber proxies, stolen credentials, artificial intelligence, or election infrastructure, the lesson is the same: in modern espionage, trust has become the most valuable target.

Title Story

THE KREMLIN’S CRIMINAL ARMY

How modern intelligence services turned cybercriminals into the world’s most effective spies.

During the Cold War, intelligence officers rarely met their spies face to face. Instead, they relied on intermediaries known as cutouts—trusted go-betweens who delivered money, passed messages, arranged secret meetings, and insulated the intelligence officer from discovery. If an operation unraveled, investigators found the cutout, not the government directing it.

The brilliance of the cutout wasn’t convenience. It was plausible deniability.

That tradecraft never disappeared. It simply went digital.

Last week, the United Kingdom and the European Union announced coordinated sanctions against what officials describe as a sprawling Russian cyber ecosystem responsible for espionage, sabotage, ransomware, credential theft, and attacks against critical infrastructure across Europe. Most headlines focused on the sanctions. They missed the more important story: modern intelligence services no longer need to build every cyber capability themselves.Why recruit and train an army of hackers when criminal organizations have already built one? Malware developers, ransomware operators, credential thieves, cryptocurrency launderers, and bulletproof hosting providers already possess the expertise and infrastructure governments need. Today’s cutout isn’t a courier with a briefcase. It may be a ransomware gang, an infostealer developer, a hosting company, or even a Telegram administrator rallying patriotic volunteers. To the victim, it looks like ordinary cybercrime. To an intelligence service, it’s another instrument of national power.

According to the European Union, Russia has cultivated a cyber ecosystem that blends state intelligence services with criminal proxies and technical enablers pursuing Russian strategic objectives. The sanctions announced this week target individuals and organizations connected to credential theft, malware development, ransomware operations, and attacks against public services and critical infrastructure.

One example illustrates the stakes. British officials disclosed that a Russian-attributed cyberattack attempted to disrupt Poland’s energy grid. The attack failed, and no one lost power. But according to the UK government, had it succeeded, as many as 500,000 people could have been left without electricity during winter.

That matters because the objective wasn’t financial. It was geopolitical. Cybercrime has become one of the least expensive ways for governments to project power without crossing the threshold into conventional war. Criminal infrastructure provides technical expertise, operational reach, and, perhaps most importantly, deniability. When an operation is exposed, governments can dismiss it as the work of “independent hackers” while quietly benefiting from the access those criminals created.

This convergence of espionage and cybercrime should change the way organizations think about security. Too often, credential theft is treated as an IT problem and ransomware as organized crime. Increasingly, those same stolen passwords become intelligence assets. Access obtained for profit today may be repurposed for espionage or sabotage tomorrow.

That’s why identity has become the newest battlefield. Every forgotten administrator account, stale VPN credential, dormant contractor login, or privileged service account represents more than a security vulnerability. It is an opportunity.

The lesson extends well beyond Russia. Governments and criminals increasingly borrow from one another’s playbooks until the line separating espionage from cybercrime becomes difficult to distinguish. The next time you read about a ransomware attack, don’t stop at asking who demanded payment. Ask yourself who else benefits from the access. Sometimes the ransom is simply a distraction from the espionage goals.

Spy Hunter’s Lesson: The best intelligence operations hide behind someone else’s fingerprints. In cyberspace, those fingerprints increasingly belong to criminals.

Breach of the Week

Your Medical File Is Worth More Than Your Credit Card

Most people assume criminals want their credit card numbers. Increasingly, they want something far more valuable: medical records. Unlike a credit card, your medical history can’t simply be canceled and replaced. It provides criminals with enough information to commit insurance fraud, build synthetic identities, and craft remarkably convincing phishing attacks.

This week, Centers Laboratory disclosed a data security incident involving sensitive patient information, adding to the growing list of healthcare organizations targeted by cybercriminals. Whether or not your information was affected, the lesson is the same. If a healthcare provider notifies you of a breach, review your insurance statements, monitor your explanation of benefits, and remain skeptical of anyone contacting you about your medical care. Once criminals know your story, they become much better storytellers.

Tip of the Week

Kill Your Zombie Accounts

Every organization has them: former employees whose accounts were never disabled, contractors who can still log in months after a project ends, forgotten service accounts quietly running in the background. Cybersecurity professionals call them dormant accounts. I call them zombie accounts because they should be dead but continue wandering your network.

This week’s title story explains why they’re so dangerous. Cybercriminals don’t always break in. Sometimes they simply log in using credentials purchased on the Dark Web. A forgotten account can be worth more than an unpatched vulnerability because it already carries your organization’s trust.

Take fifteen minutes this week to ask five questions. Do former employees still have access? Are contractor accounts reviewed regularly? Are old service accounts still necessary? Do privileged accounts require phishing-resistant multi-factor authentication? When was the last dormant account audit? Security isn’t just about building stronger defenses. It’s about making sure nobody left a key under the welcome mat.

AI Watch

“/generatehandwrittenimage”

One of this week’s most popular AI trends isn’t creating fantasy artwork or cinematic portraits. It’s generating realistic handwriting. Using a simple prompt like /generatehandwrittenimage, users are creating remarkably convincing handwritten notes, journal pages, postcards, and letters complete with crossed-out words, notebook paper, and unique penmanship.

It’s entertaining, but it also reveals where AI is heading. For generations we’ve associated handwriting with authenticity. A handwritten note feels personal because we assume another human took the time to write it. Artificial intelligence is beginning to undermine that assumption.

Imagine receiving what appears to be a handwritten note from your financial advisor asking you to call about an exclusive investment opportunity. Soon, appearance alone may no longer tell us whether a person ever picked up a pen. AI isn’t just learning to imitate images and voices. It’s learning to imitate authenticity itself.

It’s also quite handy to create a study guide. I created this note from a portion of my reader-favorite issue: The Vacation Trap

Think Like a Spy

The Best Cover Story Contains the Truth

Hollywood loves to portray spies as master liars spinning elaborate stories from thin air. In reality, successful espionage usually works very differently. The most effective cover stories are built on truth. A criminal steals credentials because they’re valuable. A ransomware gang wants to make money. A hacktivist genuinely believes they’re advancing a political cause. All of those motivations are real, and that’s precisely what makes them useful to an intelligence service.

Rather than inventing an operation from scratch, experienced intelligence officers often look for existing activity they can quietly exploit. They borrow infrastructure, motivations, and opportunities that already exist, allowing someone else to absorb the attention if the operation is exposed. That’s one reason today’s most dangerous cyberattacks frequently resemble ordinary criminal activity. The cover story isn’t fabricated; it’s borrowed.

The next time you read about a ransomware attack or a major credential theft, don’t stop at asking who committed the crime. Ask a second question: Who else benefits? That simple habit has uncovered more espionage operations than any sophisticated technology ever invented.

From the Field

Talking AI, Spies, and Cybercrime

One of the great privileges of this work is the opportunity to continue the conversation long after I step off the stage. Last week I joined commercial real estate expert Chris Vogt for a wide-ranging YouTube interview on a subject that affects every industry today: the growing trust crisis created by artificial intelligence and cybercrime.

Commercial real estate provided the perfect backdrop for the discussion. High-value transactions often depend on long-standing relationships, email communications, and the assumption that the person on the other end of the conversation is exactly who they claim to be. Those same elements have become prime targets for cybercriminals using AI to impersonate trusted advisors, manipulate financial transactions, and exploit the confidence that makes business possible.

Continue the Mission

If you enjoyed this week’s newsletter, you’ll find even more inside my new book, SPIES, LIES, AND CYBERCRIME. Drawing on my years hunting spies for the FBI, it reveals how espionage, cybercrime, and AI-powered deception intersect—and what you can do to stay one step ahead.

Ready for the next mission?

Already read the book? A quick review on Amazon or Goodreads helps more readers discover it. Thank you for your support.

Please support my sponsors. It only takes a click - no purchase necessary!

The free newsletter making HR less lonely

The best HR advice comes from people who’ve been in the trenches.

That’s what this newsletter delivers.

I Hate it Here is your insider’s guide to surviving and thriving in HR, from someone who’s been there. It’s not about theory or buzzwords — it’s about practical, real-world advice for navigating everything from tricky managers to messy policies.

Every newsletter is written by Hebba Youssef — a Chief People Officer who’s seen it all and is here to share what actually works (and what doesn’t). We’re talking real talk, real strategies, and real support — all with a side of humor to keep you sane.

Because HR shouldn’t feel like a thankless job. And you shouldn’t feel alone in it.

Know Someone Who’d Enjoy This?

If someone forwarded you this newsletter, join more than 4,500 readers every Tuesday for practical lessons from the worlds of espionage, cybercrime, artificial intelligence, and the human stories behind them.

Closing Thoughts

Every week seems to bring another ransomware attack, another data breach, another artificial intelligence breakthrough, and another reminder that the digital world is becoming more complex. It’s easy to look at the headlines and conclude that technology is changing faster than anyone can keep up.

Yet after years spent hunting spies and studying cybercriminals, I’ve become convinced that the fundamentals haven’t changed nearly as much as we think. Technology evolves constantly, but human nature remains remarkably consistent. Spies still manipulate trust. Criminals still search for the easiest path into their target. Intelligence services still rely on plausible deniability. The tools may become more sophisticated, but the underlying tradecraft endures.

The better you understand how deception works, the more difficult you become to deceive.

Until next Tuesday,

Praemonitus Praemunitus!

Forewarned is Forearmed!

~Eric

Reply

Avatar

or to participate

Recommended for you