This website uses cookies

Read our Privacy policy and Terms of use for more information.

In partnership with

Weekly Intelligence for a Digital World

INTELLIGENCE BRIEF // DECLASSIFIED

Briefing No. 101
August 25, 2026

Note From Eric

I spent most of last week in bed.

My family returned home from Germany carrying a virus that my immune system was apparently unprepared to fight. One daughter caught it on the trip. It worked its way through the family. Then it found me.

I spent the next week valiantly trying to get better while becoming increasingly frustrated by everything I wasn’t doing. Client work piled up. My new book sat neglected. The mountain of research that goes into this newsletter kept growing while I contemplated the extraordinary distance between my bed and my desk.

It always amazes me that during the first days of an illness that knocks me off my feet, it feels as though I will never recover. I don’t pretend to understand the psychology behind this, but eventually, almost as if God poked me with his finger, the overwhelming malaise retreated and healing began.

What frustrated me most was that I work pretty hard to prevent exactly this sort of thing. I exercise almost every day. I eat well. My principal vice is coffee. I try, with varying degrees of success, to manage stress. None of it mattered. Something got through the defenses, overwhelmed the system and shut me down.

Which, as I finally dragged myself back to my desk, struck me as a pretty good metaphor for cybersecurity.

We spend enormous amounts of time trying to stop attacks. We build firewalls, deploy endpoint protection, require multifactor authentication, patch vulnerabilities and train employees. All of that matters enormously, but eventually something gets through. The question then becomes whether you have built an organization capable of getting back on its feet.

Welcome to Issue 101. This week we’re talking about resilience.

Title Story

The Generator Was Small, The Warning Was Not

Thank you to Laura for sending me this story!

A reported Iran-backed cyberattack knocked a small British power generator offline for four days in July. Four days.

The good news is that Britain’s wider energy system was never in danger. The UK Department for Energy Security and Net Zero confirmed that a cyber incident affected what it described as a “small-scale energy generator” and said there was no threat to the broader energy system.

The attribution is less certain. British officials have publicly confirmed the incident and its effect, but they have not formally attributed the attack to Iran. Press reports blame Iran-linked hackers. No public forensic evidence establishing the attacker has been released.

So here’s what we know. Someone successfully attacked a British energy generator. The attack had enough operational impact to knock the facility offline for four days.

Here’s what we don’t know. We don’t know which generator was attacked. We don’t know who operates it, its generating capacity, how the attackers got inside, what systems they compromised, what malware or tools they used or precisely why the facility required four days to recover. I’m putting my money on Iran, but I’m waiting for the British government to show us the evidence.

That uncertainty actually makes the attack more interesting.

It would be easy to dismiss this because the generator was small and Britain’s grid kept humming. That’s a mistake. Counterintelligence officers don’t judge an adversary solely by the operation they happen to catch.

Was this an opportunistic intrusion? Was the generator simply vulnerable? Was someone testing capabilities? Was it reconnaissance that turned into disruption? Was the attacker trying to learn something? We don’t know. And that’s the point.

A small attack doesn’t necessarily demonstrate the limit of an adversary’s capability. Sometimes it only demonstrates the part of the operation you can see.

Iran has long understood the asymmetric value of cyber operations. So have Russia, China and North Korea. Cyber capabilities allow governments and their proxies to steal, surveil and disrupt targets thousands of miles away without sending a soldier across a border.

The UK incident gives us something unusually tangible. Something stopped working. That moves the discussion away from theoretical vulnerabilities and stolen data and into operational consequence.

The generator was eventually restored. Which brings us to the important part: it got back up.

Tip of the Week

Take the Four-Day Recovery Test

Security teams spend enormous energy asking how to keep attackers out. Here’s another question worth asking: If they get in and take something critical offline, how quickly can you recover?

Run the Four-Day Recovery Test against your most important systems. Determine who can remotely access them and make sure every legitimate route is controlled and logged. Understand which critical operations can safely continue locally or manually if the network disappears. Make certain you have known-good configurations, backups and credentials rather than discovering during an emergency that your recovery environment was compromised too.

Most important, practice the recovery. A plan sitting in a binder is a theory. Restoration performed under simulated attack conditions is a capability.

We don’t know how the British generator was compromised, so these aren’t prescriptions for stopping that particular attack. They’re preparation for the day something gets through yours.

Breach of the Week

The 31-Terabyte University Heist

While Britain was dealing with Iran’s alleged attack against energy infrastructure, the U.S. Justice Department revealed the extraordinary scale of another Iranian cyber operation.

Federal prosecutors have charged 17 alleged members of Iran’s Mabna Institute in a superseding indictment describing a massive campaign against universities, companies, government agencies and other organizations1. According to the DOJ, the attackers targeted more than 100,000 professor accounts, compromised roughly 8,000 of them and stole at least 31.5 terabytes of academic data and intellectual property from 144 American and 178 foreign universities.

There’s an important chronology point here. The principal university campaign occurred between 2013 and 2017. The August 2026 development is the new superseding indictment and additional allegations, not a new 31-terabyte breach.

But the operation illustrates something about espionage that hasn’t changed. The spies didn’t have to recruit the professor. They stole the professor’s identity.

Prosecutors allege the hackers used techniques including spearphishing to capture legitimate credentials, turning trusted users into unwitting access points for collecting research and intellectual property. DOJ alleges many intrusions were conducted for the Islamic Revolutionary Guard Corps and other Iranian clients, while stolen information and access were also sold commercially.

The takeaway is simple: research identity is privileged identity. Scientists, professors, engineers, lawyers and executives may possess information every bit as valuable as the data protected inside traditional high-security environments. Protect their identities accordingly.

AI Watch

The Hacker Who Hired Eight AI Agents

There is another reason resilience is becoming more important. Attackers are scaling.

Dream Research Labs recently described an overseas cyber spy who allegedly deployed as many as eight AI agents simultaneously during attacks against government targets in Asia. According to Dream, the operation mapped 21 connected government systems, compromised 85 accounts and extracted more than 2,500 personnel records.

Taiwan has separately confirmed foreign attacks against government agencies involving AI-agent assistance, although the two accounts should not be treated as conclusively the same operation. Still, it’s looking a lot like the Chinese government is behind the attack.

The larger development matters regardless. For years, cybersecurity has been constrained by something surprisingly mundane: labor. A human attacker can only research so many targets, test so many credentials and analyze so much stolen information at once.

Agentic AI begins changing that equation. One capable cyber criminal or spy can increasingly behave like a small intrusion team, assigning different agents to reconnaissance, credential attacks, exploitation and collection while the human operator directs the larger mission.

The attacker doesn’t need eight hackers. He only needs eight AI agents.

That means defenders should start thinking differently about scale. The attack that previously required a team may increasingly be launched by one person with the right tools.

Continue the Mission

If you enjoyed this week’s newsletter, you’ll find even more inside my new book, SPIES, LIES, AND CYBERCRIME. Drawing on my years hunting spies for the FBI, it reveals how espionage, cybercrime, and AI-powered deception intersect—and what you can do to stay one step ahead.

Ready for the next mission?

Already read the book? A quick review on Amazon or Goodreads helps more readers discover it. Thank you for your support.

Please support my sponsors. It only takes a click - no purchase necessary!

You Use AI Every Day. Why don't you own any of it?

You probably opened something powered by AI before your first coffee this morning. Millions of people do. Almost none of them own a piece of it.

That's been the catch with the AI boom — the biggest gains went to insiders and venture funds, while the companies actually building the frontier stayed private and out of reach.

That's starting to change. A wave of AI IPOs is forming, and a few are shaping up to be among the most retail-accessible mega-listings in years — the rare chance to get in near the ground floor instead of reading about the gains after the fact.

Our free briefing lays out the timeline, the access window, and the filing risk most investors will miss. No credit card. Sent straight to your inbox.

Know Someone Who’d Enjoy This?

If someone forwarded you this newsletter, join nearly 5,000 readers every Tuesday for practical lessons from the worlds of espionage, cybercrime, artificial intelligence, and the human stories behind them.

Closing Thoughts

Which brings us back to where we started. I got sick despite doing most of the things you’re supposed to do to stay healthy. Security works the same way. Preparation matters. Prevention matters. Good defenses dramatically reduce your chances of getting hit. But resilience begins with accepting an uncomfortable reality: defenses sometimes fail.

The healthiest organizations won’t necessarily be the ones that never suffer an attack. They will be the ones that detect it, contain it, recover from it, learn from it and become harder to defeat the next time.

Last week, that meant finally getting myself out of bed. For the British generator, it meant getting the power flowing again.

For the rest of us, the question is worth asking before we’re attacked: How quickly can you get back on your feet?

Stay safe out there and keep thinking like a spy hunter.

Praemonitus Praemunitus!

Forewarned is Forearmed!

~Eric

Reply

Avatar

or to participate

Recommended for you

View all
caret-right