This brief highlights significant threats to US homeland security posed by China, Russia, Iran, and North Korea observed in August 2026.
Executive Summary:
Observed Threats - Current activity that poses direct risk to US homeland security
The US Department of Justice indicted 17 Iranian nationals for their involvement in cyber espionage operations targeting American universities, companies, and research institutions as part of the Islamic Revolutionary Guard Corps-affiliated Mabna Institute.
A Chinese national pleaded guilty to violating the US Arms Export Control Act for attempting to smuggle encrypted US military satellite radio systems to China through Mexico.
A CNN investigative report highlighted a surging number of suspicious incidents involving Chinese nationals near US military bases. The incidents involve surveillance, increasingly facilitated by drones, and collectively appear to form a decentralized Chinese intelligence campaign.
A new report by the House Select Committee on Strategic Competition between the United States and the Chinese Communist Party highlighted threats to US critical infrastructure posed by the continued presence of components sourced from banned Chinese companies in US internet networks.
Horizon Threats - International activity that may pose future risk to US homeland security
Germany blamed Russian military intelligence for an attempted attack at Leipzig/Halle Airport involving multiple armed drones.
The Telegraph reported disclosures by British officials that an Iran-linked cyber attack shut down a small power plant in the country for four days.
OBSERVED THREATS
Current activity that poses direct risk to US homeland security
1. SEVENTEEN IRANIANS INDICTED FOR CYBER ESPIONAGE CAMPAIGN AGAINST US INSTITUTIONS
On August 18, 2026, the US Department of Justice (DOJ) announced charges against 17 Iranians for an expansive state-directed cyber espionage and theft campaign targeting US companies, government agencies, and universities. The indicted Iranian hackers were affiliated with the Mabna Institute, an Iranian Islamic Revolutionary Guard Corps (IRGC)-affiliated company founded in 2013 to steal foreign research for Iranian universities. According to the indictment, since its founding, the Mabna Institute has targeted as many as “144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations (NGOs)”, and stolen 31 terabytes of data and intellectual property.
The Mabna Institute hackers specifically sought research in medical and scientific fields and sold acquired data to Iranian academic publishing houses Megapaper.ir (Megapaper) and Gigapaper.ir (Gigapaper). The DOJ estimated that the value of the stolen research could have amounted to $3.4B.
Additional Information:
It is likely that the Mabna Institute specifically targeted universities due to their perceived value as the easiest targets within the US’s broader scientific research community. The hackers targeted 100,000 professors worldwide and successfully compromised at least 8,000 email accounts.
The Mabna Institute is only one of a number of Iranian actors targeting US research and intellectual property in recent years, motivated in part by a desire to circumvent the country’s global isolation. A May 22, 2026, report by cybersecurity firm Palo Alto Networks identified several clusters associated with the Iranian government-linked “Screening Serpens” advanced persistent threat group (AKA Nimbus Manticore, Smoke Sandstorm, UNC1549) that have targeted critical industries in the US, UK, and Middle East since late 2025. That campaign has utilized sophisticated lures, including personalized fake job postings for IT and software engineering positions, used to gain access to an individual’s devices and credentials.
2. CHINESE NATIONAL PLEADS GUILTY TO SMUGGLING US MILITARY COMMUNICATIONS EQUIPMENT THROUGH MEXICO
On August 10, 2026, 29-year old Chinese citizen Dingwei Chen pleaded guilty to violating the US Arms Export Control Act. Chen worked as part of a network of Chinese actors to purchase US military communications equipment, including encrypted satellite radios, and smuggle them back to China through Mexico.
Chen arranged for the purchase of 10 systems using encrypted messaging apps and a combination of cash and cryptocurrency:
“After making an initial down payment of over $40,000 U.S. dollars, Chen and his co-conspirators switched to cryptocurrency, noting that “cold wallets are essentially anonymous bank accounts. Each transaction processed through them is private and untraceable.” They went on to pay roughly $30,000 worth of USDT, which is a type of cryptocurrency.”
Additional Information:
The guilty plea represents only the latest instance of Chinese smuggling of US military equipment abroad, and not just to supply the Chinese military but onward to partner nations such as North Korea and Iran:
In January 2024, four Chinese nationals—Liu Baoxia (刘保霞/ 劉保霞), also known as Emily Liu; Li Yongxin (李永欣), also known as Emma Lee; Yung Yiu Wa (耀華 容), also known as Stephen Yung; and Zhong Yanlai (鐘硯來), also known as Sydney Chung—were indicted by the US Department of Justice for a years-long operation smuggling controlled US-origin technology products through front companies in Hong Kong and mainland China to entities affiliated with the Iranian IRGC. In March 2025, the US Department of State announced a $15M reward for information leading to the arrest of the group.
In August 2025, a Chinese national was sentenced to eight years in US federal prison for smuggling $2M worth of US firearms, ammunition, and sensitive dual-use technology to North Korea via intermediaries in China. The US Department of Justice subsequently charged five additional Chinese nationals and one US citizen for their role in the scheme in January 2026.
3. NEW REPORT HIGHLIGHTS UNUSUAL AND GROWING CHINESE INTELLIGENCE CAMPAIGN TARGETING US MILITARY BASES
An August 31, 2026, report by CNN detailed a multi-agency effort to identify and counter growing drone intrusions at US military installations by Chinese nationals believed to be operating on behalf of Chinese intelligence. The report was particularly noteworthy for its depiction of such operations as a mix of targeted intelligence gathering and what officials termed “nuisance surveillance” conducted by amateurs and “intelligence entrepreneurs”.
Additional Information:
OPFOR Journal’s Homeland Security Brief - January 2026 noted that there have been dozens and possibly hundreds of cases of suspicious incidents involving Chinese nationals near US military bases in recent years. Many of the incidents appear individually innocuous, involving misunderstandings by enthusiastic tourists and hobbyists. However, when viewed collectively they suggest a pattern of coordinated crowd-sourced intelligence collection by Chinese authorities. As noted in the CNN article, the less professional “nuisance” operations may be intended to confuse US authorities and complicate efforts to identify and disrupt more sophisticated intelligence-gathering operations.
4. CONGRESSIONAL REPORT: BANNED CHINESE TELECOM COMPANIES MAINTAIN PRESENCE IN US CRITICAL INFRASTRUCTURE
On August 4, 2026, the House Select Committee on Strategic Competition between the United States and the Chinese Communist Party released a new investigative report “Stranger Pings: Chinese Telecom Companies Infiltrate U.S. Infrastructure” detailing the continued presence of components sourced from banned Chinese companies in US internet networks. The report specifically identified China Telecom Americas (CTA), China Mobile International USA (CMI USA), and China Unicom Americas (CUA), which previously had their Section 214 telecommunications licenses denied or revoked. The report states that the companies’ equipment has remained in place throughout US critical infrastructure due to loopholes in regulation that did not require the physical removal of affected Chinese components.
Of particular concern are Chinese components present in critical data chokepoints, including landing stations for submarine cables. According to the report:
CTA’s 2025 production to the Select Committee identified ten active points of presence (PoPs) across seven U.S. metro areas known for their concentration of data centers, submarine cable landings, or both: Ashburn, VA, Chicago, IL, Hillsboro, OR, Los Angeles, CA, Miami, FL, New York, NY, and San Jose, CA. CTA stated that it “only owns network equipment in the PoPs” with sites located in facilities operated by U.S. and PRC digital infrastructure companies.
CUA had the most extensively documented footprint. Witness 6 confirmed that the company owned equipment at leased facilities, and Witness 7 described roughly ten data centers after two closures. The company’s representations to the Select Committee document active colocation cages, power allocations, and live cross-connects across Ashburn, Chicago, Dallas, Hillsboro, Los Angeles, Miami, New York, Reston, San Jose, Seattle, and Palo Alto among various providers. Notably, CUA retained active interconnections with major U.S. backbone providers.
CMI USA’s posture was different because the FCC denied China Mobile USA’s Section 214 application before the company received authority to provide covered international common-carrier services. Even so, CMI USA’s records identified 39 U.S. PoP entries across 27 distinct data center and interconnection facilities operated by U.S. digital infrastructure companies. This vast physical footprint allows the company to bypass the regular public internet and handle staggering amounts of data. Anchored inside major internet hubs across Los Angeles, New York, and Chicago, CMI USA commands an immense total network capacity of up to 1,380 gigabits per second. An internal interconnection inventory produced by the company details how the company uses its physical presence inside these facilities to plug directly into global telecom backbones, public data exchanges, and the private networks of major American tech giants operating right next to them. This is consistent with the Select Committee’s Shodan scans at the time, which identified at least 143 active China Mobile network assets across U.S. facilities.

Additional Information:
The report suggests that the affected technology in US systems opens networks to intrusions by Chinese state-affiliated cyber actors such as “Salt Typhoon”, a notorious group that has targeted US critical infrastructure since 2021. While a definitive link between Salt Typhoon and China Telecom, China Mobile, and China Unicom has not been independently established, previous reporting has suggested that the group appears to utilize inside knowledge of network architecture to evade detection and conduct operations, potentially facilitated by compromised hardware. Investigations into previous Salt Typhoon intrusions have traced its attacks on US government and defense industry networks, through US telecom companies, back to an apparent origin in Chinese infrastructure.
HORIZON THREATS
International activity that may pose future risk to US homeland security
5. ATTEMPTED RUSSIAN DRONE ATTACK THREATENS GERMANY’S LEIPZIG/HALLE AIRPORT
On August 4, 2026, an employee at Germany’s Leipzig/Halle Airport discovered a drone carrying an explosive device on the tarmac next to a Ukrainian An-124 cargo aircraft. The drone was part of an attempted sabotage attack that both the US and Germany have attributed to Russian military intelligence (GRU). DNA recovered from the drone matched evidence recovered from another suspected Russian plot involving incendiary packages aboard DHL commercial flights at the same airport in July 2024. Another armed drone was later recovered in a field west of the airport.
Additional Information:
The July 2024 plot involved at least four packages shipped through DHL from Lithuania to the UK and Poland. The plot has been assessed as a trial run for larger explosives to detonate in flight and destroy the DHL aircraft.
According to German newspaper Süddeutsche Zeitung, a confidential situation report by the German Federal Criminal Police Office (BKA) has identified as many as 165 suspected cases of sabotage and 747 suspicious drone incidents in Germany in 2026. Russian involvement is suspected in many of the cases.
6. IRANIAN-LINKED CYBER ATTACK SHUTS DOWN UK POWER PLANT
On August 23, 2026, The Telegraph reported disclosures by British officials that Iranian regime-linked hackers targeted and effectively shut down a small power plant in the UK for four days. The location of the power plant was not identified, and officials claimed there was no lasting damage to the power grid or supply of electricity. The attack is believed to be the most successful of its kind targeting power generation infrastructure in the UK.
Additional Information:
The UK cyber attack occurred at roughly the same time as the series of Iranian-linked cyber attacks on US water systems in late July. These attacks are discussed in detail in the Situation Report: “US Water Systems Hit by Suspected Iranian Cyber Attacks”. On August 26, 2026, TechCrunch reported that officials at the Cybersecurity and Infrastructure Security Agency (CISA) observed as many as 100 systems in the Water and Wastewater sector targeted by the attacks.
Both the UK and US attacks suggest Iran is becoming much more aggressive and sophisticated in its cyber operations and that such operations may increasingly be facilitated with AI tools to discover and exploit vulnerabilities. According to CISA, threat actors are using AI tools and open source software libraries to more rapidly scan systems and iterate attacks against operational technology (OT) running critical infrastructure using the following techniques:
Using Internet scanning services (e.g., Censys, ZoomEye) to identify Internet-exposed or insufficiently segmented Siemens S7 Series PLCs [T1596.005]
Rapidly iterating exploit code through AI-assisted development, lowering technical barriers to ICS attacks [T1587.004, T1588.007]
Taking advantage of insecure credentials to access exposed devices that have unconfigured (default) or minimally configured authentication [T1694]
Deploying AI-generated Python scripts that incorporate the
snap7.dlllibrary from public repositories [T0834] to gain read/write access to the PLC and mimic legitimate toolsMasquerading malicious scripts as legitimate monitoring tools to evade detection by security teams [T0849]
Conducting read/write operations on data blocks, potentially for reconnaissance, capability testing, or pre-positioning for effects operations [T0893, T0821]
This briefing was compiled by Dan White. Dan is an independent foreign policy analyst based in the New York Metro Area. Dan is a former member of The Wilson Center and The Kennan Institute. Dan holds masters degrees from the Johns Hopkins University School of Advanced International Studies (SAIS), the Naval Postgraduate School, and the University of Washington. Dan is a former officer in the United States Army and a veteran of the War in Afghanistan.
For more information, corrections, or comments, please contact djwhite155@gmail.com.



