Homeland Security Brief - July 2026
This brief highlights significant threats to US homeland security posed by China, Russia, Iran, and North Korea observed in July 2026.
Summary:
Observed Threats - Current activity that poses direct risk to US homeland security
A series of cyber attacks, believed to be linked with Iran, targeted water systems in 12 states including Georgia, Minnesota, Michigan, New Jersey and South Dakota.
Jie Lijian, a prominent Chinese pro-democracy activist, was beaten into a coma by suspected agents of the Chinese Communist Party (CCP) in Flushing, New York.
A study released in the academic journal Proceedings on Privacy Enhancing Technologies Symposium found 7% of a sample of 220 military themed mobile apps used by significant numbers of US troops contained code from China’s Huawei and Russia’s Yandex to collect user metadata.
According to a new alert issued by the US Department of State and Federal Bureau of Investigation, North Korea is using a network of IT workers to fraudulently secure remote work positions with US and other Western companies to earn income to fund its missile and nuclear programs.
Horizon Threats - International activity that may pose future risk to US homeland security
The website for Canadian think tank Macdonald-Laurier Institute was reportedly cloned in a suspected Russian or Chinese cyber espionage operation.
Belgian authorities arrested a Canadian national of Chinese origin suspected of spying for China while serving as an intern at NATO’s Supreme Headquarters Allied Powers Europe in Mons.
OBSERVED THREATS
Current activity that poses direct risk to US homeland security
1. WATER SYSTEMS IN TWELVE STATES TARGETED IN SUSPECTED IRANIAN CYBER ATTACKS
A series of cyber intrusions bearing the hallmarks of Iranian cyber actors targeted water and wastewater systems across multiple US states at the end of July. These events were covered in detail in the Situation Report: “US Water Systems Hit by Suspected Iranian Cyber Attacks”. Follow the link below for the full report.
Additional Information:
By August 5, officials announced that the number of states affected by the attacks climbed to 12, with Georgia, Minnesota, Michigan, New Jersey and South Dakota publicly identified as targets.
2. PROMINENT CHINESE PRO-DEMOCRACY ACTIVIST BEATEN INTO A COMA IN NEW YORK CITY BY SUSPECTED CCP AGENTS
On July 15, 2026, prominent Chinese pro-democracy activist and head of the China Democracy Party International Alliance, Jie Lijian, was attacked and beaten into unconsciousness in Flushing, New York, by three unidentified men. The attack left Jie in a coma for two days with severe head injuries. US law enforcement continues investigating the incident, but circumstantial evidence suggests the attack was carried out at the behest of the Chinese government. The attack came just a week after Jie filed a lawsuit against the Chinese government and Chinese Consulate General in Los Angeles for previous acts of transnational repression.
Additional Information:
This is not the first time Jie Lijian has been attacked by assailants suspected of acting on behalf of the Chinese Communist Party (CCP) in the US. On November 17, 2023 a crowd of demonstrators organized by Jie Lijian in San Francisco to protest the arrival of Xi Jinping at the annual Asia-Pacific Economic Cooperation (APEC) summit held in the city was violently assaulted by pro-CCP counter protestors wielding clubs and pepper spray and allegedly a knife. According to a follow-on report of the incident by the then Chair of the Congressional Select Committee on China Representative Mike Gallagher (R-WI) and Ranking Member Raja Krishnamoorthi (D-IL), 15 demonstrators were injured in the melee and Jie Lijian reported being pursued by a group of five to six men.

Pro-CCP counter protestors assault pro-democracy protestors in San Francisco on November 17, 2023 outside APEC. Source: Voice of America. On July 8, Akio Yaita, a Japanese national and the director of a Taiwan-based think tank critical of the CCP called Indo-Pacific Strategy, was assaulted in Taipei. The attack was carried out by a 33-year old mainland-born Chinese man residing in Hong Kong with suspected ties to the city’s Wo Shing Wo organized crime group.1 Taiwan’s Liberty Times drew parallels between both attacks suggesting they may have been inspired by, or explicitly green lit, after the enactment of China’s "Ethnic Unity and Progress Promotion Law," on July 1.
As previously noted in OPFOR Journal’s Weekly Significant Activity Report - June 27, 2026, the new Chinese ethnic unity law is widely suspected to be a signal that Beijing intends to more forcefully target foreign critics of its domestic policies, particularly related to human rights.
China has used similar measures in the past to target overseas Hong Kong dissidents under the city’s National Security Law. On July 25, 2025, the National Security Department of the Hong Kong Police Force issued warrants for the arrest of 19 overseas democratic activists associated with the “Hong Kong Parliament” group, including 15 bounties worth HK$1 million (approximately $127,400). Nathan Law, among the most prominent of the activists targeted, was denied entry into Singapore in September 2025. Singapore defended its decision, saying Law’s presence was not in its national interest due to his outstanding arrest warrant.
Flushing, New York, where the attack on Jie Lijian took place, is also a suspected hotbed for Chinese transnational repression. The area is home to a large community of Falun Gong practitioners, a conservative spiritual movement banned in China in 1999. The group has encountered increasingly frequent acts of harassment and violence directed at its members and group events since as early as 2008, by pro-CCP agitators.
3. STUDY FINDS RUSSIAN AND CHINESE CODE IN LARGE NUMBER OF MILITARY THEMED MOBILE APPS MARKETED TO US TROOPS
A new article “No Privacy for Privates: How Military Communities Experience and Perceive the Privacy Risks of Military-Marketed Mobile Apps” released in July in the academic journal Proceedings on Privacy Enhancing Technologies Symposium found that 7% of a sample of 220 mobile apps marketed specifically to US service members and their families, and several linked to National Guard units, contained code directly linked to Chinese and Russian companies. The research conducted by a team from Purdue University, the US Military Academy at West Point, and Florida International University additionally found that at least 12 of the Military-Marketed Mobile Apps (MMMapps) reviewed, including several specifically tied to National Guard units, integrated with Huawei's HMS Core SDK software to collect information on a user’s location and other metadata. An additional two apps built by Russian companies integrated user data into Russia’s Yandex ad service. Of further concern, the report found that 40% of the apps collected more user data than their privacy labels disclosed.

The researchers provided the following policy recommendations to reduce the risk of personal or other sensitive information being transferred to US adversaries:
(1) a DoD-maintained approved app list for military-affiliated personnel; (2) DoD extension of privacy standards to MMMapps on personal devices; (3) app stores setting and enforcing rules for MMMapps; (4) a U.S. federal law restricting data brokers from buying or selling data about military-affiliated personnel; (5) a U.S. federal law requiring independent audits to verify the accuracy of privacy disclosures for MMMapps; (6) stricter bans on foreign code in MMMapps; and (7) in-phone warnings when foreign or unknown third-party code is present in an installed app.
Additional Information:
Data collection on US military personnel is especially concerning given multiple recent reports that Iran has used metadata collected by its cyber forces to direct drone and missile attacks in the Middle East.
4. NORTH KOREAN REMOTE IT WORKER SCAM TARGETING US AND WESTERN COMPANIES BEING USED TO FUND MISSILE AND NUCLEAR PROGRAMS
On July 31, the US Department of State and Federal Bureau of Investigation (FBI) issued a joint alert co-signed by 10 allied countries warning that North Korea is using a global network of remote IT workers to earn income for Pyongyang's nuclear weapons and ballistic missile programs.2 According to the alert, the IT workers use sophisticated fake documents as well as AI technology to conceal their identity and impersonate the nationals of other countries to gain remote work positions whose earnings are then remitted to the North Korean government. The workers are known to also use their access to their employers’ systems to steal data and commit other crimes.
The alert details the following tactics, techniques and procedures commonly used in the scheme to fool recruiters and remit money back to North Korea:
Many North Korean IT workers register for accounts on online platforms by falsifying their nationality or identity. Typical methods used include forging identification documents and impersonating another person. North Korean IT workers use images of identification documents provided by third parties—such as proxies residing in third countries—to register accounts, while the actual work is conducted by the North Korean IT workers themselves.
North Korean IT workers are increasingly likely to use third-party proxies to facilitate the creation of online accounts, participate in job interviews, and even establish in-person contact to create a false sense of trust and obtain work contracts.
North Korean IT workers often attempt to avoid being paid by direct deposit and may request payment via money transfer services or cryptocurrency. In many cases, North Korean IT workers provide employers a third party’s bank account as the recipient for payments, request that the third party transfer the funds to a designated foreign account, and provide a part of the payment to the third party as a fee for use of their bank account.
North Korean IT workers often possess high-level skills in IT-related work and are seeking work in wider areas—such as the development of web pages, mobile applications, software, and blockchain applications—through online platforms and other channels. In some cases, they also get work contracts directly from companies or individuals.
While many North Korean IT workers reside in North Korea, China, and Russia, as well as Southeast Asian and African countries, they may conceal the fact that they are working from abroad using third-party proxies, VPNs, remote desktop software, and similar tools.
North Korean IT workers are known to use third-party proxies as facilitators overseas, such as in the United States, to run “laptop farms” which receive company-provided laptop computers for North Korean IT workers to remotely access, obfuscating their true location.
In addition to obtaining IT-related work, North Korean IT workers may obtain foreign currency by engaging in fraudulent foreign exchange trading using automated trading systems they themselves developed.
Additional Information:
Multiple investigations launched by Mexican financial technology firm Bitso Quetzal have found that suspected North Korean remote workers associated with the Advanced Persistent Threat Actor Famous Chollima have attempted to apply for remote work positions within their firm using VPNs in order to appear to reside in Latin America along with AI-enabled face filters to alter their complexion to appear Hispanic.

HORIZON THREATS
International activity that may pose future risk to US homeland security
5. CANADIAN THINK TANK REPORTS ITS WEBSITE BEING CLONED IN A SUSPECTED RUSSIAN OR CHINESE CYBER ESPIONAGE OPERATION
On July 14, the Macdonald-Laurier Institute, a top Canadian conservative think tank, reported that their website had been cloned by a foreign adversary, likely Russia or China, in order to entice its fellows to provide sensitive information.
Early in June 2026, the Macdonald-Laurier Institute was informed by Canadian security and law enforcement officials that an organization linked to a hostile foreign intelligence service had cloned our website. And not just a few pages. They mirrored our very large site essentially in its entirety.
We had every reason to believe that this organization was using its mock MLI website and associated infrastructure to, among other things, recruit Canadians to supply sensitive and even classified information by offering research and other contracts that appeared to be from a reputable and prestigious Canadian think tank. We also believe this to be related to recent warnings issued by Five Eyes intelligence services about the alleged use of social media to recruit just such unsuspecting sources of intelligence in various countries around the world.
Additional Information:
Macdonald-Laurier Institute has been blacklisted by the Russian government as an “undesirable organization” and subjected to previous Russia-linked cyber attacks, suggesting the latest incident may also be the result of Russian actors.
It is also plausible that China is responsible for the website clone as it resembles similar cyber espionage operations recently directed at think tanks in the US. As noted in the Homeland Security Brief - June 2026, Chinese intelligence officers have targeted former employees of the US government and military by posing as recruiters for think tanks to solicit research on specialized or sensitive topics to better understand US policy. The Macdonald-Laurier Institute may be of particular interest to Chinese intelligence due to its “Dragon at the Door” project documenting CCP influence on Canadian elections and domestic politics.
6. BELGIAN POLICE ARREST NATO INTERN ON SUSPICION OF SPYING FOR CHINA
On July 24, Belgian authorities announced that they had arrested a Canadian citizen of Chinese origin on suspicion of spying while working as an intern at the NATO Supreme Headquarters Allied Powers Europe (SHAPE), in Mons. Canada’s Globe and Mail later identified the suspect as Biwei "Claire" Zhang and confirmed China as the country directing the espionage.
Zhang reportedly attended the University of Ottawa for a master’s degree in computer science prior to obtaining the NATO internship in the summer of 2025. Zhang’s self-reported employment history on LinkedIn included previous short periods of work at the Standards Council of Canada, Canadian Space Agency, European Space Agency, and World Trade Organization.
Additional Information:
While this case is unusual, it is not the first instance of an intelligence asset belonging to a member of the OPFOR being embedded into a Western institution through a university internship program.
In 2022, Russian military intelligence (GRU) officer Sergey Cherkasov was arrested in the Netherlands after attempting to begin an internship with the International Criminal Court (ICC). Cherkasov had secured the highly competitive internship, in part, through the recommendations of professors after graduating from the Johns Hopkins School of Advanced International Studies (SAIS) under the fabricated identity of a Brazilian national named “Viktor Muller Ferreira.” It is suspected that Cherkasov was attempting to get insights into the ongoing (at the time) ICC investigation into the downing of Malaysia Airlines flight MH-17 over Ukraine in 2014 by a Russian air defense missile.
This briefing was compiled by Dan White. Dan is an independent foreign policy analyst based in the New York Metro Area. Dan is a former member of The Wilson Center and The Kennan Institute. Dan holds masters degrees from the Johns Hopkins University School of Advanced International Studies (SAIS), the Naval Postgraduate School, and the University of Washington. Dan is a former officer in the United States Army and a veteran of the War in Afghanistan.
For more information, corrections, or comments, please contact dan@opforjournal.com.
The suspect, surname Liu, is originally from Guangdong province in mainland China.
Co-signers included Australia, Canada, France, Germany, Italy, Japan, the Netherlands, New Zealand, South Korea, and the United Kingdom




