
This brief highlights significant threats to US homeland security posed by China, Russia, Iran, and North Korea observed in September 2026.
Executive Summary:
Observed Threats - Current activity that poses direct risk to US homeland security
The US Department of Justice charged five men associated with the Russian intelligence services with plotting to murder prominent Russian dissidents in the US.
The US Department of Justice announced the arrest of the CEO and CTO of US government contractor Oxygen Forensics over a multi-year plot to conceal the company’s Russian ownership.
A new report indicated that Chinese shipping giant COSCO has employed sophisticated signals intelligence collection systems hidden aboard its ships to intercept US military communications when transiting US waters.
The US Coast Guard and FBI conducted investigations into suspected Iranian cyberattacks on Texas-bound tanker ships.
Horizon Threats - International activity that may pose future risk to US homeland security
A man wearing Chinese paraphernalia and invoking Chinese ethnic unity laws threatened Falun Gong protesters outside the Chinese consulate in Toronto.
OBSERVED THREATS
Current activity that poses direct risk to US homeland security
1. RUSSIAN INTELLIGENCE ASSETS CHARGED WITH PLOT TO MURDER RUSSIAN DISSIDENTS IN US
On September 15, 2026, US Attorney General Todd Blanche announced criminal charges against five members of a Russian intelligence network with a plot to assassinate a high-profile Russian dissident in the US.
According to the indictment issued by the Southern District of New York, the network included Yuri Khrameev, a retired Russian intelligence officer; Kirill Khrameev, an active Russian intelligence officer and son of Yuri Khrameev; Oemis Romagoza Durruthy, a Cuban national living in Russia who serves as a recruiter for the Russian intelligence services; Yaidel Delgado Suarez, a Cuban national affiliated with the Russian intelligence services; and Angel Eduardo Castro, a Venezuelan national affiliated with the Russian intelligence services.
Most recently, this summer, the RIS [Russian intelligence service] Network recruited an individual based in the United States (U.S. Resident-1) to surveil and murder a prominent Russian dissident they believed to be residing in the United States. Among other things, Suarez sent U.S. Resident-1 two locations associated with Victim-1 to surveil; provided U.S. Resident-1 with explicit instructions on how to conduct surveillance; and promised U.S. Resident-1 between $1,000 and $1,500 dollars to carry out the pre-operational surveillance. In turn, U.S. Resident-1 conducted the requested surveillance and passed back to Suarez multiple photographs and videos of locations associated with Victim-1. Suarez and Castro further offered U.S. Resident-1 $40,000 to “eliminate” or “disappear” Victim-1 and, when U.S. Resident-1told them that he did not want to carry out the murder by his own hand, asked U.S. Resident-1 if he knew “someone [who] can do the work.” Suarez also told U.S. Resident-1 that he had “people in Mexico” who could otherwise carry out the murder, but they were delayed in doing so. In addition, Suarez attempted to recruit multiple other individuals within the United States to conduct pre-operational surveillance and murder Victim-1 and other potential targets within the United States and offered them substantial sums of money to carry out the targeting of the U.S. based victims.

Additional Information:
A September 30, 2026 report by Spanish news outlet El Mundo identified two targets of the plot: Ilya Ponomarev, an exiled former member of the Russian State Duma, and Garry Kasparov, the renowned Russian chess champion and long-time critic of the Putin regime. Both men are members of the Free Russia Forum.
This is the first publicly attributed Russian assassination plot on US soil in decades. However, Russian intelligence services have carried out numerous successful and attempted assassinations in Europe in recent years. The most prominent of these are the poisoning of former Russian military officer Sergei Skripal and his daughter Yulia with a deadly Novichok nerve agent in Salisbury, England on March 4, 2018. The number of assassination plots in Europe appears to have grown dramatically in the wake of the 2022 invasion of Ukraine. Examples include the February 2024 killing of Maksim Kuzminov, a Russian helicopter pilot who defected to Ukraine along with his aircraft; a foiled 2025 plot in France to kill Vladimir Osechkin, a Russian human rights activist; a foiled 2026 plot in Lithuania targeting Valdas Bartkevičius, a prominent pro-Ukrainian activist and Lithuanian citizen, and exiled Russian minority rights activist Ruslan Gabbasov; the June 2026 killing of Robert Kuzovkov (aka “Semyon Skrepetsky”), an exiled Russian satirist in Poland; and a foiled 2026 plot to kill a US-Ukrainian dual citizen in Poland.
2. US GOVERNMENT SOFTWARE PROVIDER CHARGED WITH ATTEMPT TO CONCEAL RUSSIAN OWNERSHIP
On September 23, 2026, the US Department of Justice announced the arrest of Lee Reiber, 55, a US citizen and CEO of the Virginia-based government contractor Oxygen Forensics, along with Russian national and company CTO Oleg Davydov, 52, on charges of conspiracy to commit wire fraud. Both men are charged with attempting to conceal the ownership of Oxygen Forensics by Davydov and four other Russian nationals through a Cyprus-based shell company. The company also employed software developers in Russia to produce its products.
Oxygen Forensics has served as a software provider for US government agencies including the Department of Defense and Department of Homeland Security.
Davydov and the four other Russian owners of Oxygen Forensics also owned a second company, MKO Systems LLC, which provided similar software offerings in Russia, including to the Russian security services.
Additional Information:
The homeland security concerns of this case echo a June 2024 decision by the US Department of Commerce to prohibit the sale and use of products by Russian-owned cybersecurity firm Kaspersky Lab. The crux of both cases is that exposure to technology companies owned by citizens of foreign adversaries poses unique risks, even if their products and services are legitimate, because such companies simply cannot be counted on to protect American data from their own governments. The Department of Commerce explicitly cited this rationale in its decision to ban Kaspersky:
As an entity subject to Russian jurisdiction, it [Kaspersky] must comply with any Russian government request for assistance or information. Russian laws compel companies subject to Russian jurisdiction to cooperate with Russian intelligence and law enforcement efforts, to include requests from the Russian Federal Security Service (“FSB”). In its responses to the Department’s subpoenas and its Written Submission, Kaspersky did not dispute that it is obligated to comply with requests from the FSB. Accordingly, Russia, through its jurisdiction, direction, or control over Kaspersky, could exploit access to sensitive information present on electronic devices that use Kaspersky’s cybersecurity and anti-virus software in the United States or install or inject new malware through manipulation of Kaspersky’s signature library and source code updates.
3. CHINESE SHIPPING GIANT COSCO HELPING BEIJING SPY ON THE US MILITARY
On September 1, 2026, Reuters reported disclosures from senior US officials that Chinese state-owned shipping company COSCO has employed sophisticated signals intelligence equipment concealed on its ships to intercept military communications when transiting near US and allied military bases.
Additional Information:
Concerns about China’s use of its vast civilian shipping fleet for espionage have persisted for years. An April 2025 report by the US Naval War College’s China Maritime Studies Institute (CMSI) detailed indications of cooperation between maritime intelligence specialists and civilian fishing and shipping companies.
Given the evidence presented above, it is more likely than not that PRC vessels operating overseas have already begun embarking information personnel to serve intelligence collection and reporting functions. In the case of China’s fishing fleet, serving this foreign intelligence collection function could be as simple as adding a new duty to the “information personnel” that already embark aboard some distant-water fishing vessels. Aside from their primary responsibilities of tallying and reporting production numbers, serving as experts on international and national fisheries regulations that affect their work, and handling interactions with foreign officials while at sea and in port, they might also be tasked with collecting and reporting military and political intelligence while operating overseas. Similar processes may already be in place in the commercial shipping industry. For instance, Guangxi province’s Beihai city has built up its ranks of maritime intelligence specialists by recruiting from among marine shipping personnel (海上交 通运输从业人员).
The 2017 National Intelligence Law of the People’s Republic of China requires that Chinese companies and citizens support state intelligence work when called upon. Specifically, Article 7 of the law stipulates “All organizations and citizens shall support, assist, and cooperate with national intelligence efforts in accordance with law, and shall protect national intelligence work secrets they are aware of.” Article 14 similarly mandates compliance: “National intelligence work institutions lawfully carrying out intelligence efforts may request that relevant organs, organizations, and citizens provide necessary support, assistance, and cooperation.”
4. US COAST GUARD AND FBI BOARDED TANKERS TARGETED BY SUSPECTED IRANIAN CYBERATTACKS
On September 16, 2026, CBS News reported that the US Coast Guard and Federal Bureau of Investigation (FBI) conducted joint operations in August to board two Texas-bound tanker ships that were compromised by suspected Iranian cyberattacks. One of the tankers, identified as the Liberian-flagged VL Prosperity, lost control of its communications, propulsion and other operational systems for over 30 hours while transiting the Atlantic toward Galveston, Texas.
Commander of US Coast Guard Cyber Command, Rear Admiral Amy Grable, announced that the inspection of the VL Prosperity turned up evidence of malicious cyber activity in the ship’s operational systems.
Iran’s government-sponsored Mehr News Agency reported the VL Prosperity hack on August 20, 2026. The detailed reporting of the incident, through unnamed third-party sources well before it was widely known, has led to widespread speculation of direct Iranian involvement.

Additional Information:
According to preliminary findings by the FBI and Coast Guard reported by Bloomberg on October 2, 2026, hackers were briefly able to access the propulsion systems of the VL Prosperity as it approached the coast of Texas. The announcement did not officially attribute the cyberattack to Iran, but the description of systems compromised on the ship matches those reported by Mehr News on August 20. The timing of the attack suggests the hackers may have tried to cause the ship to lose control and create a major accident near the US coast.
Commercial shipping has increasingly become a target of state-affiliated cyber actors. Another notable recent incident of this trend came in December 2025, when French authorities announced an investigation into malware installed on board the GNV Fantastic, a Mediterranean ferry operated by Italian shipping company Grandi Navi Veloci (GNV). The incident sparked immediate suspicions of Russian involvement, which were renewed in May 2026 after reporting by Italian news outlet Il Foglio indicated that the malware discovered was designed to divert data on GNV operations to a server controlled by pro-Russian hackers.
HORIZON THREATS
International activity that may pose future risk to US homeland security
5. ANTI-CCP PROTESTERS THREATENED OUTSIDE TORONTO CONSULATE BY MAN INVOKING CHINESE LAW
On September 24, 2026, Canadian independent journalist Sam Cooper reported that the Toronto Police were investigating a September 22 incident in which a man wearing People’s Republic of China paraphernalia accosted attendees of a Falun Gong protest near the city’s Chinese consulate. The aggressor in the incident invoked China’s newly enacted “Ethnic Unity and Progress Promotion Law” to threaten protesters with violence.
Additional Information:
The incident fits a broader pattern of Chinese transnational repression directed at the Falun Gong group and members of the Chinese diaspora more broadly, trends discussed in detail in Homeland Security Brief - July 2026. More concerning, the threats in this incident, which referenced the new Chinese ethnic unity law, serve as an early warning of how Chinese actors may attempt to use the law to pursue more aggressive actions against foreign critics of the Chinese Communist Party. This recourse to lawfare was made explicit by Hu Weilie, China’s Vice Justice Minister, who announced on June 23, 2026 that Beijing would use the law to prosecute foreign individuals and groups who engage in “illegal acts” that “undermine ethnic unity and progress or incite ethnic separatism” in China.
This briefing was compiled by Dan White. Dan is an independent foreign policy analyst based in the New York Metro Area. Dan is a former member of The Wilson Center and The Kennan Institute. Dan holds masters degrees from the Johns Hopkins University School of Advanced International Studies (SAIS), the Naval Postgraduate School, and the University of Washington. Dan is a former officer in the United States Army and a veteran of the War in Afghanistan.
For more information, corrections, or comments, please contact djwhite155@gmail.com.




