At the Cyber Yankee exercise in May 2025, National Guard personnel received a briefing from a utility that had been a victim of the intrusion set tracked as Volt Typhoon — an activity characterised by US authorities as pre-positioning within critical infrastructure rather than espionage or extortion.
Pre-Positioning Has No Incident To Respond To
Every response playbook in this corpus assumes an event: something encrypted, something stolen, something stopped. Detection follows damage, and the work is containment and restoration.
Pre-positioning inverts that. The intruder’s objective is to be present, capable and unnoticed, taking no action that would justify the risk of discovery. There is nothing to contain, no data to trace, and no adversary behaviour to alert on — because the adversary is deliberately behaving like an administrator.
Eviction under those conditions is the problem filed at 26-0728 and 26-0601: you cannot confirm you have removed something whose only signature is legitimate activity.
Why A Victim Briefing Matters More Than A Report
The corpus is full of published guidance on this intrusion set — advisories, indicator lists, hunting recommendations. What none of it conveys is what the experience is like: how the access looked to the people who found it, what convinced them, what they tried that did not work.
That knowledge normally stays inside the affected organisation, because sharing it means describing your own failures to peers and potential litigants. An exercise creates a setting where it can move without becoming a public admission, and this desk has found no other mechanism in the corpus that does.
And The Responders Are Part-Time
The National Guard is frequently the entity a US state can call on for cyber response capacity it does not otherwise fund. Its personnel are largely part-time, many working in the private sector — which produces genuine expertise and an availability model that would be tested by a simultaneous, multi-state event.
Graded medium: the exercise and the briefing are reported; the utility is not named, and the nature and duration of the intrusion are not established.
Compiled from public reporting of a defence exercise, listed below. The utility is not named in the material we reviewed. Characterisation of the intrusion set follows published US government assessments. Corrections: corrections@forensicpost.com.