Desk live·
ForensicPost
Nation-state/Utilities/File 25-0522

A Utility That Was Pre-Positioned in Briefed the People Who Would Have to Respond

At the Cyber Yankee exercise in May 2025, National Guard personnel were briefed by a utility that had been a victim of the Volt Typhoon intrusion set. The knowledge transfer is the interesting part.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUS utility
ActorVolt Typhoon
S. Rosler11 min readConfidence: medium2 sources reviewed

At the Cyber Yankee exercise in May 2025, National Guard personnel received a briefing from a utility that had been a victim of the intrusion set tracked as Volt Typhoon — an activity characterised by US authorities as pre-positioning within critical infrastructure rather than espionage or extortion.

Pre-Positioning Has No Incident To Respond To

Every response playbook in this corpus assumes an event: something encrypted, something stolen, something stopped. Detection follows damage, and the work is containment and restoration.

Pre-positioning inverts that. The intruder’s objective is to be present, capable and unnoticed, taking no action that would justify the risk of discovery. There is nothing to contain, no data to trace, and no adversary behaviour to alert on — because the adversary is deliberately behaving like an administrator.

Eviction under those conditions is the problem filed at 26-0728 and 26-0601: you cannot confirm you have removed something whose only signature is legitimate activity.

Why A Victim Briefing Matters More Than A Report

The corpus is full of published guidance on this intrusion set — advisories, indicator lists, hunting recommendations. What none of it conveys is what the experience is like: how the access looked to the people who found it, what convinced them, what they tried that did not work.

That knowledge normally stays inside the affected organisation, because sharing it means describing your own failures to peers and potential litigants. An exercise creates a setting where it can move without becoming a public admission, and this desk has found no other mechanism in the corpus that does.

And The Responders Are Part-Time

The National Guard is frequently the entity a US state can call on for cyber response capacity it does not otherwise fund. Its personnel are largely part-time, many working in the private sector — which produces genuine expertise and an availability model that would be tested by a simultaneous, multi-state event.

Graded medium: the exercise and the briefing are reported; the utility is not named, and the nature and duration of the intrusion are not established.

How we reported this

Compiled from public reporting of a defence exercise, listed below. The utility is not named in the material we reviewed. Characterisation of the intrusion set follows published US government assessments. Corrections: corrections@forensicpost.com.

Sources
  1. National Guardsmen receive brief from Volt Typhoon utility victim at cyber exerciseDefenseScoop
  2. China’s Typhoon cyber operations target US critical infrastructure sectorsIndustrial Cyber
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary