A US Department of Homeland Security memorandum dated 11 June 2025 recorded that attackers had accessed Army National Guard network diagrams, location maps and sensitive information about service members.
Three Categories, Three Different Lifespans
Service-member data is personal information, harmful in the familiar ways this database records elsewhere, and it ages: people leave, addresses change, the file decays.
Location maps are operational and time-bounded in a similar way. Facilities move, units relocate, and the map degrades as the estate changes.
Network diagrams do not behave like either. A diagram is the map of how an organisation is put together — which segments connect to which, where the trust boundaries sit, what depends on what. Networks are rebuilt slowly and in layers, and a diagram remains substantially accurate for years after it is taken.
It Is Reconnaissance You Cannot Redo
The expensive, noisy and detectable part of an intrusion is working out the internal shape of an estate: probing, enumerating, moving laterally and being observed doing it.
A stolen diagram removes that phase. It converts a future intrusion from exploration into navigation, and it does so silently — nothing about possessing a document generates a detection event. The theft is the last observable act.
That is the pre-positioning logic filed at 26-0715 and 26-0728: access and knowledge held for their own sake, valuable precisely because they are not used yet.
And The National Guard Is A Joining Point
The National Guard sits at a structural seam — a federal military organisation with units administered by states, connecting defence networks to state government systems, and frequently the entity called on to respond to a state-level cyber incident.
Documentation of how that seam is wired describes more than one organisation’s estate. It is worth being careful, though: the reporting we reviewed does not establish what the diagrams covered, and we are not asserting they extended to state networks.
What We Are Not Saying
Contemporary reporting connected this to a state-aligned intrusion set. This desk’s position on attribution, set out at 26-0217, is that a resemblance in tradecraft is not an identification, and we do not name an actor here.
Graded medium: the memo’s existence and its broad content are well reported; the scope of the access, the dates and the identity of the intruder are not established in the material we reviewed.
Compiled from public reporting of a government memorandum, listed below. We have not seen the memorandum. No actor is named. Corrections: corrections@forensicpost.com.