Desk live·
ForensicPost
Nation-state/Defence/File 25-0611

Network Diagrams, Location Maps, and the People Who Work There

A US Department of Homeland Security memo dated 11 June 2025 recorded that attackers accessed Army National Guard network diagrams, location maps and service-member data. The diagrams are the part that keeps working.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUS Army National Guard
ActorUnattributed
D. Kennedy11 min readConfidence: medium2 sources reviewed

A US Department of Homeland Security memorandum dated 11 June 2025 recorded that attackers had accessed Army National Guard network diagrams, location maps and sensitive information about service members.

Three Categories, Three Different Lifespans

Service-member data is personal information, harmful in the familiar ways this database records elsewhere, and it ages: people leave, addresses change, the file decays.

Location maps are operational and time-bounded in a similar way. Facilities move, units relocate, and the map degrades as the estate changes.

Network diagrams do not behave like either. A diagram is the map of how an organisation is put together — which segments connect to which, where the trust boundaries sit, what depends on what. Networks are rebuilt slowly and in layers, and a diagram remains substantially accurate for years after it is taken.

It Is Reconnaissance You Cannot Redo

The expensive, noisy and detectable part of an intrusion is working out the internal shape of an estate: probing, enumerating, moving laterally and being observed doing it.

A stolen diagram removes that phase. It converts a future intrusion from exploration into navigation, and it does so silently — nothing about possessing a document generates a detection event. The theft is the last observable act.

That is the pre-positioning logic filed at 26-0715 and 26-0728: access and knowledge held for their own sake, valuable precisely because they are not used yet.

And The National Guard Is A Joining Point

The National Guard sits at a structural seam — a federal military organisation with units administered by states, connecting defence networks to state government systems, and frequently the entity called on to respond to a state-level cyber incident.

Documentation of how that seam is wired describes more than one organisation’s estate. It is worth being careful, though: the reporting we reviewed does not establish what the diagrams covered, and we are not asserting they extended to state networks.

What We Are Not Saying

Contemporary reporting connected this to a state-aligned intrusion set. This desk’s position on attribution, set out at 26-0217, is that a resemblance in tradecraft is not an identification, and we do not name an actor here.

Graded medium: the memo’s existence and its broad content are well reported; the scope of the access, the dates and the identity of the intruder are not established in the material we reviewed.

How we reported this

Compiled from public reporting of a government memorandum, listed below. We have not seen the memorandum. No actor is named. Corrections: corrections@forensicpost.com.

Sources
  1. U.S. state and local government under ransomware: 2025–2026 trend analysisSOCRadar
  2. Why state and local governments keep losing to ransomwareUDT
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary