/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Inside the US Cyber National Mission Force, which has been deployed to 20 countries since 2018 to battle state-backed Russian, Chinese, and North Korean hackers

BBC Gordon Corera

Context & Ripple Effects

The Cyber National Mission Force's 20-country footprint is the visible output of a doctrine Paul Nakasone has been building since he stood up the Russia Small Group task force at Cyber Command in 2018. The unit's remit has widened steadily since: from disrupting ISIS's media operations in what NPR called the largest offensive cyber operation in US military history, to election-defense surges around 2018 and 2020.

What changed by 2022 is geography and tempo. Nakasone confirmed US military hackers conducted offensive cyber operations in support of Ukraine after Russia's invasion, and this BBC reporting shows the mission force now rotating through allied networks worldwide rather than concentrating on single adversaries or single events.

First-order effects

  • Host governments in the 20 partner countries get US cyber teams operating on or alongside their networks ahead of and during elections, directly raising the cost for Russian, Chinese, and North Korean intrusion teams working those targets.
  • For Cyber Command itself, the deployment model turns what were episodic task forces like the Russia Small Group into a standing, exportable capability that can be pointed at any state-backed campaign.

Second-order effects

  • Allied intelligence agencies increasingly lean on US-provided attribution instead of building their own — the pattern Ars Technica documented when several US agencies jointly detailed a North Korean hacking campaign — which concentrates naming-and-shaming power in Washington.
  • Moscow, Beijing, and Pyongyang face a forward defense on third-country soil rather than at home, pushing their operators toward harder targets and forcing rival services to assume US presence in networks they previously treated as uncontested.

Third-order effects

  • If the rotation model holds, forward-deployed military cyber teams become a normalized instrument of alliance policy — the successor to the election-cycle surges NSA described before 2020, running continuously rather than per event.
  • The line between defensive assistance and offensive cyber operations keeps blurring: the same mission force that hunted ISIS's media infrastructure is now embedded with partners, setting precedent for how states justify military action in civilian networks.

The trend: US Cyber Command is institutionalizing 'defend forward' as permanent forward-deployed presence in allied networks, moving from event-driven task forces to continuous global operations against state-backed hackers.

Discussion

  • @aahronheim Anna Ahronheim on x
    “'They are hunters and they know the behaviour of their ‘prey’,” explains the operator who leads defensive work against Russia." https://www.bbc.com/...