By Ken Robinson
“History does not announce the moment it changes. It just changes - and then punishes the people who kept operating like yesterday.”
“We are not in peacetime. We are in the part of war where uniforms are optional, truth is contested, and the battlefield is your phone, your ballot, and your bank account.”
I have spent my adult life on the unlit side of national security. As a covert action operator, intelligence officer, and later a practitioner of quiet Track II diplomacy, my job was never to theorize about adversaries. It was to encounter them where they actually operate: in ambiguity, in deniability, in deception, and in the space deliberately engineered to sit just below the threshold of open war.
Espionage is no longer a preparatory activity conducted in anticipation of war. It is the war. In the twenty-first century, intelligence services operate continuously, exploiting what many analysts describe as fifth-generation warfare: cyber operations, disinformation, lawfare, proxy violence, financial sabotage, and political subversion designed to weaken a rival without triggering a formal shooting war.
Today, four authoritarian states - Russia, China, Iran, and North Korea - function as a loose but increasingly coordinated intelligence cabal. They share tools, tradecraft, financial corridors, diplomatic cover, and lessons learned. They exploit Western openness, legal restraint, political fragmentation, and institutional seams. These are the Four Horsemen of the Espionage Apocalypse. They are not approaching. They are already here.
This National Security update adds eight very recent, open-source examples (two per horseman) drawn from credible government statements and mainstream reporting. Each example is a real-world instance of the same pattern: undeclared conflict conducted below the threshold of traditional war.
HORSEMAN ONE: RUSSIA - THE DISRUPTOR
“Russia does not need to defeat the West on the battlefield. It only needs to keep the West arguing about whether the battlefield exists.”
“The Russian model is cheap, deniable violence at scale: throwaway agents, plausible lies, and the corrosive certainty that democracies will investigate longer than they will act.”
Modern Russian espionage is not built for decisive victory. It is built for corrosion. Russian intelligence services prize chaos over control and paralysis over conquest. Sabotage, assassination, intimidation, and disinformation are not auxiliary tools. They are instruments of state power designed to fracture alliances, exhaust institutions, and convince democratic societies that truth itself is contested terrain.
Recent example 1 - state-directed sabotage by proxy: On January 16, 2026, Lithuanian authorities accused Russian military intelligence, the Main Directorate of the General Staff (commonly known as the GRU), of directing an attempted arson attack targeting a Lithuanian facility supplying equipment to Ukraine, using a multinational set of paid operatives. Reuters reporting on Lithuania’s charges (January 16, 2026)
Recent example 2 - hybrid sabotage warning against critical infrastructure: On February 6, 2026, Norway’s domestic security service publicly warned it expects stepped-up Russian espionage and potential sabotage activity in 2026, especially targeting Arctic security, allied exercises, and critical infrastructure, including through cyber means. Reuters reporting on Norway’s security assessment (February 6, 2026)
These are not isolated incidents. They are manifestations of a strategic design: deniable disruption that forces the defender into slow attribution cycles while the attacker keeps moving. Russia’s operating principle is simple: if the West cannot agree on what happened, it cannot agree on what to do next.
HORSEMAN TWO: CHINA - THE ENCIRCLER
“China does not rush the target. China surrounds the target - and then makes the target depend on the walls.”
“The most dangerous Chinese operation is the one that feels like business as usual until the day you realize the exits were closed years ago.”
China plays a fundamentally different game. If Russia is the arsonist, China is the architect.
To understand Chinese intelligence strategy, one must understand the ancient Chinese board game Go (Weiqi), played for more than two millennia and embedded in Chinese strategic culture. Go is not chess. Chess emphasizes decisive engagements and the capture of a central king. Go is a game of positioning, patience, and encirclement. Players place stones one by one on an open board to control space, restrict movement, isolate weak positions, and quietly remove escape routes. Individual stones are expendable if their sacrifice strengthens the overall position. Victory is rarely sudden. It becomes inevitable.
Chinese intelligence services operate this way: patient placement, persistent access, gradual encirclement, and leverage held for the moment that matters.
Recent example 1 - large-scale cyber espionage with deliberate ambiguity: On February 12, 2026, Reuters reported that a major cybersecurity firm chose not to publicly tie a global cyber espionage campaign directly to the People’s Republic of China, despite internal attribution work pointing to Chinese state alignment. The episode illustrates a core feature of fifth-generation conflict: coercion and intimidation shaping even the public language around attribution. Reuters reporting on the campaign and attribution pressures (February 12, 2026)
Recent example 2 - persistent access into telecommunications and critical infrastructure: On January 29, 2026, War on the Rocks summarized Senate findings and public reporting on Salt Typhoon, a Chinese state-sponsored cyber espionage campaign targeting United States telecommunications networks, emphasizing the durability of access and the difficulty of eviction once a nation-state actor is embedded. War on the Rocks analysis referencing Salt Typhoon and U.S. Senate scrutiny (January 29, 2026)
China’s method is not primarily about spectacle. It is about position. Persistent access, data harvesting, influence and pressure operations, and economic leverage become a single integrated system. That is Go at national scale: surround, isolate, normalize, and win without fighting.
HORSEMAN THREE: IRAN - THE PROXY MASTER
“Iran’s genius is not power. It is denial: violence that never quite has fingerprints, and pressure that never quite looks like war.”
“If Russia attacks your cohesion and China attacks your options, Iran attacks your attention - one proxy fire at a time, everywhere at once.”
Iranian intelligence and security services operate through layers: the Islamic Revolutionary Guard Corps, its expeditionary Quds Force, intelligence elements, proxy militias, cyber operators, and financial facilitators. The strategic goal is to impose cost across regions and domains while avoiding a threshold that would justify overwhelming retaliation.
Iran’s model is insurgent warfare scaled to the level of a state: plausible deniability, proxy action, and asymmetric pressure designed to grind down a stronger opponent.
Recent example 1 - transnational targeting and intimidation on U.S. soil: On January 28, 2026, the United States Department of Justice announced the sentencing of an individual involved in a murder-for-hire plot targeting Iranian American journalist and activist Masih Alinejad. The Department of Justice described the plot as orchestrated on behalf of the Iranian government - a clear instance of overseas coercion and political violence projected into the West. United States Department of Justice press release on the sentencing (January 28, 2026)
Recent example 2 - financial warfare through sanctioned digital infrastructure: On January 30, 2026, the United States Department of the Treasury sanctioned Iranian officials and, notably, announced the first designation of an Islamic Revolutionary Guard Corps-linked digital asset exchange, highlighting how sanctions evasion, digital finance, and regime repression now converge into a single operating system. United States Department of the Treasury press release (January 30, 2026)
Iran’s fifth-generation approach is not built on decisive battles. It is built on pressure. It aims to make daily life, governance, and politics more costly for its adversaries, while keeping every action contested enough to slow response.
HORSEMAN FOUR: NORTH KOREA - THE CRIMINAL STATE
“North Korea is what happens when an intelligence service becomes the national business model.”
“In Pyongyang, cybercrime is not a deviation from policy. It is policy - a revenue engine protected by missiles.”
North Korea is a mutation of the modern intelligence state. Its services - especially the Reconnaissance General Bureau - operate like a transnational criminal enterprise backed by nuclear weapons. Cyber theft, ransomware, cryptocurrency hacks, and fraud schemes are not peripheral. They are core state revenue streams that finance weapons programs and regime survival.
North Korea also demonstrates an uncomfortable truth of fifth-generation warfare: when the attacker is already sanctioned, naming and shaming is not enough. You must deny them money, access, and platforms.
Recent example 1 - industrial scale cryptocurrency theft funding the regime: On December 18, 2025, Chainalysis reported that North Korean hackers stole approximately 2.02 billion United States dollars in cryptocurrency in 2025, increasing the regime’s total haul and demonstrating larger thefts with fewer incidents - a sign of professionalization, insider access, and operational patience. Chainalysis analysis of 2025 theft attributed to North Korea (December 18, 2025)
Recent example 2 - record illicit crypto flows highlighting state-enabled criminal ecosystems: On January 28, 2026, TRM Labs published its 2026 Crypto Crime Report describing a sharp rise in illicit cryptocurrency flows in 2025, a trend strongly associated in open reporting with state-linked actors and sanctions-evasion ecosystems, including North Korean cyber operators. TRM Labs 2026 Crypto Crime Report (January 28, 2026)
North Korea’s method is blunt but effective: steal at scale, launder fast, deny everything, and rely on the world’s enforcement gaps. It is a criminal strategy protected by geopolitics.
A CABAL OPERATING IN PLAIN SIGHT
These four states coordinate more than the public typically sees. They share cyber tools, laundering routes, diplomatic cover, and operational lessons. Their operators exploit Western legal norms and democratic openness while treating those same constraints as vulnerabilities to be systematically abused.
While Western societies argue internally, these services exploit the noise. Polarization is not collateral damage. It is the battlefield.
This is not competition. This is conflict.
Just because World War Three is undeclared does not mean it is not underway. We are in the great game of spies again - but this time the board is global, digital, and instantaneous.
FROM WARNING TO ACTION: WHAT AN OSS-SCALE RETHINK REQUIRES
What is required now is an Office of Strategic Services-scale rethinking of intelligence and national security.
The Office of Strategic Services, created during World War Two, was not incremental reform. It was emergency adaptation. Intelligence collection, covert action, sabotage, psychological warfare, financial disruption, and support to military operations were fused under a single strategic logic: defeat the enemy before the enemy defeats you.
An Office of Strategic Services-scale rethink today requires the same mindset. Incremental bureaucratic reform will fail. Task forces will fail. Committees will fail. Our adversaries do not operate in stovepipes. They operate as systems. We must respond as one.
Integrated Intelligence Without Erasing the Law
The United States intelligence and security architecture is intentionally divided. That division protects liberty in peacetime. In sustained conflict, it creates seams adversaries exploit.
True integration does not mean collapsing agencies or ignoring legal boundaries. It means operational unity: real-time information sharing, unified attribution, rapid operational handoff from intelligence to law enforcement and financial enforcement, and a single national prioritization process for counterintelligence and foreign subversion.
The adversary operates at network speed. We still respond at committee speed.
Allies and the Intelligence Reality
The North Atlantic Treaty Organization is a military alliance, not an intelligence service. Intelligence sharing occurs through national contributions, bilateral agreements, and classified fusion mechanisms.
The most capable intelligence-sharing framework in the world is the Five Eyes alliance: the United States, the United Kingdom, Canada, Australia, and New Zealand. Even inside Five Eyes, sharing is constrained by national caveats, domestic law, source protection, and political risk.
Outside Five Eyes - including many partners inside the North Atlantic Treaty Organization and the European Union - intelligence sharing becomes slower and more fragmented. Adversaries exploit these seams ruthlessly.
Consequences: The Missing Weapon
The West’s greatest weakness is not intelligence collection. It is consequences.
Our adversaries assume - often correctly - that investigations will take years, sentences will be light, financial penalties will be reversible, and political pressure will dilute enforcement.
An Office of Strategic Services-scale response requires a consequences portfolio with teeth: long mandatory prison sentences for espionage and material support, aggressive asset seizure, permanent financial incapacitation, and swift disruption authorities that prevent networks from metastasizing faster than the state can respond.
Election Security Is National Defense
Elections are no longer purely civic processes. They are operational targets. Foreign intelligence services attack election infrastructure, political narratives, social trust, and legitimacy.
Treating this as a regulatory or speech issue is a category error. Election security must be treated as national defense.
THE CALL TO ACTION
“The most dangerous sentence in national security is: ‘That is not our lane.’ The enemy lives in the gaps between lanes.”
This is the moment for the United States, the North Atlantic Treaty Organization, the European Union, and the Five Eyes nations to act with unified seriousness.
Fifth-generation warfare is designed to make free societies doubt themselves: to slow decisions, dilute accountability, and normalize intrusion until it feels inevitable. The answer is not panic. The answer is disciplined integration, hard consequences, and a modernized legal and operational tool kit that matches the adversary’s speed.
We have done this before. In World War Two, the Office of Strategic Services was built because the nation understood that survival required an emergency fusion of intelligence, action, finance, and influence. Today, we do not need nostalgia. We need the same clarity: the willingness to call this what it is, and the courage to respond at scale.
Sovereignty without enforcement is fiction. Deterrence without consequence is theater. If we intend to defend the republic and the democratic alliance system that has underwritten global stability for eighty years, we must stop treating this as episodic scandal and start treating it as sustained conflict.
The spies are already among us. They always have been. The only question left is whether we will keep documenting the erosion - or finally impose the costs that make erosion impossible.
If you found this reporting credible, timely, accurate, and relevant, please restack, and send to a friend, share on your Facebook, Instagram, Linkedin, and other social networking platforms. National Security impacts all of us!


https://open.substack.com/pub/olgalautman/p/wagners-role-in-russias-expanding?r=2fbxd&utm_medium=ios