Cyber Warfare Explained: Nation-State Hacking and Critical Infrastructure
Cyber warfare has become an important part of modern geopolitical competition, intelligence gathering and military conflict. Governments can use cyber capabilities to steal intelligence, disrupt communications, infiltrate critical infrastructure, sabotage systems or quietly establish access that could become valuable during a future crisis.
But one of the biggest misunderstandings surrounding cyber warfare is the assumption that every hack linked to a government is automatically an act of war.
It is not.
Cyber espionage, criminal activity, influence operations, infrastructure preparation and military cyber operations can overlap, but they are not legally or strategically identical.
The distinction matters because governments including China, Russia, Iran and North Korea have been publicly linked by U.S., UK and allied authorities to different forms of malicious cyber activity. Some operations focus on intelligence collection. Others seek money, political influence or strategic access. A smaller but particularly serious category can disrupt or potentially damage the systems that keep modern societies functioning.
The threat is no longer theoretical.
In June 2026, the UK’s National Cyber Security Centre said it had managed more than 200 cyber incidents affecting critical national infrastructure and its supporting ecosystem during the year to May 2026. The NCSC said approximately three-quarters were believed to be linked to hostile state actors.
This is why cyber warfare matters well beyond military networks.
Electricity, telecommunications, transportation, water systems, hospitals, financial infrastructure and internet services are now deeply connected to computers and communications networks.
An attack on software can therefore become an attack on real-world services.
For the wider framework around malware, identity security, phishing, networks, ransomware and cyber defense, start with The News Ink’s Cybersecurity Explained: Complete Guide.
Cyber Warfare at a Glance
| Activity | Main purpose | Typical target |
|---|---|---|
| Cyber espionage | Steal intelligence | Governments, defense, technology |
| Pre-positioning | Establish access for possible future use | Critical infrastructure |
| Cyber sabotage | Damage or disrupt systems | Industrial and government systems |
| Influence operations | Shape public opinion or political behavior | Citizens and institutions |
| Data theft | Obtain sensitive information | Telecoms, government, research |
| Disruption | Interrupt services | Websites, communications, infrastructure |
| Military cyber operations | Support broader conflict objectives | Command, logistics, communications |
| Financial cyber operations | Generate money for state objectives | Banks, cryptocurrency, businesses |
The categories can overlap.
One intrusion can begin as espionage and later provide an opportunity for disruption.
That uncertainty is part of what makes cyber warfare strategically dangerous.
What Is Cyber Warfare?
There is no universally accepted simple definition covering every hostile cyber operation between states.
In everyday use, cyber warfare generally refers to cyber operations conducted by or on behalf of governments as part of strategic competition or armed conflict, particularly when those operations are intended to disrupt, damage, manipulate or influence another country’s systems.
But the term should be used carefully.
The International Committee of the Red Cross distinguishes ordinary cybercrime, cyber espionage and state-sponsored cyber activity from cyber operations conducted in connection with armed conflict.
International humanitarian law applies to cyber operations conducted in the context of an armed conflict, according to the ICRC. That does not mean every hostile state-sponsored intrusion automatically reaches the threshold of warfare.
This creates several different levels of activity:
cybercrime → espionage → covert state operations → disruption or sabotage → cyber operations during armed conflict
The boundaries are not always clear.
That ambiguity can itself be useful to governments because cyber operations can create strategic pressure without immediately producing the same visible consequences as a missile strike.
Nation-State Hacking Is Different From Ordinary Cybercrime
A financially motivated criminal normally wants money.
A nation-state can have much broader goals.
Those goals may include:
- collecting political intelligence;
- stealing military technology;
- monitoring communications;
- obtaining intellectual property;
- disrupting logistics;
- preparing access to critical infrastructure;
- influencing public opinion;
- supporting military operations;
- or raising money for government programs.
The FBI says China, Russia, Iran and North Korea continue to conduct cyber intrusions against U.S. targets, while warning that some state actors are trying to establish long-term positions inside critical infrastructure and private-sector networks.
Nation-state attackers also tend to have advantages ordinary criminals may lack.
They can have:
- significant funding;
- intelligence support;
- long-term strategic objectives;
- highly trained operators;
- access to vulnerability research;
- and the patience to remain inside a network for months or years.
That is why some state-backed groups are described as advanced persistent threats, or APTs.
“Persistent” is just as important as “advanced.”
The attacker may value remaining hidden more than creating immediate damage.
Why Critical Infrastructure Is a Major Cyber Warfare Target
Critical infrastructure includes systems whose disruption could create serious consequences for national security, economic activity, health or public safety.
CISA recognizes 16 U.S. critical infrastructure sectors, including energy, communications, transportation, financial services, healthcare, water, information technology, government facilities and critical manufacturing.
These sectors are also highly interconnected.
Electricity powers communications.
Communications support emergency services.
Water utilities depend on electricity and digital control systems.
Financial markets depend on communications networks.
Transportation relies on energy and information technology.
CISA specifically notes that communications, energy, transportation and water are foundational to many other critical sectors.
That creates a strategic problem.
An attacker does not necessarily need to strike every system directly.
Disrupting one highly connected service can create secondary effects elsewhere.
Information Technology and Operational Technology Are Different
Understanding cyber warfare requires distinguishing IT from OT.
Information technology includes systems such as:
- email;
- databases;
- business applications;
- cloud environments;
- office computers;
- and enterprise networks.
Operational technology, or OT, interacts with physical processes.
Examples include systems that control:
- water pumps;
- industrial machinery;
- electricity distribution;
- manufacturing;
- pipelines;
- building systems;
- and transportation infrastructure.
This distinction matters because an IT compromise may expose information.
An OT compromise can potentially change what physical equipment does.
That makes operational technology especially sensitive in discussions of cyber warfare.
In July 2026, the FBI and EPA warned of malicious cyber actors targeting internet-facing programmable logic controllers used in U.S. water and wastewater systems. Utilities in at least seven states had reported incidents, and some activity degraded water operations.
Separately, the FBI reported Iranian-affiliated cyber actors targeting programmable logic controllers across U.S. critical infrastructure during 2026.
These incidents demonstrate how digital access can create physical-world consequences.
China and the Strategy of Pre-Positioning
One of the most closely watched nation-state cyber threats involves Chinese state-sponsored groups.
U.S. and allied authorities have publicly warned about activity associated with a group commonly tracked as Volt Typhoon.
The concern has not simply been traditional espionage.
CISA, the NSA, FBI and international partners reported that PRC-linked operators were compromising critical infrastructure while using legitimate administrative tools already present inside networks, a technique known as living off the land.
Living-off-the-land activity is difficult to detect because attackers may avoid installing obvious malware.
They instead abuse tools administrators legitimately use.
This can make malicious actions resemble ordinary network activity.
The strategic concern is pre-positioning.
An attacker may establish persistent access during peacetime so that access already exists if relations later deteriorate into a crisis.
That changes how cyber warfare should be understood.
The immediate goal of an intrusion may not be destruction.
The access itself may be the strategic asset.
Telecommunications Are a Strategic Target
Telecommunications infrastructure is enormously valuable to intelligence services.
It carries communications across governments, companies and individuals.
The FBI has highlighted PRC-linked activity publicly tracked as Salt Typhoon, which compromised multiple telecommunications companies and accessed customer call-record data as well as communications involving a limited number of targeted individuals.
In August 2025, CISA and international partners published broader guidance describing Chinese state-sponsored compromises of telecommunications and other networks around the world in support of a global espionage system.
These campaigns show why cyber warfare and cyber espionage often overlap.
Telecom infrastructure can provide intelligence during peacetime.
The same understanding of communications networks can become strategically valuable during a crisis.
Russia Uses Cyber Operations Alongside Wider Strategic Pressure
Russia has long been associated by Western governments with espionage, disruptive cyber activity and operations connected to geopolitical conflict.
CISA’s Russia threat material highlights state-sponsored campaigns against governments, logistics organizations, technology companies and critical infrastructure.
In July 2026, NATO issued a formal statement condemning what it called Russia’s persistent malicious cyber activities targeting Allied and partner countries, including attacks affecting government entities and critical national infrastructure.
Russia’s invasion of Ukraine has also demonstrated how cyber activity can operate alongside conventional warfare.
Cyber operations can support goals such as:
- intelligence collection;
- communications disruption;
- targeting;
- psychological operations;
- logistics interference;
- and information warfare.
The key lesson is that future conflicts are unlikely to remain separated into neat “physical” and “digital” categories.
Modern military, civilian and economic systems depend on the same interconnected digital infrastructure.
The News Ink has also examined this overlap in its coverage of the hidden cyber battlefield during the Iran conflict.
Iran Shows How Cyber Operations Can Reach Industrial Systems
Iran-linked cyber actors have been associated with espionage, credential attacks, disruptive operations and activity affecting critical infrastructure.
CISA and FBI advisories have documented Iranian actors using brute-force and credential-access techniques against critical infrastructure organizations. U.S. authorities have also linked Iran-based actors with ransomware-enabling activity.
The threat became particularly relevant again during 2026.
The FBI’s Iran threat page lists several 2026 cases involving Iranian-affiliated cyber activity, including attacks on programmable logic controllers and an August case involving 17 Iranians charged over a large cyber-theft campaign allegedly conducted on behalf of the Islamic Revolutionary Guard Corps and other Iranian entities.
The important lesson is not simply that one country has “hackers.”
Different state-linked groups can pursue different objectives at different times.
Cyber capabilities can support intelligence, economic pressure, retaliation or broader geopolitical conflict.
North Korea Combines Espionage With Revenue Generation
North Korean cyber operations demonstrate another model.
The country’s cyber activity has been associated with:
- espionage;
- cryptocurrency theft;
- financial attacks;
- military and nuclear intelligence collection;
- and fraudulent overseas IT-worker schemes.
A 2024 joint CISA advisory described a North Korean cyber group conducting global espionage aimed at advancing the regime’s military and nuclear programs.
In July 2026, the FBI again warned governments and businesses about North Korean IT workers using false identities to obtain remote employment and generate revenue that can support the country’s weapons programs.
The same 2026 FBI alert collection includes continuing activity by the North Korean Kimsuky group using spearphishing techniques against think tanks, NGOs, academia and foreign-policy experts.
This demonstrates why the boundary between cybercrime and national security can become blurred.
The money stolen through cyber activity can itself serve state objectives.
Cyber Espionage Is Not the Same as Cyber Sabotage
These two concepts are often confused.
Cyber Espionage
The objective is usually to remain hidden while collecting information.
Targets may include:
- diplomatic communications;
- defense research;
- intellectual property;
- military plans;
- technology;
- or political intelligence.
Cyber Sabotage
The objective is to damage, manipulate or disrupt.
Possible effects include:
- shutting down systems;
- deleting data;
- disrupting transportation;
- interfering with communications;
- or changing industrial processes.
Espionage rewards stealth.
Sabotage eventually reveals itself through impact.
But espionage access can potentially become sabotage access later.
That is why defenders must take quiet long-term intrusions seriously.
Cyber Warfare Can Target the Supply Chain
Governments and major companies rarely operate entirely on systems they built themselves.
They depend on:
- software vendors;
- cloud providers;
- telecommunications companies;
- managed service providers;
- hardware manufacturers;
- contractors;
- and open-source software.
An attacker that compromises one widely trusted supplier may gain access to many downstream organizations.
The SolarWinds intrusion demonstrated the scale that a supply-chain compromise can reach. The FBI has publicly attributed those intrusions to Russia’s Foreign Intelligence Service.
This creates a significant cyber warfare challenge.
National security increasingly depends on the cybersecurity of private companies that were never designed to function like military organizations.
Attribution Is One of the Hardest Problems
A missile has a physical launch point.
A cyberattack may move through:
- compromised computers;
- rented servers;
- botnets;
- VPNs;
- third-party infrastructure;
- stolen accounts;
- and infrastructure spread across multiple countries.
Attackers can deliberately use tools associated with other groups.
They can also attempt to erase evidence.
Attribution therefore requires more than finding one IP address.
Governments may combine:
- malware analysis;
- infrastructure patterns;
- intelligence collection;
- human intelligence;
- historical techniques;
- operational mistakes;
- and geopolitical context.
Even then, attribution can involve uncertainty.
This is strategically important because governments need confidence about responsibility before imposing sanctions, conducting counter-operations or considering military responses.
Cyber warfare therefore creates an unusual risk of escalation based on incomplete information.
Can a Cyberattack Trigger NATO Article 5?
Potentially, yes.
NATO says significant cyberattacks and other hybrid attacks may, in some circumstances, be considered an armed attack under Article 5.
But there is no automatic formula.
The decision is made case by case.
That ambiguity is deliberate.
A minor website disruption obviously does not automatically trigger collective military defense.
A cyber operation causing catastrophic physical consequences could present a very different situation.
NATO also does not say that a cyberattack must necessarily receive a cyber response.
The Alliance retains political, diplomatic, economic and military options.
That makes cyber deterrence broader than simply “hack the attacker back.”
International Law Still Applies in Cyberspace
Cyber warfare does not exist outside international law.
The ICRC’s position is that international humanitarian law applies to cyber operations conducted in connection with an armed conflict just as it applies to other methods of warfare.
That includes principles such as:
- distinction;
- proportionality;
- military necessity;
- and precautions to protect civilians.
Hospitals do not lose legal protection simply because the attack targets their computers instead of their buildings.
Water infrastructure does not become irrelevant because disruption is caused through software instead of explosives.
At the same time, difficult legal questions remain.
States and legal experts continue debating issues such as when a cyber operation reaches the threshold of a use of force and how rules governing civilian objects should apply to data.
The Tallinn Manual is influential in these debates, but it is an expert academic project rather than a binding international treaty. The NATO Cooperative Cyber Defence Centre of Excellence is currently working toward Tallinn Manual 3.0.
Why Critical Infrastructure Defense Is Different
Ordinary corporate cybersecurity focuses heavily on:
confidentiality + integrity + availability.
Critical infrastructure adds another requirement:
physical safety.
A compromised online store can be expensive.
A compromised industrial controller can potentially alter a physical process.
That means critical infrastructure security should include both IT and OT.
Important controls include:
| Defense | Why it matters |
|---|---|
| Network segmentation | Separates business IT from operational systems |
| MFA | Reduces stolen-account access |
| Asset inventory | Identifies what must be protected |
| Rapid patching | Closes known vulnerabilities |
| Offline recovery | Supports restoration after destructive attacks |
| OT monitoring | Detects abnormal industrial activity |
| Least privilege | Limits attacker capabilities |
| Secure remote access | Reduces internet-facing exposure |
| Incident exercises | Tests response under pressure |
| Redundancy | Keeps essential services operating |
For infrastructure operators, resilience matters as much as prevention.
Assume that some attacks will eventually succeed.
The important question becomes:
Can the essential service continue operating safely?
Nation-State Attackers Often Exploit Ordinary Weaknesses
Advanced attackers do not always require extraordinary techniques.
They may still exploit:
- unpatched software;
- default passwords;
- exposed routers;
- weak administrator accounts;
- poorly secured remote access;
- phishing;
- or misconfigured infrastructure.
CISA’s guidance on Chinese state-sponsored activity specifically shows how attackers can abuse legitimate administrative tools rather than introducing distinctive malware.
This is a critical defensive lesson.
An organization does not need classified intelligence to fix many of the weaknesses nation-state operators exploit.
The News Ink has separately covered concerns around foreign-made internet routers and national-security risks.
Strong basic cybersecurity remains relevant even against sophisticated adversaries.
How Governments Prepare for Cyber Warfare
Countries are investing in cyber defense through several approaches.
National Cybersecurity Agencies
Agencies such as CISA and the UK’s NCSC coordinate warnings, incident response and defensive guidance.
Military Cyber Commands
Many governments now treat cyberspace as an operational military domain.
Intelligence Sharing
Threat intelligence increasingly moves between governments, allies and private companies.
Joint Exercises
NATO and partner countries conduct large cyber-defense exercises.
The 2026 Locked Shields exercise involved nearly 4,000 participants and simulated attacks against infrastructure including 5G networks, satellite-management systems, power grids and electronic-voting systems.
Public-Private Cooperation
Much critical infrastructure is privately operated.
Governments therefore cannot defend national infrastructure without businesses, telecommunications companies, cloud providers and security vendors.
NATO expanded this cooperation in May 2026 through new cyber partnerships with technology and security companies.
NATO Is Also Strengthening Digital Resilience
NATO’s January 2026 Alliance Digital Strategy places cyber defense and digital resilience directly inside the Alliance’s modernization plans.
The strategy calls for:
- Zero Trust principles;
- stronger protection of mission-critical services;
- redundancy;
- resilient communications;
- and increased adoption of post-quantum cryptography.
This illustrates an important shift in cyber warfare thinking.
Defense does not mean guaranteeing that attackers never enter.
It means designing systems capable of continuing essential missions even while under attack.
AI Will Make Cyber Warfare Faster
Artificial intelligence is likely to influence nation-state operations on both sides.
Attackers can potentially use AI for:
- reconnaissance;
- vulnerability analysis;
- social engineering;
- code development;
- translation;
- intelligence analysis;
- and attack automation.
Defenders can use AI for:
- anomaly detection;
- malware analysis;
- incident triage;
- threat intelligence;
- and faster containment.
AI also affects information warfare.
Synthetic media can create fake speeches, fabricated events or manipulated video intended to influence public opinion.
The News Ink has already examined how AI deepfakes are being used in Russian disinformation efforts.
The future of cyber warfare may therefore combine traditional hacking, automated cyber operations and information manipulation much more closely.
What Organizations Should Do About Nation-State Risk
Most businesses should not assume they are the primary target of a foreign intelligence service.
But many companies sit inside supply chains that nation-state operators care about.
Organizations involved in:
- defense;
- telecommunications;
- energy;
- government;
- transportation;
- healthcare;
- technology;
- research;
- or critical manufacturing
should pay particular attention.
A practical defensive strategy includes:
- know every internet-facing system;
- patch known exploited vulnerabilities quickly;
- require phishing-resistant authentication for privileged access;
- segment networks;
- isolate operational technology;
- monitor administrator activity;
- secure backups;
- restrict vendor access;
- keep useful security logs;
- practice incident-response and recovery plans.
CISA’s cross-sector cybersecurity performance goals are specifically designed to give critical infrastructure organizations a prioritized set of high-impact security practices.
Frequently Asked Questions
What is cyber warfare?
Cyber warfare generally refers to cyber operations connected to strategic state competition or armed conflict, particularly operations intended to disrupt, damage, manipulate or influence another state’s systems. Not every state-sponsored hack legally qualifies as warfare.
What is nation-state hacking?
Nation-state hacking is cyber activity conducted by government agencies, military or intelligence organizations, or groups acting on behalf of governments to pursue national objectives.
Why do countries target critical infrastructure?
Critical infrastructure supports essential national functions. Disrupting energy, telecommunications, transportation or water can create economic, social and national-security consequences beyond the initially compromised system.
Which countries are major nation-state cyber actors?
U.S. authorities currently identify China, Russia, Iran and North Korea among the most significant foreign state cyber threats, although their objectives, capabilities and tactics differ.
What is cyber espionage?
Cyber espionage uses digital intrusion to steal intelligence without necessarily disrupting the target. Governments may seek diplomatic communications, military information, intellectual property or strategic technology.
Can cyberattacks cause physical damage?
Yes. Cyber operations affecting industrial control or operational-technology systems can potentially manipulate physical processes. Even attacks that do not physically damage equipment can disrupt water, electricity, healthcare or transportation.
Can a cyberattack start a war?
Potentially, but the legal and political threshold is complex. NATO says significant cyberattacks could be considered armed attacks under Article 5 on a case-by-case basis.
Does international law apply to cyber warfare?
Yes. The ICRC’s position is that international humanitarian law applies to cyber operations conducted during armed conflict, including protections for civilians and civilian infrastructure.
Conclusion
Cyber warfare is no longer a theoretical future battlefield.
Governments already use cyber capabilities for espionage, intelligence collection, strategic positioning, influence operations and, in some situations, disruptive activity.
But precision matters.
Not every nation-state intrusion is warfare.
Some operations steal intelligence.
Some generate revenue.
Some manipulate information.
Some establish quiet access to systems that could become strategically important during a future conflict.
And some cyber operations take place directly alongside conventional military activity.
Critical infrastructure sits at the center of this problem because modern societies depend on deeply connected electricity, communications, transportation, water, financial and digital systems.
A successful cyberattack against one of those systems can create consequences far beyond a stolen file.
Current evidence makes the scale of the threat difficult to ignore. The UK’s NCSC says roughly three-quarters of the critical-infrastructure incidents it managed in the year to May 2026 were linked to hostile states. The FBI continues to warn about state-linked threats from China, Russia, Iran and North Korea. NATO formally condemned persistent Russian cyber activity in July 2026 while strengthening its own cyber posture.
The best defense against cyber warfare is not one secret government technology.
Much of it begins with resilient fundamentals:
know what systems exist, patch vulnerabilities, secure identities, segment networks, protect operational technology, monitor unusual activity, control third-party access and prepare to continue essential services even during an attack.
Cyber warfare changes the geopolitical stakes of cybersecurity.
It does not change the importance of strong cybersecurity itself.
For the complete framework covering malware, ransomware, identity protection, network security, AI threats, cloud risk and cyber resilience, continue with The News Ink’s Cybersecurity Explained: Complete Guide.
Follow The News Ink
Stay connected with The News Ink for cybersecurity, artificial intelligence, technology, business and major global developments.
Follow The News Ink on X, Instagram and Threads.
Join The News Ink WhatsApp Channel and follow The News Ink on Medium for longer explainers and analysis.
