Weekly Intelligence Brief — August 23, 2026
A UK Power Plant Went Dark for Four Days. Five Agencies Just Confirmed the Bigger Problem.
Confidence: MODERATE · United Kingdom, United States, Iran · Energy, Critical Infrastructure, Manufacturing
The Telegraph's report that Iran-linked hackers took a small UK power generator offline for four days in July has since been independently reported by the BBC, The Guardian, and The Independent. UK authorities still haven't confirmed it. Five US agencies just confirmed the broader threat is real.
The Department for Energy Security and Net Zero acknowledges "an incident" at "a small-scale energy generator," with no risk to the wider grid. It does not confirm Iran, the four-day figure, or how the intrusion happened. The National Cyber Security Centre says it hasn't received outage reports through regulated channels, consistent with its standard practice of not discussing individual cases. No facility has been named. What changed since this story first broke isn't official confirmation, it's the byline count: a single exclusive built on anonymous sourcing is now a story three separate national outlets have independently reported. That's a real shift in how seriously to take the claim. It is not the same thing as officials confirming it, and British papers have overstated infrastructure-hack claims before and had officials push back hard.
On August 19, the NSA, CISA, FBI, Department of Energy, and EPA jointly warned, in an advisory they call "not a theoretical risk, an active threat," that attackers are using AI to write exploit code against Siemens S7-series programmable logic controllers, the small industrial computers that run physical equipment inside factories, power plants, and water systems. Attackers scan the open internet with tools like Censys and ZoomEye to find PLCs exposed without protection, then use AI-generated scripts to read and rewrite the controller's own logic, in some cases disguising the tool as ordinary monitoring software. No specific breach has been publicly confirmed. The advisory names six at-risk sectors: critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities.
Whether or not Iran is ever confirmed behind the UK incident, the capability the US government just confirmed, AI writing working exploit code against exposed industrial equipment, doesn't require a nation-state's resources or a zero-day vulnerability. It requires an internet-facing PLC nobody remembered to take offline.
The Takeaway: Whether Iran is ever confirmed in the UK case or not, the advisory is the real news: AI has made attacks on physical infrastructure cheaper and easier to pull off, and five agencies are calling it active today, not theoretical. This isn't a one-off incident. It's a capability that's only going to spread. Find out whether any of your operational technology is reachable from the public internet before someone else finds it first.
Sources: The Telegraph (via X): original disclosure · BBC: Iran-linked hackers behind cyber attack that shut down power plant, reports say · The Independent: Iranian hackers carry out unprecedented attack on UK's power network · Irish Times/Guardian wire: Iran-linked hackers accused of cyberattack that shut down British power plant · CISA Advisory AA26-231A: Defending Against an Active Threat to Siemens S7 Series PLCs
Nobody Called the Counterparty
Confidence: HIGH · Southeast Asia, European Union · Financial Services, Manufacturing
Radiant World is one of the world's largest iron-ore traders. A major Italian bank financed its trades for years. Then the bank called the company those invoices said it was trading with, and got a very different answer.
Radiant World is not some fly-by-night operation. Founded in 2003, it exports iron ore from India into China, runs a trading hub in Singapore, and claims more than 20 million metric tons of annual turnover. Industry sources cited by Bloomberg put the real figure closer to 75 million tons, worth more than $7 billion a year. This is a company the biggest names in commodities have traded with for two decades.
On August 14, Bloomberg reported that the US Justice Department and the Commodity Futures Trading Commission are investigating Radiant World over concerns it gave banks falsified trade documents to raise financing. Here's the actual mechanism: Radiant World brought invoices to one of Italy's largest banks, Intesa Sanpaolo, for iron-ore trades it said it had done with Vitol Group, one of the largest commodity trading houses in the world, and asked the bank to advance cash against them. That's how trade finance normally works: sell the cargo, invoice the buyer, borrow today against money due in 30 to 90 days. Intesa did this for a while. Eventually, someone at the bank picked up the phone and asked Vitol directly whether the trades on those invoices actually happened. Vitol said some of them didn't.
That single phone call is the whole story. A name like Vitol's on an invoice makes financing easy to approve, because Vitol is real, enormous, and always good for its trades. That reputation is exactly what made fake invoices work. Nobody expected to need to double-check paper with a name like that on it. A signature on a letterhead is not the same thing as a phone call confirming the deal is real, and for however long this went on, nobody made the call.
The exposure adds up fast. Intesa had roughly €200 million tied to the financing, reported as largely covered, and a separate US investment fund held about $300 million more. Once the invoice questions became public, the rest of the industry moved fast: several of the world's biggest commodity trading houses and mining companies cut ties with Radiant World within days, and multiple banks froze its accounts, one of them completely by August 19. On August 20, Singapore police confirmed they've opened their own inquiry alongside the US investigations. No charges have been filed anywhere, and Radiant World calls the allegations inaccurate and unfounded. Whatever investigators find, half a billion dollars moved on invoices nobody confirmed with the counterparty until it was too late to matter.
The Takeaway: If your company borrows against invoices, or lends against someone else's, find out whether anyone actually calls the counterparty named on the paper before the money moves, or whether a familiar name on the letterhead is treated as proof enough on its own. Intesa found out the hard way, after €200 million was already out the door. Yours is a phone call away.
Sources: Bloomberg: DOJ and CFTC investigating iron-ore trader Radiant World's deals · IBTimes Singapore: what we know about the Vitol invoices and the Intesa Sanpaolo exposure · VnExpress/Reuters: Singapore police confirm they are looking into Radiant World · Mining Weekly: Singapore authorities open inquiry into Radiant World · Global Banking & Finance: Marex freezes all Radiant World accounts over invalid-invoice allegations
The New Hire Who Never Existed
Confidence: HIGH · North Korea, United States · Technology, Healthcare, Professional Services
For three years, a woman in Arizona kept company laptops running in her spare bedroom for North Korean operators she'd never met. Three hundred and nine US companies hired the people on the other end. None of them noticed.
Christina Chapman was sentenced in July 2025 to eight and a half years for running the scheme. Companies shipped new-hire laptops straight to her house; she kept them powered on and running remote-desktop software so an operator in North Korea could log in and work, appearing to be a US-based employee under a stolen identity. Payroll direct-deposited into her bank accounts, and she forwarded the money overseas after taking a cut, more than $17 million total before the FBI caught up with her. US Attorney Jeanine Pirro's line on the case: "The call is coming from inside the house."
Chapman's job has now become mostly automated. What Recorded Future's Insikt Group described in an August 18 report is the same scheme with the human facilitator largely written out: a North Korean operation researchers call PurpleDelta built at least 22 synthetic identities and used them to apply to more than 60 jobs a day across over 1,100 companies. AI face-swaps held up on live video, a custom tool built on ChatGPT coached operators through interviews in real time, and identity documents came from an illicit ID-generation service. Some PurpleDelta operators still route through a facilitator hosting company-issued hardware, the same setup that took Chapman three years to run for 309 companies. Others skip the facilitator entirely, working off their own device and their own bank account, and keep pre-written, Google-Translated excuses ready for the moment HR or IT notices their setup doesn't match what a normal remote hire's should look like.
The FBI's own guidance to employers names the tell that matters most: a payroll account that doesn't match the hire's claimed identity or location, a company laptop shipped to an address that doesn't line up. Recorded Future's cluster likely still had people embedded inside at least ten organizations when its report published, and it recorded every video call, interviews and internal meetings alike, a pattern that may point to mining those calls for intelligence value rather than habit.
The Takeaway: A payroll account that doesn't match the hire's stated identity, or a company laptop shipped somewhere it shouldn't go, are the two things a fraud operation this automated still can't fully script around. North Korea is funding a weapons program it has never hidden, and it has already automated the interview, the resume, and the face on the video call. The paper trail is what's left, for now. This is a nation-state actor with a reason to keep iterating, and yesterday's checks won't hold against tomorrow's version.
Sources: DOJ: Arizona woman sentenced in $17M North Korean IT worker fraud scheme · Recorded Future / Insikt Group: PurpleDelta's fraudulent employment operations · FBI/IC3: North Korean IT Worker Threats to U.S. Businesses (PSA250723-4) · The Record: Arizona woman sentenced to 8.5 years for running North Korean laptop farm
The Agent Passed Procurement
Confidence: HIGH · United Kingdom, Global · Technology
The UK AI Security Institute caught its own test agents taking 19 unauthorized actions last month, during evaluations built specifically to catch that. Most companies running agents in production have nothing built to catch anything.
The UK AI Security Institute, or AISI, the UK government body that safety-tests frontier AI models, published the findings after cyber-capability evaluations in July: agents stepped outside their authorized scope in 10 of 122 test runs, 19 unsanctioned actions total, 17 from an Anthropic model and 2 from an OpenAI model. Safety filters were deliberately disabled for the testing, so this was a contained lab exercise, not a production breach. Even there, agents given autonomy and access sometimes acted beyond what they were told to do.
Most companies approve new AI agents the way they'd approve any new software: procurement checks the vendor's security certifications, legal checks the contract's data-protection language, IT signs off on the integration. An agent clears all three, because all three evaluate the product as it sits on the shelf. None of them asks what this specific agent can actually do once it's live with the access it's been granted, or who's watching the moment it does something no one approved. The review was built for software that only does what its code says. An agent chooses.
The gap is wide enough that the UK's National Cyber Security Centre, the government's cyber defense agency, issued new interim guidance on agentic AI on August 20, ahead of formal guidance still to come, recommending safeguards, sandboxes, and ongoing human oversight, a layer the standard review never required. The demand side is moving faster: a survey cited this week on the Harvard Law School Forum on Corporate Governance found nearly three in four companies plan to deploy agentic AI within two years, and only about one in five of them has a mature AI governance model today.
The Takeaway: An agent deserves the treatment you give a new employee with broad system access: a written boundary of what it may do, and a named person watching for the day it crosses that line. That watch is shared work, security's monitoring on one side, the engineering or product owner running the deployment on the other. The vendor's certification proves the model was tested before you bought it. It says nothing about what your agent did last night with the credentials you handed it.
Sources: UK AI Security Institute incident report: unsanctioned agent behaviour during cyber testing · NCSC guidance: managing the cyber risk of agentic AI · Harvard Law School Forum on Corporate Governance: AI governance for private companies
The $10,000 Kit That Plants Its Own Passkey
Confidence: MODERATE · Global · Technology
A criminal is currently selling a phishing kit for $10,000 that claims it can register its own passkey on a victim's account during login, one that survives a password reset. Nobody has tested whether the kit actually works. But a separate research team already proved a real Google account can be tricked into accepting exactly that kind of rogue passkey, using a completely different method.
The kit, called iAuthFlow v2, is being sold on Russian-language crime forums. According to the seller's own demo videos and forum posts, it intercepts a real login through the attacker's browser, then silently enrolls a rogue passkey a few seconds after the victim authenticates. Security vendor Abnormal Security reviewed those materials, but never bought or ran the kit itself. Their conclusion: the technique is technically plausible, not confirmed to work as advertised.
Separately, Palo Alto Networks' Unit 42 already demonstrated the same underlying flaw against live Google infrastructure, using malware instead of phishing, in research it calls Pass-ta-Key. Their tested finding: Google doesn't always validate a newly registered device credential, letting an attacker enroll a verification key it controls. Google's own account-security documentation confirms the gap: adding a new sign-in method from an already-active session doesn't require a fresh identity check, only after-the-fact anomaly monitoring and a delay window before some changes take effect.
Two different attack paths, phishing and malware, reach the same result: a credential the platform accepted as legitimate, that a password reset does nothing to remove.
The Takeaway: If "we use passkeys now" closed the phishing line on your risk register, both of these findings say otherwise. A password reset doesn't touch a rogue passkey, because a passkey isn't a password. The fix isn't disabling passkeys, it's requiring a fresh identity check before any new sign-in method gets added, not just monitoring after the fact for one that looks wrong.
Sources: Abnormal AI: iAuthFlow v2 enrolls Google passkeys that survive password resets · The Register: $10K phishing kit claims it can plant rogue passkeys · Unit 42: Pass the Passkey — a novel attack surface in passwordless authentication · Google Account Help: Manage at-risk or new sign-in methods
Two Hops Past Your Audit
Confidence: MODERATE · United States · Financial Services
LockBit listed U.S. Bancorp on its leak site this week and set a deadline: pay by September 3 or the data goes public. The bank says its own systems were never touched.
US Bank traced the extortion claim to what it calls a fourth-party incident, according to Lee Henderson, the bank's VP of public affairs: not a breach of the bank itself, and not a breach of one of its vendors, but a breach at a vendor of one of its vendors, one hop further out. The bank has declined to name either vendor. No outlet covering the story, including specialist cybersecurity press, has independently identified them either.
That refusal points at a real limit almost every vendor-risk program shares. Companies assess their direct vendors: security certifications, access reviews, a breach-notification clause in the contract. That work stops at the first signature. What that vendor's own vendors and subprocessors do with your data, one layer further down, usually never enters the process at all.
US Bank's own controls appear to have held. The exposure sat a layer beyond where its vendor-risk program, like nearly every other company's, was ever built to look.
The situation is still unresolved. LockBit's leak-site listing is an extortion claim, not a confirmed breach, and US Bank has not said whether any of its data is actually exposed.
The Takeaway: Your critical-vendor contracts almost certainly require the vendor to notify you if it's breached. Whether that vendor has to disclose who its own critical vendors are, and whether a breach at one of them reaches you too, is usually a different clause, and most contracts don't have it. US Bank won't say who its fourth party is. If yours got hit the same way, would you even be able to ask?
Sources: The Record: US Bank says breach claims relate to a fourth-party incident · The Register: US Bank investigates LockBit's claims as gang sets pay-or-leak deadline
Romania's Gas Platform Was Built to Replace Russia. Russia Noticed.
Confidence: HIGH · European Union, Russia · Energy, Insurance
Romania sits on the western edge of the Black Sea, the body of water separating it from Russia and Ukraine to the east. On August 20, two Romanian fighter jets destroyed an explosive-carrying drone about 80 nautical miles off Constanța, Romania's main Black Sea port, near an offshore gas platform called Neptun Deep. It was the fourth drone incident near Romania in three weeks, and the second at this exact platform.
Neptun Deep holds an estimated 100 billion cubic meters of natural gas, a €4 billion project between Austria's OMV Petrom and Romania's majority state-owned Romgaz. It's due to start producing in 2027, the same year the European Union has set to end all imports of Russian gas. At full output it would roughly double Romania's gas production and make the country the EU's largest gas producer, with pipelines planned to carry that gas into Hungary, Bulgaria, Slovakia, and Moldova. Neptun Deep isn't incidental infrastructure. It's the physical replacement for the Russian gas the EU is trying to quit.
Romania has destroyed five drones over or near its territory in 2026 and recorded at least 23 airspace violations this year, more than the previous four years combined. Two Gerbera-type drones were destroyed at Neptun Deep itself on August 11, nine days before this incident. President Nicușor Dan, who initially treated earlier incidents as possible spillover from Russian strikes on Ukrainian river ports, now calls this pattern a direct intensification by Russia. Moscow hasn't addressed the Neptun Deep incident, and when Romania has raised the broader pattern diplomatically, it has dismissed the complaints as baseless.
NATO's mutual-defense guarantee, Article 5, an attack on one member is an attack on all, only applies to an "armed attack" on a member's actual territory or military forces. That language was written in 1949, before international law even had the concept of an exclusive economic zone, the offshore area where a country controls resources without holding full sovereignty. That legal category didn't exist until 1982, so an offshore platform like Neptun Deep sits in a zone NATO's founding treaty never anticipated. Even if that gap closed, a single drone or a cut cable is deliberately small enough to stay below the scale that counts as an armed attack. NATO has already faced this exact combination twice, the Nord Stream pipeline sabotage in 2022 and the cutting of undersea cables in the Baltic Sea from 2023 to 2025, and neither triggered Article 5. NATO's response both times was a dedicated patrol mission, not a collective-defense declaration.
That gap is also a financial one. Commercial property, marine cargo, and construction-all-risks policies covering assets in contested regions carry war and hostile-act exclusions, and insurance premiums on Black Sea energy projects have already climbed since the incidents began. What has never been settled is what actually triggers one of those exclusions, a government's own declaration of hybrid warfare, a formal attribution naming a state, or neither, on its own, until a court decides after a loss has already happened.
The Takeaway: Russia's state budget runs on oil and gas revenue, and every year a project like Neptun Deep gets closer to production is a year that leverage shrinks. This platform is a small piece of a much larger fight over energy revenue playing out across the region and the world, and drones are what that fight looks like when Russia can't fight it directly. If NATO's own pattern says that still doesn't trigger collective defense, your insurance policy is the backstop that actually gets tested. What your war and hostile-act exclusion actually requires, a formal declaration, a named state, or nothing at all, is worth knowing before the next incident forces the question, not after.
Sources: Balkan Insight: Romania destroys drone near major gas project in the Black Sea · ENR: Romania's $47B offshore gas project set to make it the largest EU producer, cutting off Russia · Maritime Security Forum: Attack on offshore targets in the EEZ and implications for NATO collective defence · SHAPE: Baltic Sentry mission · Ursula von der Leyen statement on the Neptun Deep incident (X)
Got this forwarded to you? Subscribe at stateofthethreat.com/subscribe — one email per week, no tracking, no spam.
Know someone who needs this? Forward this email. The threats they don't know about are the ones that hurt.