Cyber Warfare: The Invisible Battlefield of 2026

In late December 2025, something went wrong at roughly thirty sites connected to Poland's energy grid. Operational technology was disrupted. Equipment was damaged. Power, mercifully, stayed on. Researchers attributed the operation to Electrum, a Russia-linked threat actor, and within weeks the story had largely vanished from international headlines, crowded out by louder wars in Ukraine and the Middle East. This is precisely the point. Cyber warfare in 2026 does not announce itself with the kind of imagery that holds a news cycle - no burning cities, no marching columns, no dramatic press conference. It announces itself, when it announces itself at all, as a vague reference to "operational technology disruption" buried in a cybersecurity trade publication, while the actual operation it describes may have been months or years in the making, embedded quietly inside a network long before anyone outside a small circle of intelligence analysts noticed anything at all.

This is the defining feature of the invisible battlefield: most of the war is not the attack. It is the waiting. Hacker groups linked to China, Russia, Iran, and North Korea, alongside ransomware groups, continue to threaten critical infrastructure at scale, with these operations deliberate and sustained, aimed at embedding access within key systems to enable disruption during periods of conflict or crisis. Somewhere right now, inside a water utility's control system or a regional telecom backbone or a hospital network, an adversary may already be sitting, patient, undetected, waiting for the day a crisis makes that access worth using. Understanding cyber warfare in 2026 means understanding this strategic patience - and understanding that the absence of a headline-grabbing cyber Pearl Harbor does not mean the war isn't already well underway.

Executive Summary

Cyber warfare has matured by 2026 into a permanent, continuous feature of great-power competition rather than an occasional crisis event, fought primarily through four state actors collectively known in cybersecurity circles as CRINK - China, Russia, Iran, and North Korea - alongside an increasingly professionalized ransomware ecosystem operating as proxy instruments for state objectives. China alone accounts for one-third of all state-sponsored cyber operations tracked globally, and when combined with Russia, the two nations represent 57 percent of such activity worldwide, with China having conducted more than twelve times the number of operations attributed to the United States.

The strategic logic underlying this activity has shifted decisively toward pre-positioning rather than immediate disruption. Chinese government-linked advanced persistent threat actors, including groups tracked as Volt Typhoon and Salt Typhoon, exhibit tactics and target selection that extend beyond traditional espionage, positioning themselves within information technology networks specifically to enable lateral movement into the operational technology systems that control critical infrastructure - power, water, telecommunications - long before any conflict requires activating that access. For China specifically, this pre-positioning inside critical infrastructure ahead of a potential Taiwan conflict represents a core strategic objective, alongside continued theft of intellectual property from technology, defense, pharmaceutical, and energy sectors.

2026 has also brought the clearest demonstration yet of cyber warfare operating in direct, real-time concert with kinetic conflict. Following February 2026 US-Israeli strikes against Iranian targets, security researchers reported a surge of retaliatory cyber operations and hacktivist campaigns targeting organizations in Israel, the United States, and allied countries, with one particularly striking episode involving the hacking of a popular Iranian prayer app to broadcast anti-regime messages urging military personnel to defect during the actual airstrikes themselves. Artificial intelligence has emerged as the single most consequential force multiplier reshaping this domain, accelerating attack speed, scale, and believability across every major actor simultaneously. This report examines the current state-actor landscape, the specific doctrines and target sets driving Chinese, Russian, Iranian, and North Korean cyber operations, AI's transformative role in the domain, and the genuine, growing risk that this invisible war eventually produces visible, catastrophic consequences.

Background

Cyber warfare's evolution from a niche intelligence concern into a primary arena of great-power conflict has proceeded gradually but consistently over roughly two decades, accelerating sharply in the period following Russia's 2022 invasion of Ukraine and the subsequent normalization of cyber operations as a standard accompaniment to active military conflict. The US intelligence community's 2026 Annual Threat Assessment makes clear that China, Russia, Iran, North Korea, and non-state ransomware groups will continue seeking to compromise government and private-sector networks alongside critical infrastructure, for intelligence collection, future disruption options, and financial gain, with China and Russia presenting the most persistent and active threats given their sustained research and development investment in offensive cyber capability.

The Ukraine war specifically has functioned as both a laboratory and an accelerant for state-sponsored cyber operations integrated directly with conventional warfare. Russian state-sponsored cyber threat actors have maintained persistent pressure on Ukrainian and NATO-aligned critical infrastructure, particularly in the energy, logistics, and communications sectors, working to collect intelligence, map networks, and position themselves for potential disruptive action - establishing a template of sustained, infrastructure-focused cyber pressure that has since proliferated well beyond the immediate Russia-Ukraine theater. The 2026 Iran-Israel-US war provided a second, parallel demonstration of this same pattern playing out in real time in the Middle East, with cyber operations launching essentially simultaneously with kinetic strikes rather than following at any meaningful delay.

North Korea's cyber program has developed along a distinctly different trajectory, blending traditional espionage objectives with direct financial theft serving the regime's broader strategic funding needs. North Korea's cryptocurrency heists alone probably stole $2 billion in 2025, funding the regime including further development of its strategic weapons programs, reflecting a sophisticated and agile cyber program that has become genuinely integral to the broader nuclear and missile development trajectory examined extensively in Global Chanakya's Korean Peninsula Nuclear Future analysis.

Current Situation

China: The Infrastructure Pre-Positioning Campaign

China's cyber operations in 2026 represent the most sophisticated and most strategically patient campaign of any state actor, organized around a core objective that distinguishes it sharply from more opportunistic or purely espionage-driven activity: establishing durable, undetected access inside the critical infrastructure of rival states well in advance of any specific crisis that might require activating it. CISA, NSA, and FBI assessment indicates Chinese government-linked APT actors are positioning themselves within information technology networks specifically to enable lateral movement to the operational technology systems controlling pipelines, aviation infrastructure, and water and wastewater systems - a pattern of activity that extends well beyond traditional intelligence-gathering toward genuine pre-conflict strategic positioning.

The Singapore telecommunications breach illustrates the scale and sophistication this campaign has achieved by 2026. Singapore's Cyber Security Agency revealed that the China-linked group UNC3886 breached all four of the country's major telecommunications providers in a months-long espionage campaign, using zero-day exploits and rootkits to gain persistent access, ultimately forcing Singapore to mount an eleven-month counteroperation codenamed CYBER GUARDIAN - its largest ever - simply to evict the hackers and harden its defenses. This episode is instructive precisely because Singapore is not a frontline conflict state; it is a wealthy, technologically sophisticated city-state with no direct territorial dispute with Beijing, illustrating how broadly distributed China's pre-positioning campaign has become across the entire Indo-Pacific telecommunications backbone rather than concentrating narrowly on states with active disputes.

Russia: Hybrid Warfare as Continuous Pressure

Russia's cyber posture in 2026 operates as one integrated component within a considerably broader hybrid warfare strategy that British intelligence leadership has characterized with unusual public bluntness. GCHQ Director Anne Keast-Butler has warned that Moscow is relentlessly targeting critical infrastructure, democratic processes, supply chains, and public trust, describing the current period as a "moment of consequence" for Britain and its allies, while assessing that the risk of miscalculation is as high as she has ever seen it throughout her career in the role.

The Polish energy grid incident referenced at the opening of this report sits within a broader, sustained pattern of Russian infrastructure-focused operations across NATO's eastern flank specifically. The coordinated cyberattack on roughly thirty sites connected to Poland's energy grid, attributed to the Russia-linked threat actor Electrum, disrupted operational technology and damaged key equipment without causing widespread power outages - a calibrated demonstration of capability that stopped short of the kind of catastrophic disruption that might trigger a more forceful NATO collective response, while nonetheless signaling genuine offensive intent and capability against alliance infrastructure.

Russian operations have continued targeting political and civil society organizations directly, illustrating the domain's role in broader information and political warfare beyond pure infrastructure targeting. A Russian-speaking ransomware group calling itself Qilin claimed responsibility for a cyberattack on the German political party Die Linke, threatening to publish stolen data unless a ransom was paid, with the party itself describing the incident as a hybrid warfare operation directly linking the group's activity to Moscow's broader geopolitical objectives. Security researchers have continued tracking the Russian threat group APT28 actively targeting government and military entities through 2026 using a multi-stage attack chain exploiting a Microsoft Office vulnerability designed specifically to remain stealthy during post-exploitation phases.

Iran: Conflict-Driven Escalation

Iran's cyber posture has transformed dramatically through 2026, shifting from its historical pattern of regionally contained operations toward genuinely global retaliatory activity directly tied to the country's escalating military confrontation with the United States and Israel. Iran's cyber operations have traditionally centered on suppressing internal dissent and punishing external enemies, but in 2026, amid rising tensions with the US and Israel, Iran's cyber capabilities have been weaponized at a scale never previously observed.

The most operationally striking episode of this escalation occurred during the war's most acute combat phase itself. The popular Iranian prayer app BadeSaba Calendar was hacked to broadcast anti-regime push notifications during US and Israeli airstrikes on Iran, with messages sent over a thirty-minute period urging Iranian military personnel to defect and lay down their weapons - an operation cybersecurity experts assessed as likely Israeli in origin, though no group formally claimed responsibility. This episode represents a genuinely novel category of cyber operation: not infrastructure disruption or data theft, but real-time psychological operations delivered through compromised civilian applications, timed precisely to coincide with kinetic military action for maximum psychological effect on enemy combatants.

The retaliatory dimension of this conflict has proven equally significant. Following the February 2026 US-Israeli strikes against Iranian targets, security researchers reported a surge of retaliatory cyber operations and hacktivist campaigns targeting organizations across Israel, the United States, and allied countries, with intelligence reporting from early March 2026 specifically warning of potential retaliatory cyber activity connected to the escalating tensions.

North Korea: Financial Warfare as Strategic Funding

North Korea's cyber program has continued blurring the line between traditional state-sponsored espionage and organized financial crime, serving a uniquely direct strategic function: funding the regime's nuclear and missile programs through large-scale cryptocurrency theft. One of the most widely reported examples of this pattern involved the attribution of a $1.5 billion cryptocurrency theft from the Bybit exchange in February 2025 to North Korea's Lazarus Group, with financial theft serving both economic and strategic purposes for the North Korean state simultaneously. This direct linkage between cyber theft and weapons program funding represents a genuinely distinct model among the major state cyber actors, one with direct relevance to the broader nuclear trajectory examined in Global Chanakya's Korean Peninsula Nuclear Future report.

The Ransomware Ecosystem as Proxy Warfare

A defining structural feature of the 2026 cyber landscape is the increasingly explicit role ransomware groups play as deniable instruments of state geopolitical strategy, rather than purely financially motivated criminal enterprises operating independently of government direction. Ransomware groups are increasingly being used as proxy weapons in geopolitical cyber warfare, enabling nation-states to exert pressure on adversaries while maintaining plausible deniability - a dynamic the Die Linke attack illustrates directly, given the party's own characterization of the incident as a hybrid warfare operation tied to broader Russian geopolitical objectives rather than simple financially motivated extortion.

The scale of this ransomware activity has continued intensifying even as overall cyberattack volume has shown signs of plateauing in certain categories. Ransomware attacks have jumped 48 percent year over year despite an overall decline in broader cyberattack activity, reflecting a strategic concentration of effort toward this particular, deniable instrument rather than a general reduction in the intensity of state-linked cyber operations.

AI's Transformation of the Domain

Artificial intelligence has emerged as the single most consequential force multiplier reshaping cyber warfare across every major actor's operations simultaneously, accelerating both offensive capability and the speed at which defenders must respond. Innovation in artificial intelligence will likely accelerate threats in the cyber domain specifically, with state actors increasingly seeking new capabilities spanning both kinetic and cyber warfare as AI's role in enabling weapons and systems design, shaping offensive and defensive cyber operations, and increasing the autonomy of uncrewed systems continues expanding.

China's specific application of AI within this domain has focused heavily on information warfare and influence operations rather than purely technical intrusion. Chinese Communist Party-affiliated actors have been observed publishing AI-generated content on social media specifically to amplify controversial domestic issues across various countries including the United States, employing AI-generated images, videos, and entirely synthetic AI-generated personas as part of information warfare conducted at genuine scale. Forward-looking threat assessments project Chinese state-sponsored actors will continue expanding beyond pure data exfiltration into what researchers describe as "AI-enabled narrative flooding" - reshaping digital environments through tailored, AI-generated influence operations at a volume and personalization level no human-staffed operation could previously achieve.

Strategic Analysis

The deepest analytical insight available from cyber warfare's 2026 trajectory is that the domain's strategic value derives overwhelmingly from patient pre-positioning rather than dramatic, immediate disruption, and Western defensive and deterrence frameworks built around responding to discrete "attacks" remain poorly calibrated to counter a strategy explicitly designed to avoid producing any single, attributable, response-triggering event. China's embedding of access within Western and allied critical infrastructure, documented extensively through the Volt Typhoon and Salt Typhoon campaigns and reinforced by the Singapore telecommunications breach, represents a form of strategic latent capability genuinely analogous to a conventional military force pre-positioning ahead of a future conflict - except largely invisible, largely deniable, and largely unaddressed by existing international legal and deterrence frameworks.

This pre-positioning strategy carries a specific, identifiable strategic rationale tied directly to the Taiwan question. China's embedding of access inside critical infrastructure specifically ahead of a potential Taiwan conflict suggests Beijing's cyber establishment views this access as a genuine instrument of coercion and disruption available for activation during precisely the kind of crisis scenario examined extensively in Global Chanakya's China Strategic Intelligence Report - providing Beijing a capability to disrupt allied logistics, communications, or energy supply at the moment of maximum strategic value, without requiring any pre-conflict escalation that might tip off defenders or trigger preemptive countermeasures.

The legal and normative framework governing cyber warfare's escalation thresholds remains genuinely underdeveloped relative to the domain's strategic significance, a gap that itself shapes state behavior in consequential ways. Russia and China have accepted the general applicability of international law to cyberspace while refraining from engaging with its actual operationalization in cyber warfare specifically, a silence that is legally significant in indicating both a lack of consensus and a shared reluctance to adopt positions that could limit operational use in a domain increasingly viewed as strategically valuable by both states. This deliberate ambiguity functions strategically: it preserves maximum operational flexibility for states willing to operate in the gray zone between clearly criminal activity and clearly armed conflict, while leaving victim states without a clear legal framework for determining when a cyber incident justifies an internationally recognized forceful response.

The integration of cyber operations directly with kinetic military action, demonstrated clearly during the Iran war's most acute phase, represents a genuinely significant doctrinal maturation worth tracking closely across future conflicts. State practice during armed conflict increasingly shows cyber operations integrated into military campaigns alongside kinetic force, but in a manner that deliberately avoids physical destruction, injury, or clearly classifiable attacks, instead focusing on pre-positioning within adversary networks and disrupting infrastructure supporting both civilian and military functions simultaneously. The BadeSaba prayer app operation illustrates a further, genuinely novel evolution of this pattern: real-time psychological cyber operations synchronized precisely with kinetic strikes, designed to compound a conventional military campaign's psychological effect on enemy personnel rather than serving a purely intelligence or disruption function independent of the broader military operation.

AI's role in this domain deserves particular strategic emphasis because it threatens to fundamentally restructure the offense-defense balance that has historically governed cybersecurity competition. The speed of AI-enabled cyber operations is shifting legal and operational review away from the employment stage toward ex ante governance through system design, training, and testing - reflecting a genuine recognition that human-paced review and response mechanisms, adequate for previous decades of cyber competition, cannot keep pace with AI-accelerated attack tempo, requiring an entirely different governance model built around constraining capability at the design stage rather than reviewing and authorizing specific operations as they occur.

Global Impact

Cyber warfare's continuous, normalized presence across nearly every major geopolitical theater carries consequences extending well beyond any single targeted state or institution. The Singapore telecommunications breach and the broader CYBER GUARDIAN counteroperation it triggered illustrate the genuine resource burden states across the Indo-Pacific now bear simply defending against persistent Chinese pre-positioning activity - an eleven-month, largest-ever counteroperation represents a substantial diversion of national cybersecurity resources that smaller, less wealthy states in the region may struggle to replicate to comparable effect.

For NATO and the broader transatlantic security architecture, Russia's sustained, calibrated infrastructure targeting - illustrated by the Polish energy grid incident and the broader pattern GCHQ's leadership has publicly highlighted - represents a genuine test of the alliance's collective response framework for cyber incidents that fall short of triggering Article 5 considerations while still causing real, documented damage to allied infrastructure. The deliberate calibration evident in Russia's approach, damaging equipment without triggering widespread outages severe enough to force a more forceful collective response, illustrates a sophisticated understanding of exactly where that response threshold currently sits.

For the broader Middle East, the cyber dimension of the Iran-Israel-US war examined extensively in Global Chanakya's dedicated coverage of that conflict demonstrates how thoroughly the cyber domain has become integrated into even the most acute, kinetic phases of contemporary great-power-adjacent conflict, with retaliatory hacktivist and state-linked cyber activity spreading across Israel, the United States, and allied countries within days of the conflict's most intense combat phase.

For the global financial and cryptocurrency ecosystem specifically, North Korea's continued large-scale theft - probably totaling $2 billion in 2025 alone - illustrates a genuinely distinct category of cyber warfare impact: direct financial damage to global markets and institutions that simultaneously funds an active, escalating nuclear weapons program, creating a direct, traceable link between cybersecurity failures in the commercial cryptocurrency sector and the broader nuclear proliferation risk examined throughout this platform's Korean Peninsula coverage.

Risk Assessment

The most significant systemic risk in the current cyber warfare landscape involves the gap between the scale of documented pre-positioning activity inside critical infrastructure and the international community's continued inability to establish clear escalation thresholds or accountability mechanisms for this kind of latent, pre-conflict cyber presence. A Volt Typhoon or Salt Typhoon-style access, sitting dormant for years inside operational technology systems controlling water, power, or telecommunications, represents a form of strategic vulnerability that conventional deterrence frameworks - built around responding to discrete, attributable acts of aggression - are poorly equipped to address before that access is actually activated.

The risk of miscalculation is as high as I've ever seen it. Moscow is relentlessly targeting critical infrastructure, democratic processes, supply chains, and public trust.

A second significant risk involves AI's accelerating effect on both offensive capability and the broader information warfare landscape simultaneously. As AI-enabled narrative flooding and synthetic disinformation campaigns scale beyond what human-staffed operations could previously achieve, the cumulative effect on democratic information environments across multiple countries simultaneously represents a genuinely difficult-to-counter, diffuse threat that existing platform moderation and government response frameworks have not yet demonstrated capacity to address at the necessary scale.

A third risk involves the ransomware ecosystem's continued evolution into an explicit instrument of state geopolitical pressure, given the 48 percent year-over-year increase in ransomware activity despite broader cyberattack volume trends. As more state actors recognize the deniability advantages this proxy model offers, the line between criminal extortion and state-directed hybrid warfare will likely continue blurring in ways that complicate both attribution and any internationally coordinated response.

A fourth risk, specific to active conflict zones, involves the demonstrated pattern of cyber operations escalating in direct, real-time concert with kinetic military action, as the Iran war illustrated clearly. Any future crisis - a Taiwan contingency, a renewed escalation in the Korean Peninsula, or further Middle East conflict - should be expected to feature an immediate, substantial cyber dimension synchronized precisely with kinetic operations, a planning assumption that defense and critical infrastructure operators in any potentially affected state must now treat as a baseline expectation rather than a worst-case contingency.

Future Scenarios

Scenario Analysis - the following projections are analytical simulations grounded in current trends, not confirmed intelligence or guaranteed outcomes.

Scenario One: Continued Pre-Positioning Without Major Activation (Most Likely, roughly 50% probability)

The current pattern of sustained, patient infrastructure pre-positioning by China, Russia, Iran, and North Korea continues through 2026 and beyond without a major activation event causing catastrophic, attributable damage, with periodic calibrated demonstrations - comparable to the Polish energy grid incident - continuing to signal capability without crossing thresholds likely to trigger a more forceful collective response from targeted states or alliances.

Scenario Two: Taiwan or Korea Crisis Triggers Major Cyber Activation (Moderate Likelihood, roughly 25% probability)

A genuine military crisis involving Taiwan or the Korean Peninsula triggers activation of previously dormant Chinese or North Korean pre-positioned access inside allied critical infrastructure, producing the kind of disruptive, attributable cyber event that has so far remained largely theoretical, testing both the affected states' resilience and the broader international community's capacity to respond collectively to cyber operations synchronized with kinetic conflict.

Scenario Three: AI-Accelerated Attack Tempo Outpaces Defensive Adaptation (Moderate Likelihood, roughly 20% probability)

AI-enabled offensive cyber capability advances faster than defensive AI integration and governance frameworks can adapt, producing a measurable widening of the gap between attacker and defender capability across multiple major actors simultaneously, with corresponding increases in successful intrusion rates and disruption events even absent any single major crisis trigger.

Scenario Four: International Legal Framework Achieves Genuine Clarification (Lower Likelihood, roughly 5% probability)

Sustained diplomatic pressure through United Nations and other multilateral channels produces genuine clarification of international humanitarian law's application to cyber operations during armed conflict, establishing clearer escalation thresholds and accountability mechanisms that meaningfully constrain state behavior in this domain - representing the most favorable but least probable near-term outcome given the demonstrated reluctance of major cyber-capable states to accept any meaningful operational constraint.

Intelligence Forecast

Watch continued reporting on Chinese pre-positioning campaigns specifically tied to Taiwan contingency planning, given the explicit strategic linkage between this activity and the broader cross-Strait security environment examined in Global Chanakya's China Strategic Intelligence Report. Watch for any further calibrated Russian infrastructure incidents across NATO's eastern flank, comparable to the Polish energy grid attack, as indicators of Moscow's continued willingness to test alliance response thresholds without triggering a more forceful collective reaction.

Watch North Korean cryptocurrency theft figures closely as a direct proxy indicator of the regime's broader weapons program funding capacity, given the documented linkage between cyber theft revenue and continued nuclear and missile development. Watch the continued evolution of AI-enabled influence operations specifically, particularly any further documented instances of Chinese state-linked AI-generated narrative campaigns, as indicators of how rapidly this dimension of the cyber domain is scaling relative to platform and government countermeasure capacity.

Watch any further cyber dimension developments tied to ongoing or future kinetic conflicts, given the now-established pattern of cyber operations launching in direct synchronization with military action, as demonstrated during the Iran war. Watch international legal and multilateral diplomatic developments around cyber warfare governance specifically, including any further United Nations Open-Ended Working Group output, as indicators of whether meaningful international consensus on cyber escalation thresholds is genuinely advancing or remaining permanently deferred.

Final Strategic Takeaway

Cyber warfare's defining characteristic in 2026 is not its destructive capacity, which remains, despite genuine and growing concern, largely demonstrated through calibrated, contained incidents rather than catastrophic infrastructure collapse. Its defining characteristic is its patience - a strategic posture, most fully developed by China but increasingly adopted across every major state actor examined in this report, that treats years of undetected network access as more valuable than any single disruptive event, precisely because that patient access remains available for activation at the moment of maximum strategic value, whenever that moment eventually arrives. This patience is what makes the domain genuinely invisible in a way conventional military buildups are not: a Volt Typhoon implant inside a water utility's control system produces no satellite imagery, no troop movement, no diplomatic démarche, until the day someone decides to use it.

The most consequential question this invisible battlefield poses for the remainder of this decade is not whether state actors will continue this pre-positioning campaign - they unambiguously will, at increasing scale and sophistication, accelerated further by artificial intelligence's continued integration into both offensive and defensive operations. The consequential question is whether targeted states, alliances, and the broader international legal architecture can develop response frameworks adequate to a threat that, by design, avoids producing the kind of clear, attributable, escalation-triggering event those frameworks were originally built to address. Until that gap closes, the most dangerous cyber operations of this decade will likely remain the ones nobody has yet noticed - sitting quietly inside critical infrastructure somewhere right now, waiting for a crisis that has not yet arrived.