The Four-Party Ecosystem

Video: The 4PE Explained

Click here for video

The Threat Actors

๐Ÿ‡จ๐Ÿ‡ณ China (Volt Typhoon / Voltzite)

Strategic architect. Confirmed pre-positioned inside U.S. electric utility, oil pipeline, and water system OT networks (2023โ€“2025). Progressing inside operational control loops. Capable of simultaneous multi-sector disruption. Strategic objective: fix U.S. military within CONUS during Taiwan contingency.

๐Ÿ‡ท๐Ÿ‡บ Russia (Sandworm / GRU Unit 74455)

Only nation to conduct confirmed cyberattacks against national power grids (Ukraine 2015/2016). Demonstrated ability to cause physical equipment damage via cyber (Industroyer2). Doctrine treats infrastructure attack as routine military operations.

๐Ÿ‡ฎ๐Ÿ‡ท Iran (IRGC / Unit 910 / Unit 840)

Physical proxy capability via Hezbollah Unit 910 distributed cell model, Unit 840 cartel outsourcing, and ~18,000+ KSTs. Demonstrated CI attack capability (Saudi Aramco, Jordan fuel, Aliquippa PA water utility). Lowest barrier to kinetic attack on U.S. soil.

๐Ÿ‡ฐ๐Ÿ‡ต North Korea (Lazarus Group / RGB)

Nuclear EMP capability (demonstrated ICBM 2017). Cyber financial theft ($1.5B+). Escalation wildcard โ€” may act independently or as force multiplier during PRC/Russia operations. Unpredictability is itself a strategic asset.

Watch: Infrastructure Threat Briefings

Senior government and military officials explain the threat in their own words.

Former NSA Director Gen. Tim Haugh: Chinese Infrastructure Hacking

FBI Director Wray: Chinese Infiltration of Our Infrastructure

60 Minutes: Nine Substations Can Trigger a Black Sky Event

Assessment of China’s capability to hack our infrastructure, from the perspective of US Air Power

FIR Threat Analysis โ€” Download

The Foundation for Infrastructure Resilience has published detailed analysis of the Four-Party Ecosystem threat model.