United States Cyberwarfare Capabilities: Access, Effects and Power
An evidence-led journey through American cyber power—from the reported Stuxnet operation and the campaign against ISIS to defend forward, global hunt operations, intelligence access, alliances, private industry, and the contested view from China and Asia.
Begin at Natanz: a machine obeys two realities
Evidence cutoff: 18 September 2026. Inside Iran’s Natanz enrichment facility, centrifuges appeared to operators to be behaving normally while malicious logic reportedly changed their speed. The operation required much more than a clever file. Its designers needed intelligence about a guarded industrial process, knowledge of specific controllers and frequency converters, a route into an isolated environment, testing against representative equipment, code that altered physical behavior, and deception that delayed diagnosis. When the malware escaped its intended environment and researchers discovered it in 2010, the world learned the name Stuxnet.
Extensive reporting based on current and former American officials attributes the operation—often called Olympic Games—to the United States and Israel. Neither government has formally acknowledged responsibility. The U.S. Army’s professional journal preserves this distinction in its Army Stuxnet history: it describes the widely reported joint venture and physical effect while noting that Pentagon officials had not taken credit. That is the correct evidentiary formulation. “Strongly reported” is not the same as “officially admitted.”
Natanz nevertheless provides a starting point for understanding American capability. It demonstrates the reported integration of foreign intelligence, covert access, engineering knowledge, software development, physical testing, allied cooperation, and national-level decision-making. The technical effect was narrow—alter the operation of selected equipment—but the political objective was larger: impede a nuclear program while avoiding or delaying a conventional strike. Cyber action served statecraft and coercion rather than existing as a separate digital war.
The episode also exposes operational risk. Code built for a controlled target propagated beyond it. Discovery allowed researchers and governments to study the methods. Iran adapted and continued enrichment. A covert action intended to avoid escalation arguably helped normalize cyber-physical sabotage and gave other states a powerful precedent to cite. Sophistication did not eliminate uncertainty, proliferation, or long-term strategic consequence.
This page therefore uses the practical definition of cyberwarfare: examine authority, objective, target, mechanism, effect, and conflict context. It does not assume that espionage is war, that every intelligence access is an attack, or that a technically impressive operation achieved its strategic goal. The journey moves from Natanz to an institutional system capable of intelligence collection, military campaigning, partner defense, disruption, public attribution, and effects integrated with conventional force.
The system behind the operation: command, intelligence and civilian power
American cyber power is not synonymous with U.S. Cyber Command. It is an interlocking system whose parts have different legal authorities and institutional incentives. The President directs national policy and military or covert action within constitutional and statutory frameworks. Congress authorizes, funds, oversees, and requires reporting. The National Security Council coordinates departments. The Office of the National Cyber Director addresses national policy coherence. Classification conceals much of the operational record, so public documents explain responsibilities more clearly than capabilities.
U.S. Cyber Command (USCYBERCOM) is the military hub. Established in 2009 and operational in 2010, it became a unified combatant command in 2018. Its mission includes directing, synchronizing, and coordinating military cyberspace planning and operations. The Cyber Mission Force supplies teams for national missions, combatant-command support, protection, and network defense. Army Cyber Command, Fleet Cyber Command/Tenth Fleet, Air Forces Cyber/Sixteenth Air Force, Marine Forces Cyberspace Command, and the Space Force provide or retain service capabilities. The Cyber National Mission Force became a subordinate unified command in 2022, reflecting the permanence of the defend-the-nation mission.
The National Security Agency provides the intelligence foundation. Its public NSA mission statement describes foreign signals-intelligence collection and analysis under Executive Order 12333 and other authorities, alongside cybersecurity for national-security systems. NSA develops insights into foreign communications, infrastructure, capabilities, and intent; Cyber Command can convert intelligence and access into military options. Co-location and the historical dual-hat command arrangement improve integration but create a persistent tension: intelligence officers may want to preserve an access for collection, while military operators may want to use or disrupt it and thereby reveal it.
The CIA and wider Intelligence Community can conduct foreign intelligence and, when properly authorized, covert action. CISA leads civilian federal cybersecurity and coordinates critical-infrastructure risk management; it does not command military offensive operations. The FBI and Department of Justice investigate, seize infrastructure under judicial authority, indict operators, and work with victims. State and Treasury coordinate diplomacy, public attribution, sanctions, and coalition action. Sector agencies contribute expertise in energy, finance, transport, communications, and other critical systems.
The boundaries matter. Title 10 authorities govern military activity; Title 50 covers intelligence, including statutory covert-action rules; domestic law-enforcement and homeland-security authorities operate differently again. The CRS cyberspace operations primer explains that Congress affirmed presidential authority for offensive cyberspace operations, characterized certain clandestine military cyber activity as traditional military activity, and established notification and oversight requirements. “Classified” does not mean “unregulated,” but outsiders cannot independently assess every approval, target, safeguard, or compliance decision.
Size creates both strength and friction. A GAO organizational assessment identified about 500 Department of Defense organizations with cyberspace roles and potential overlap. The ecosystem provides specialization, service knowledge, laboratories, acquisition, intelligence, training, and global reach. It also creates duplication, incompatible tooling, talent competition, unclear ownership, and slow deconfliction. American capacity is best understood as an orchestration problem, not a single elite team with unlimited access.
From a weapon held in reserve to persistent engagement
When Cyber Command began, senior thinking often treated offensive cyber capability like a strategic instrument to hold in reserve. Approval was centralized, accesses were fragile, and leaders feared unintended effects or escalation. Meanwhile, adversaries operated continuously below the threshold of armed conflict: stealing intellectual property, collecting government data, preparing infrastructure, running influence campaigns, and using criminal ecosystems. A model built around waiting for a catastrophic “cyber Pearl Harbor” did not match that daily competition.
The 2018 Defense cyber strategy answered with defend forward: disrupt or halt malicious activity closer to its source, including activity below armed conflict. Cyber Command’s operational concept of persistent engagement treats cyberspace as a domain of continuous contact. The objective is not to launch a destructive attack every day. It is to observe campaigns, generate intelligence, expose tools, work inside consenting partner networks, contest infrastructure, create uncertainty, and, when authorized, disrupt or degrade the adversary’s ability to act.
Law and policy changed with the posture. National Security Presidential Memorandum 13 replaced the more centralized approval framework associated with Presidential Policy Directive 20 and delegated categories of time-sensitive military cyber decisions. The FY2019 National Defense Authorization Act affirmed authorities to act in foreign cyberspace against active, systematic, and ongoing campaigns. Delegation can increase speed; it also raises questions about strategic coherence, escalation signals, third-party infrastructure, intelligence loss, and whether repeated tactical disruption changes an adversary’s long-term behavior.
The unclassified 2023 Defense cyber strategy kept defend forward while placing it inside integrated deterrence. It described four lines of effort: defend the nation; prepare to fight and win; build advantages with allies and partners; and build enduring advantages in people, intelligence, science, technology, organization, and readiness. Its central lesson from Ukraine was restraint in prediction: cyber capabilities are most effective alongside other instruments and may be limited when used alone.
The 2026 national cyber strategy intensifies the language. It calls for defensive and offensive operations to shape adversary behavior, modernization of federal systems, critical-infrastructure and supply-chain security, technological superiority, talent, and private-sector incentives to help identify and disrupt adversary networks. It also states that responses need not remain in the cyber domain. The document is a statement of policy ambition, not evidence that every promised capability is fielded, lawful in every circumstance, or strategically effective.
The strategic test is campaign-level. Cyber campaign design asks whether repeated actions connect to a defined political end, what theory explains adversary behavior, how success is measured, and what happens when the opponent adapts. Removing one server or burning one implant can protect victims and still leave recruitment, financing, replacement infrastructure, and state sponsorship intact. Persistent activity is not automatically persistent advantage.
The first public campaign: Cyber Command enters the war against ISIS
In 2016, Joint Task Force ARES began Operation Glowing Symphony against the Islamic State’s online media infrastructure. ISIS depended on digital systems to produce, store, distribute, and defend propaganda; maintain accounts; and coordinate a global message. The American objective was to interrupt that production chain, delete or corrupt data, lock operators out, and force the organization to spend time rebuilding rather than recruiting and directing attention.
The operation matters because declassified material exposes the machinery behind an offensive campaign. The Glowing Symphony archive contains planning and assessment records showing target nomination, legal review, collateral-effects estimation, intelligence-gain-and-loss analysis, political-military assessment, blowback assessment, coalition coordination, and approval. Cyber effects were treated as military actions requiring more than technical feasibility.
The documents also reveal friction. Target infrastructure crossed jurisdictions and often sat on third-party systems. Intelligence agencies valued collection from accounts that military operators wanted to disrupt. Interagency objection and approval could take longer than the opportunity. The command encountered data-handling and storage problems after collecting more material than expected. Assessors could measure whether operators completed tasks more readily than whether the campaign durably reduced ISIS influence. These are not minor administrative details; they are capability limits.
Glowing Symphony nevertheless became a model. It organized offensive cyber activity around a target system rather than an isolated machine: development, distribution, dissemination, defense, and the people who kept those functions running. This systems approach later informed task forces focused on other adversaries. It also demonstrated that cyber operations can impose repeated friction without producing the cinematic destruction often associated with “cyberwar.”
The next visible test was election defense. During the 2018 U.S. midterms, Cyber Command reportedly disrupted access used by Russia’s Internet Research Agency while other agencies warned targets, shared intelligence, imposed sanctions, and protected election systems. The public record is incomplete, but Defense officials cite election operations as an early defend-forward success. The effect was time-bounded and paired with non-cyber instruments; it did not eliminate Russian influence capability.
Together, the cases show a characteristic American strength: combine intelligence, military access, platform or infrastructure knowledge, interagency action, and allies to pressure an operational system. They also show why cyber effects assessment must separate task completion from behavior change. Accounts deleted, servers unavailable, adversary work hours consumed, propaganda output reduced, audience behavior changed, and strategic objectives achieved are six different measurements.
The hidden foundation: signals intelligence, access and the vulnerability economy
An offensive operation begins long before execution. Operators need to understand the target’s people, technologies, trust relationships, network boundaries, physical process, and recovery behavior. They may need credentials, infrastructure, implants, exploitable flaws, language expertise, target replicas, and a way to remain undetected. The United States’ greatest advantage may therefore be the combination of global signals intelligence, a large research base, advanced computing, military access development, allied collection, and proximity to major technology and communications companies.
NSA’s public mission combines foreign signals intelligence with national-security cybersecurity. The same cryptologic and technical knowledge that finds a weakness in a foreign system can help defend an American one. It also produces conflict: disclosing a vulnerability to a vendor protects users, while retaining it may preserve intelligence or an operational option. The United States uses an interagency vulnerabilities-equities process to weigh such interests, but individual deliberations are usually secret.
The Shadow Brokers disclosures made the risk concrete. In 2017, a cache publicly presented as stolen NSA tooling included exploitation techniques later reused by criminals and states. Microsoft’s Microsoft WannaCry assessment said WannaCry drew from exploits stolen from NSA and argued that government stockpiles can create civilian harm when they escape. NSA did not publicly validate every provenance claim. The downstream lesson remains: an exploit is not a missile stored unchanged in a guarded bunker. It is information that can be copied, reverse engineered, repurposed, and deployed at global speed.
Access itself must be governed. Access stewardship requires an owner, mission rationale, legal basis, exposure assessment, intelligence value, safety analysis, deconfliction, monitoring, and an exit or disclosure decision. Using an access may reveal it. Leaving it in place may expose victims or allow another actor to discover the same flaw. Disrupting a server can destroy intelligence that identifies a wider network. A third country may own the infrastructure even when the adversary rents it.
American private-sector strength multiplies capability without making companies military auxiliaries. Cloud providers, endpoint vendors, telecommunications carriers, domain registries, cryptocurrency firms, incident responders, universities, and security researchers hold telemetry or infrastructure relevant to campaigns. They can patch products, suspend services, preserve evidence, notify victims, or collaborate under legal and contractual mechanisms. The government can also buy commercial data and capabilities. Each relationship raises questions about due process, privacy, market concentration, cross-border jurisdiction, transparency, and whether defensive cooperation becomes operational dependence.
This intelligence foundation explains why capability cannot be inferred from disclosed malware alone. The expensive and scarce portion may be target discovery, clandestine access, identity, testing, intelligence support, or a partner relationship; the payload may be deliberately simple. Defenders should protect cyber key terrain—identity, software delivery, administrative planes, telecommunications, cloud control, engineering workstations, and recovery—not merely hunt for famous tool names.
A capability that travels: hunt forward, Ukraine and the alliance network
The United States’ most distinctive public capability may be permission to operate with partners at global scale. In a hunt-forward operation, Cyber National Mission Force personnel work on networks selected by a consenting host nation to find malicious activity, understand adversary methods, and help the partner act. Cyber Command describes these missions as defensive. The insight can then be shared with government and industry to protect other networks before the same tradecraft reaches them.
Ukraine shows the model under pressure. In late 2021, before Russia’s full-scale invasion, the largest American hunt-forward team to that date worked beside Ukrainian defenders across multiple networks. Cyber Command’s Ukraine hunt-forward record says the teams helped identify and address malicious activity and that insights were returned to American public and private defenders. After the invasion, the command provided remote analysis, network defense, intelligence, and options for national decision-makers. Public statements acknowledge that operations were conducted as directed but do not identify every target or effect.
The network has expanded. The 2026 Cyber Command posture statement reports more than one hundred partner-enabled deployments across over thirty countries in recent years, including more than two dozen hunt-forward missions during 2025. Earlier public releases identify operations in Estonia, Lithuania, Montenegro, North Macedonia, Croatia, Albania, Latvia, and Ukraine, across every geographic combatant-command region. Malware samples discovered during missions have been released for the wider security community.
Partnerships generate several advantages simultaneously: legal access by invitation; local context; early observation of adversary tradecraft; interoperability; trust; shared warning; and an enlarged defensive sensor network. Intelligence alliances and military relationships add collection, language, geography, infrastructure, and political legitimacy that a unilateral operation may lack. Training events such as Cyber Flag turn this network into a practiced coalition rather than a contact list.
Consent does not eliminate controversy. Host governments determine the networks offered, but citizens and third parties may not know what foreign personnel can observe. Malware may communicate through infrastructure in states that did not consent. Information returned to the United States may create privacy, sovereignty, or intelligence-sharing concerns. Partners differ in law, human-rights safeguards, capacity, and political risk. Public descriptions emphasize defensive hunting, while adversaries may perceive the global presence as preparation for offensive access.
Resilience, not merely access, explains the alliance advantage. Shared cloud capacity, incident response, intelligence, satellite communications, vendors, and logistics helped Ukraine absorb attacks that might have isolated a less connected state. Yet dependence on a few American providers also concentrates risk and gives U.S. policy and corporate decisions international consequence. A mature assessment records both: alliances expand reach and defense, while shared infrastructure creates common failure modes and political obligations.
Seen from Beijing and Tokyo: the same posture produces different stories
Researching American capability only through American documents reproduces American categories. Chinese and Japanese sources ask different questions: Is “forward defense” defensive when activity occurs outside U.S. networks? Does a global partner presence distribute security or extend intelligence reach? Who can test an attribution made with classified evidence? What precedent is created when a state claims a right to disrupt an ongoing campaign below armed conflict?
Chinese official and academic writing frequently describes defend forward as an offensive expansion of the defensive boundary. Researchers note that the United States combined a unified combatant command, streamlined authorities, private-sector cooperation, allies, training ranges, and public attribution into an enduring competition architecture. That structural observation is useful even where the surrounding language about “cyber hegemony” reflects Chinese state policy. The analytical task is to extract verifiable organization and doctrine without adopting either government’s preferred moral framing.
In April 2025, Harbin police placed three alleged NSA personnel on a wanted list. The Chinese Harbin allegations state that investigators linked attacks during the Asian Winter Games to NSA and alleged targeting of event systems, critical infrastructure, Huawei, and personal information. Public reporting named technical teams and asserted links to two American universities, but association with NSA-designated academic programs is not proof that a university conducted an operation. No public American acknowledgment or independent forensic account establishes the attribution.
In October 2025, China’s Ministry of State Security and CNCERT alleged a longer campaign against the National Time Service Center, which produces and distributes China’s national time standard. The Chinese timing-center report describes alleged compromise of staff mobile devices beginning in March 2022, use of stolen credentials from April 2023, and repeated operations against internal networks through June 2024. Chinese authorities attributed the activity to NSA and alleged an attempt to reach high-precision ground-based timing systems. The report is valuable as a primary technical attribution claim. Without raw evidence, victim-independent analysis, or corroborating disclosure, its operator and intent findings remain unverified outside the issuing state.
Japanese research offers a less accusatory but important external critique. A March 2026 Japanese NIDS assessment connects persistent engagement with a broader theory of cross-domain denial: cyber power rarely decides outcomes alone and gains value when integrated with diplomatic, informational, military, economic, space, and electromagnetic action. Earlier NIDS work also highlights cases in which American planners considered cyber options but preferred conventional force because effect, reliability, and collateral consequences were more predictable.
Put together, these sources prevent two errors. The first is accepting Chinese state attribution merely because American operations are secret and technically plausible. The second is rejecting every Chinese claim merely because the source is an adversary government. Apply the same cyber attribution ladder to all states: establish the incident, cluster the technical activity, identify the operator, connect it to an institution, assess direction or control, and state confidence and gaps. Symmetrical method is more valuable than symmetrical conclusions.
The 2026 capability: what is demonstrated, what is claimed, and what remains limited
The public evidence supports a broad American portfolio. The United States can generate foreign cyber intelligence at global scale; develop and preserve access; defend military networks; organize standing offensive and defensive teams; disrupt adversary infrastructure; support conventional operations; hunt with invited partners; expose malware; coordinate seizures, indictments, sanctions, and diplomacy; and mobilize a private technology sector with worldwide reach. Its alliances provide geography, legitimacy, collection, resilience, and interoperability that no purely national force can reproduce.
Current investment points toward greater speed and integration. The FY2026 defense request described billions of dollars for cyber operations, including offensive and defensive capabilities, intelligence, access, Hunt Forward, artificial intelligence and machine learning, training, enhanced sensing, and the Joint Cyber Warfighting Architecture. Cyber Command’s 2026 posture statement says AI is being applied to collection, detection, exploitation, maneuver, and command and control. Budget language proves planned investment, not operational performance; public statements reveal direction, not tool quality or target access.
The capability also has structural weaknesses. The country depends heavily on privately owned critical infrastructure, global supply chains, cloud concentration, aging federal systems, commercial software, and exposed local services. Military cyber forces compete with industry for talent. Hundreds of defense organizations create overlap. Accesses may be lost when exposed or patched. Operations require intelligence, legal review, deconfliction, partner consent, and decisions about collateral effects. Secrecy complicates democratic evaluation and international signaling. A technically successful action may trigger adaptation, retaliation, proliferation, or political cost without changing adversary behavior.
Cyber operations are especially poor at guaranteeing durable control. Data can be restored, infrastructure replaced, accounts recreated, and adversaries rerouted. Effects may propagate through civilian dependencies or third countries. Intelligence access and destructive action often compete. For operational technology, inaccurate process knowledge can create uncontrolled safety consequences. The United States can possess an advanced capability and rationally decide not to use it because bombs, diplomacy, law enforcement, vendor action, or doing nothing offers a more predictable outcome.
Defenders outside the United States should avoid two extremes: assuming American services can enter any system at will, or ignoring them because public evidence is incomplete. Model mission-relevant exposure. Protect telecommunications, identity, software updates, cloud administration, edge devices, industrial engineering, research institutions, defense suppliers, and timing or navigation dependencies. Monitor legitimate administration and credential use, not only malware. Separate control planes. Retain independent logs. Rehearse recovery when the identity provider, management plane, or trusted supplier is compromised. Map cyber pre-positioning without treating every intrusion as proof of an imminent attack.
Analysts should maintain three columns. Demonstrated capabilities are supported by acknowledged operations, declassified records, observable effects, or multiple independent sources. Declared capabilities appear in doctrine, budgets, or official speeches but may not be publicly tested. Alleged capabilities come from investigative reporting, leaks, victims, or foreign governments and require explicit sourcing and confidence. Stuxnet belongs in the strongly reported category; Glowing Symphony and partner hunting have substantial official records; the Chinese 2025 attributions remain state allegations pending independent corroboration.
Finally, connect capability to purpose. The Iran–United States cyber conflict shows how cyber access, industrial effects, coercion, intelligence, and conventional strikes can interact across decades. The lesson is neither that cyber power replaces war nor that it is merely another support function. It creates options: to know, prepare, expose, deny, disrupt, deceive, or enable another force. American advantage depends on choosing among those options with reliable intelligence, lawful authority, disciplined access stewardship, credible assessment, allied trust, and an honest account of uncertainty.
Frequently asked questions
What are the United States’ main cyberwarfare capabilities?
Public evidence supports capabilities for foreign-intelligence collection, access development, defensive and offensive cyberspace operations, disruption of adversary infrastructure, cyber support to joint military campaigns, protection of military networks, partner-network threat hunting, malware and infrastructure exposure, and coordinated diplomatic, financial, intelligence, law-enforcement, and private-sector action. The most sensitive tools, accesses, targets, and effects remain classified.
Is U.S. Cyber Command the same organization as the NSA?
No. U.S. Cyber Command is a military combatant command, while the National Security Agency is an intelligence and combat-support agency responsible for foreign signals intelligence and national-security cybersecurity. They are co-located, share important capabilities, and have historically shared one leader under a dual-hat arrangement, but they operate under different missions, authorities, oversight, and risk calculations.
Did the United States create Stuxnet?
The United States has never publicly acknowledged responsibility. Extensive reporting based on current and former officials attributes the operation to the United States and Israel, and a U.S. Army professional publication describes that attribution while preserving the lack of official confirmation. It should therefore be presented as strongly reported, not formally admitted fact.
What do “defend forward” and “persistent engagement” mean?
Defend forward is the Department of Defense approach of countering malicious cyber activity closer to its source before it harms U.S. interests. Persistent engagement is the operational logic of maintaining continuous contact and contesting adversary campaigns below and during armed conflict. These concepts include defensive partner operations, intelligence generation, exposure, disruption, and offensive options; they do not authorize arbitrary private hacking.
How credible are Chinese allegations of American cyberattacks?
They must be evaluated claim by claim. Chinese authorities have published technical and legal allegations concerning NSA activity, including incidents involving the Harbin Asian Winter Games and China’s National Time Service Center. These are primary records of China’s attribution, not independent proof. Analysts should separate observed artifacts, infrastructure location, operator identity, agency sponsorship, intent, and state responsibility and seek corroborating telemetry or third-party investigation.