“China's cyber explosives are in place”
What Rob Joyce's warning about pre-positioned attackers means for ordinary networks — not just critical infrastructure
Rob Joyce spent decades at the National Security Agency, including as its Director of Cybersecurity, and served as White House Cybersecurity Coordinator. When someone with that vantage point tells Congress that the threat has changed, it is worth understanding precisely what he means. His warning is not about data theft. It is that state-sponsored actors have quietly established footholds inside U.S. networks — and are waiting, positioned to disrupt those networks at a moment of their choosing.
Testifying before the House Select Committee on the Chinese Communist Party in March 2025, Joyce described PRC state hackers having "prepositioned malware within our power grids, pipelines, water treatment plants, and other critical infrastructure" for use in the event of a conflict. This is not espionage in the traditional sense. It is the digital equivalent of placing explosives and walking away — leaving them in place until they are needed.
The campaigns are documented, not hypothetical
Three named operations make the pattern concrete, and all three have been documented by CISA, the FBI, and the NSA:
Volt Typhoon burrowed into routers, edge devices, and operational-technology systems inside U.S. critical infrastructure and simply waited — living off the land to evade detection. U.S. agencies have described the posture as pre-positioning for the disruption of critical services, with footholds maintained in some networks for five years or more.
Salt Typhoon penetrated major U.S. telecommunications carriers — reporting has named AT&T, Verizon, and Lumen — giving operators access to call and text records, including those of senior officials. Senator Mark Warner called it "the worst hack in our nation's history." The breach was severe enough that the FBI and CISA publicly urged Americans to move to encrypted messaging because the integrity of the telephone network could not be guaranteed.
Flax Typhoon assembled a botnet from more than 200,000 compromised routers, cameras, and other network devices — turning ordinary business and consumer equipment into attack infrastructure.
In every case, the foothold was trusted network hardware — the layer that software-based security is built to run *on top of*, and therefore the layer it cannot see into.
The foothold is the hardware
This is what makes the threat so durable. Much of the access is gained through exactly the kind of unmanaged, end-of-life, and foreign-made hardware found in everyday networks. Consider the router market alone: a single foreign manufacturer grew from roughly ten percent to more than sixty percent of the U.S. retail router share in a few years — a position Joyce told Congress appeared to have been achieved by selling below cost. And under PRC law, companies are compelled to cooperate with the state's intelligence apparatus when directed. The concern is structural, not a judgment about any single device: when the hardware beneath your network answers to someone else, the software running above it is defending a foundation it does not control.
Why it matters to you
Pre-positioning does not discriminate by size. The same neglected router that exposes a utility can expose a clinic, a factory, or a small business — organizations that will never staff a security team and have had no affordable way to address the hardware layer. A compromised device beneath your network does not announce itself. Owning and controlling your own trust, and taking devices off the public internet, removes the foothold these campaigns depend on.
The policy response is catching up — one category at a time
Joyce's warning was about hardware: the pre-positioned access built into the devices we let adversaries make and sell to us. The government is now acting on it, category by category. The FCC placed foreign-made routers on its Covered List in March 2026, and in July 2026 extended the same logic to networked smart machines and connected power inverters. The tide is turning in the right direction.
But pre-positioning is already inside the installed base. A ban on new devices does not evict an adversary who is already inside the hardware you switched on years ago. Closing that gap is not something any single agency can do — and it is not something you have to wait for.
What you can do now
Containing the foothold today is what removes the adversary's advantage. Faction's Cyber-Assured Pods and Portals sit behind your existing infrastructure and place your critical devices inside an owner-controlled network that is invisible and unreachable from the public internet, with every packet encrypted under keys only you hold. A compromised device can no longer reach, observe, or exfiltrate the traffic that matters — no rip-and-replace required.
Own your trust. Keep your peace of mind.
The new threat environment calls for a new Zero Trust model. We'd welcome the chance to show you how Faction puts you in control and secures your critical systems and assets rapidly with low cost and IT overhead.