Reading view

There are new articles available, click to refresh the page.

Why the Navy May Be Going Back to Steam

“During its 11-month deployment [mostly in the Middle East] which ended in May, and was the longest for a[n aircraft] carrier since the Vietnam War, the USS Gerald R. Ford conducted more than 11,000 aircraft carrier launches using electromagnetic catapults, more than carriers with steam [aircraft launching] systems could achieve…But perhaps the biggest benefit of the electromagnetic catapults are their lower cost and lighter personnel requirements. With the Navy running out of operating funds, and retention likely to plummet in the aftermath of the war with Iran, the fleet needs to make the most of every dollar and sailor.”

Writing that opinion piece in The Washington Post last Wednesday was Bryan Clark, a former Navy officer who at one time served as Special Assistant to the Chief of Naval Operations and Director of his Commander’s Action Group. Currently, Clark is a Senior Fellow and Director of the Center for Defense Concepts and Technology at the Hudson Institute.

I am using Clark’s article because it provides information that challenges a recent military step contained in an August 13, President Trump Presidential Memorandum which ordered “the Secretary of War, in consultation with the Secretary of the Navy, shall provide to the President… a plan on the required measures to replace the Electromagnetic Aircraft Launch System and Advanced Weapons Elevators with steam and hydraulic systems for the construction of [aircraft carrier] CVN-81[USS Doris Miller], including timelines and resourcing requirements.”

Electromagnetic catapult systems accelerate aircraft more smoothly and gradually, thus putting less stress on airframes. They also recharge faster than steam catapults which need to pressurize gases and they eliminate the need for boilers and other plumbing equipment needed to create steam.

Trump, who never served in the military, has been obsessed for years with the way that steam propels fighter jets off the decks of carriers and where a carrier’s tower structure or “island” is located.

I will point out, according to former Defense Department officials the Navy designers moved the island from the middle of the carriers to the back of the vessel to make more space for moving jet fighter aircraft around on the flight deck, in order to increase the number of flights or “sorties” that the carrier could generate.

These Trump aircraft carrier views apparently first came to him less than two months after he took office based on a March 2, 2017, tour he had on the then-under-construction USS Gerald Ford being built at the Newport News shipyard in Virginia.

Two months later, in a May 8, 2017 wide-ranging, 100-minute interview over dinner with Time Magazine editors and reporters, Trump at one point apparently brought up his visit to the Gerald Ford at Newport News where he was shown the catapult system for launching aircraft from the deck.

According to TIME, the conversation went, “Sir, this is our digital catapult system…we’re going to this because we wanted to keep up with modern [technology]. I [Trump] said, ‘You don’t use steam anymore for catapult? No sir. I [Trump] said, Ah, how is it working? Sir, not good. Not good. Doesn’t have the power. You know the steam is just brutal. You see that sucker going and steam’s going all over the place, there’s planes thrown in the air.’”

The TIME transcript then has Trump saying, “It sounded bad to me. Digital. They have digital. What is digital? And it’s very complicated, you have to be Albert Einstein to figure it out. And I [Trump] said -- and now they want to buy more aircraft carriers. I [Trump] said what system are you going to buy -- Sir, we’re staying with digital. I [Trump] said no you’re not. You going to goddamned steam, the digital costs hundreds of millions of dollars more money and it’s no good.”

I should note, at the time Trump visited and for months thereafter, there were issues with ghe new electromagnetic catapults, but fixes were made, although not in Trump’s mind.

Before I continue with Trump, let’s turn back to Heritage’s Bryan Clark, a real Navy expert, who wrote, “The biggest benefit of the electromagnetic catapults are their lower cost and lighter personnel requirements.”

Clark also noted, “The Ford’s crew is about 500 sailors smaller than its predecessors, largely because it is an all-electric ship outside of the engine room. Because they needed steam for catapults, older carriers also used steam for a variety of other functions throughout the ship — such as cooking equipment and water purification…And the steam catapults have so many moving parts and failure modes that they require about 10 more sailors per catapult — there are four catapults on a modern carrier — than electromagnetic systems.”

A Navy February press release said preliminary reports from the Sortie Generation Rate test program for aircraft show that the flight deck design in conjunction with electromagnetic systems and arresting gear “have contributed to an increased sortie generation rate compared to that of a Nimitz-class carrier.”

However, Trump over the years has kept calling for a return to steam catapults and retelling the story of his 2017 visit to the Gerald Ford.

For example, at a November 2, 2023 campaign rally in Houston, Texas, Trump was talking about shipbuilding and veered off to tell about a ship that was “in trouble” because “it was $10 billion over budget, and I wanted to go and see this ship that was costing so much money.”

At that Houston rally, Trump went on, “And I landed with a helicopter on top of this massive, incredible ship [USS Gerald Ford] being made in Newport News. And I said to the people…I want to meet the catapult people, the people that have done the catapulting.”

Trump continued, “I want to find out what the hell happened because the catapults weren't working. So for 50 years, we used steam more. And that beautiful scene, that steam goes off, and that plane gets thrown the hell off, the power, beautiful, and it's cheap.”

Trump said he asked a catapulter “Which is better, steam or electric? ‘Steam, sir.’ I [Trump] said why did they design electric? ‘Because it can keep going like this all day long, but it takes us 59 seconds to reload a plane. And when we reload the plane, the steam builds up, and it's all set, sir. It's perfect. It works so well. And we can fix it with a blowtorch if something happens. And if a wave hits it, it actually cools us down, sir. We love the waves hitting us. If a wave hits the electric [catapult], we're out of business, sir. We might -- we'll die with this thing.’"

Last July 15, at the U.S. Army War College in Carlisle, Penn., Trump again was talking about shipbuilding and switched saying, “I went to the ship [USS Gerald Ford], because I came into office and the ship was way over budget, built in Newport News, unfortunately, was way over budget.”

Trump went on, “I said, I want to meet the ‘catapultier’ and a man came over, along with four of his assistants. And I said, what's better, electric catapult or steam? He's been there for 25 years. He said, ‘Steam is better, sir. We can fix it with a hammer and a blowtorch. When the electric [catapult] goes bad, I have to send to MIT to get geniuses over here’…But I [Trump] said, so you're saying we spend billions of dollars extra to build electric catapults instead of using steam.”

Bryan Clark concluded his Post article saying, “Steam power was cutting-edge technology in the 19th century. It is the wrong choice for a Pentagon that is leaning into artificial intelligence and autonomous systems. The Navy should stay the course with electromagnetic catapults to keep the carrier fleet strong and deliver more firepower. It could use the savings to help refill the fleet’s weapons magazines.”

Clark told CNN the cost of changing catapults on the USS Doris Miller, already under construction, “will probably be into the billions” and it could delay the carrier — which was expected to be in service around 2034 — “until the end of the next decade.”

Clark also Clark said, “Nobody builds them anymore. There’s no steam catapult manufacturers in the…U.S. anymore so they’d have to restart that production line, which would cost tens of millions of dollars to get going and that’ll be, it’ll take years to start that up again and build the first catapult.”

To add insult to injury, various recent news reports have said Navy senior staffers are reviewing the name USS Doris Miller for CV-81.

Named on January 20, 2020 -- during the Trump first administration -- by then-Acting Navy Secretary Thomas B. Modly during a Martin Luther King, Jr. Day ceremony, it honored African-American Mess Attendant Third Class Doris “Dorie” Miller, who received the Navy Cross for extraordinary heroism during the attack on Pearl Harbor on December 7, 1941, where he manned an anti-aircraft machine gun without prior training and aided wounded crewmates.

In giving the new aircraft carrier Miller’s name, acting-Navy Secretary Modly said, “In selecting this name, we honor the contributions of all our enlisted ranks, past and present, men and women, of every race, religion and background.”

One name said to be under study to replace Miller’s is that of President Trump.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

It’s Time to Reengage North Korea

The U.S. and South Korea have their annual joint military drills (Ulchi Freedom Shield) from August 17-27, focusing on countering the threat from North Korea of drones and cyber-attacks. President Trump said on Sunday that he had ordered the Pentagon to “substantially reduce” joint military exercises with South Korea, according to the New York Times.

North Korea said these military exercises “are more serious, provocative and dangerous than last year.”

Although North Korea routinely criticizes these joint military exercises, this year North Korea went on to say that the U.S. is pursuing a new nuclear strategy that lowers the threshold of using nuclear weapons that pushes global security “to the brink of a nuclear war.”

North Korea’s usual response to these annual joint military exercises is the launching of short-range ballistic missiles into the Sea of Japan. This year there was no surprise when North Korea launched two ballistic missiles, saying the U.S. – South Korea drills were a “rehearsal for an aggressive war.” What was different was North Korea’s statement that the U.S. and South Korea and Japan formed a “nuclear alliance” that North Korea would respond to by building a new and higher level of nuclear deterrence.

This comes at a time when North Korea is providing Russia with combat troops, artillery shells and ballistic missiles for their war with Ukraine, while enhancing their relationship with China. The money North Korea receives from Russia is in the billions, with likely Russian assistance to North Korea’s nuclear, missile, and satellite programs.

Although North Korea has refrained from a seventh nuclear test – probably at the urging of China – they are building more nuclear weapons and ballistic missiles to deliver nuclear and conventional warheads. Recently, North Korea’s leader, Kim Jong Un, displayed to the world a new uranium enrichment facility with cascades of apparent new centrifuges to enrich uranium. This was in addition to the new uranium enrichment facility at North Korea’s nuclear complex in Yongbyon.

It was the issue of North Korea’s non-declared uranium enrichment sites that led to the failure of the 2019 Hanoi Summit. When Kim Jong Un offered to halt activities at Yongbyon, in return for the lifting of sanctions imposed on and after 2016, and President Trump responded with the request that North Korea declare “all” nuclear sites. Mr. Kim refused and that ended the Hanoi Summit.

Prior to and after the Hanoi Summit, North Korea has threatened to use tactical nuclear weapons in any conflict with South Korea. This is reminiscent of Russia’s President Vadimir Putin threat to use nuclear weapons in its invasion of and war with Ukraine. A war that North Korea joined, as an ally of Russia, with a recent Mutual Defense Treaty.

Hopefully, Ukraine will continue to receive the military support they need from the U.S. and NATO to protect its people and country from a revanchist Russian Federation that’s receiving significant military support from North Korea.

Messrs. Kim’s and Putin’s refrain of using nuclear weapons, with North Korea’s emphasis on building even more nuclear weapons, is concerning. Any use of nuclear weapons would be tragic for the world.

South Korea’s President, Lee Jae Myung, continues to reach out to North Korea, for talks that would lead to peaceful coexistence between the two Koreas. To date, North Korea’s response has been disappointing. But President Lee persists, knowing that an emboldened North Korea, now aligned with Russia, could incite conflict on the Korean Peninsula. Conflict that could cause instability on the Korean Peninsula and Northeast Asia.

Having negotiated with North Korea for over ten years, it is apparent to me that North Korea wants a normal relationship with the U.S. A relationship that would give North Korea international legitimacy and access to financial institutions.

Now would be the time for President Trump to meet with Kim Jong Un. Such a meeting would deescalate North Korea’s tension with South Korea and the U.S. It would also give the U.S. the opportunity to move in a different direction with North Korea, with the goal of getting North Korea to halt its nuclear and missile programs, in return for the easing and lifting of sanctions and a dialogue to normalize bilateral relations.

North Korea is a defacto nuclear weapons state and recognizing them as such should not be too difficult. Getting North Korea to implement a moratorium on its nuclear and weapons programs would be progress. Sanctions relief and a path to a normal relationship with the U.S. could convince Kim Jong un that a mortarium would be in North Korea’s interest, while aligning with a revanchist and fickle Vladimir Putin is not in North Korea’s interest.

Our goal should continue to be the complete and verifiable denuclearization of the Korean Peninsula, realizing that this could take years to achieve. Getting North Korea to halt its nuclear and missile programs and refraining from fomenting conflict with South Korea are immediate goals that are achievable, assuming a willingness to be flexible on sanctions relief and a dialogue on normalizing relations.

It is in the interest of world peace that the U.S. reengage with North Korea.

The author is a former Associate Director of National Intelligence. All statements of fact, opinion or analysis expressed are those of the author and do not reflect the official positions or views of the U.S. government.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Winning the Peace: The Democratic Dilemma of Limited War

In our previous article, we argued that overwhelming military superiority no longer guarantees strategic success.

Today, military and political outcomes have become increasingly disconnected.

As Carl von Clausewitz observed, war is fought to achieve political objectives, with military force only one instrument among many in statecraft.

Modern professional militaries are exceptionally proficient at identifying and destroying adversary military capabilities. Yet, they remain far less able to reshape the political, ideological, and social foundations that sustain an adversary's resilience.

The challenge confronting modern democracies is therefore not simply winning wars, but achieving what might be termed strategic translation—the successful conversion of military success into enduring political outcomes.

This predicament of strategic translation has intensified in recent years.

Operations involving Iran, Ukraine, and Gaza have once again raised questions about whether military success alone can produce durable political outcomes, echoing debates that followed the conflicts in Iraq and Afghanistan.

Strategic rivals such as Russia and China have closely monitored these outcomes, adjusting their own strategies to exploit the gap between military supremacy and political consolidation discussed in this article.

The inability to translate military victory into a long-term political settlement has evolved from a tactical issue to a defining test of democratic strategic competency as information flows quicken and domestic audiences examine protracted wars in real time.

Democratic Institutions: Competing Cultures

The principal obstacle facing democratic societies is not a lack of military capability but the complexity of democratic governance itself.

Political authority is intentionally dispersed among elected governments, legislatures and independent public institutions, each possessing different responsibilities and professional cultures. While this diffusion safeguards liberty and accountability, it complicates the integration of national strategy.

Military power achieves its greatest strategic effect only when synchronised with diplomacy, intelligence, economic statecraft and political engagement.

Yet democratic institutions frequently develop these capabilities in parallel rather than as a unified enterprise. Foreign affairs, defence, treasury and justice each define success differently, compete for resources and optimise their own organisational objectives.

Ironically, modern armed forces have become increasingly network-centric, integrating intelligence, logistics, cyber, space and operational planning within a single command framework. Governments, however, largely remain vertically organised.

Democracies have therefore become highly proficient at conducting limited tactical military campaigns while remaining less effective at integrating the broader instruments of national power necessary to convert battlefield success into enduring strategic advantage.

Selling Grand Strategy to Democratic Societies

Developing grand strategy is only half the challenge.

Democratic governments must also sustain public support over time. Unlike authoritarian systems, they must continually justify long-term strategic investment to electorates whose immediate concerns are economic security, healthcare, education and the cost of living.

Electoral competition naturally encourages governments to emphasise visible achievements—military operations, defence acquisitions, and capability announcements—rather than articulating the long-term political objectives these activities are meant to achieve.

Public debate therefore becomes centred on operations rather than strategy.

Without a compelling strategic narrative, public confidence gradually becomes tied to individual events rather than broader national objectives.

Procurement controversies, budget debates, and political disagreements increasingly dominate public discourse, making defence appear as a collection of expensive projects rather than as one component of an integrated national strategy.

Grand strategy that cannot be communicated to democratic societies cannot be sustained by democratic societies.

Democratic Time versus Strategic Time

Winning in combat requires strategic focus, but democratic politics inherently operates on short attention spans as highlighted by researchers in RAND Corporation. Electoral cycles, typically lasting two to five years, create strong incentives for governments to prioritise immediate, visible achievements over the sustained political, diplomatic, and institutional investments required to build long-term national power, as the UK Parliament's House of Commons Public Administration Committee has provided detailed structural barrier on this.

In coalition governments, differing party priorities and narrow parliamentary majorities can further complicate strategic continuity, encouraging short-term political compromise over long-term policy consistency.

The twenty-four-hour news cycle and social media amplify these pressures by encouraging governments to respond rapidly to headlines and shifts in public opinion, often elevating short-term tactical developments over long-term strategic objectives.

A single controversy, whether involving procurement, diplomacy or battlefield casualties, can dominate public debate and increase pressure for policy adjustments that disrupt strategic continuity.

This tension between political urgency and strategic reality was perhaps most evident in Afghanistan.

Throughout that conflict, successive US administrations increasingly balanced military objectives against domestic political pressures, with troop deployments and withdrawal decisions becoming closely linked to electoral cycles and public opinion.

President Obama's 2009 troop surge, while designed to reverse Taliban momentum, was accompanied by a July 2011 timetable for the start of withdrawal, signalling that the United States' commitment was not open-ended.

More than a decade later, the 2020 Doha Agreement established a fixed timeline for withdrawal despite persistent concerns over the readiness of Afghan security forces and the absence of a comprehensive political settlement.

In both cases, strategic decisions became increasingly shaped by political timelines, illustrating how democratic governments can struggle to align long-term national objectives with short-term domestic pressures.

Among NATO allies, these pressures were further compounded by divergent domestic political calendars and national priorities. France, for example, withdrew its combat forces in 2012 following President Hollande's election pledge, while Canada and several allies imposed national caveats that restricted how and where their troops could operate. NATO summits in Riga (2006) and Lisbon (2010) exposed persistent disagreements over troop contributions, burden-sharing and operational commitments, reflecting domestic political constraints as much as collective strategic planning.

As political priorities shifted across allied capitals, long-term strategic coherence became increasingly difficult to sustain.

Without stronger institutional continuity and bipartisan commitment, democratic grand strategy risks becoming reactive, fragmented and ultimately unable to translate military success into enduring political outcomes.

Winning the Peace Requires Political Campaign Design

If democracies are to prevail in limited wars, they must plan for peace before the first military operation begins.

Military campaigns should never exist independently of political campaigns. Governance, justice, policing, economic recovery, institution-building, and strategic communications must be integrated from the outset, rather than improvised after battlefield success.

Repeated strategic frustration also carries risks for democracy itself.

Failure to improve strategic integration may encourage growing calls for more centralised executive authority, expanded emergency powers and greater restrictions on civil liberties in the name of national security.

Democracies should resist this temptation.

Instead, democracies should strengthen institutions capable of ensuring long-term strategic continuity while remaining firmly accountable to constitutional government.

One possibility would be an independent National Strategy Commission, bringing together diplomatic, military, economic and informational expertise to preserve institutional memory and support integrated strategic planning across successive governments.

Conclusion

Democracies do not need to lose their democratic character in order to become more strategically effective.

Authoritarian systems maintain continuity through control, whereas democracies must maintain it through design.

Instead, the task is to create long-lasting institutions, such as an independent National Strategy Commission, that can sustain strategic memory across changing governments without consolidating authority or undermining accountability.

This requires achieving cross-party consensus on essential national goals and integrating diplomatic, military, economic, and informational tools from the outset, rather than improvising after victory.

Failure results in continued frustration and increasing demands for concentrated power.

In a period of limited conflict, success will be defined not just by battlefield successes, but also by long-term political effects.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

America Needs a New North Korea Strategy

North Korea is strategically closer to Russia and China than any time since the Korean War, while the U.S. does nothing to challenge the growing power of the Axis of Authoritarians (China, Russia, Iran, and North Korea). The irony is that North Korea has, since 1994, wanted a normal relationship with the U.S., yet the U.S. appears incapable of addressing the North Korean nuclear threat.

On July 19, 2026, North Korean Foreign Minister Choe Son Hui met with Russian President Vladimir Putin in Moscow and declared that North Korea “stands by Moscow until victory in the war with Ukraine is achieved. Ties with Russia are a strategic priority for Pyongyang.” I’ve worked with Ms. Choe, a fluent English speaker, from 2003 to 2016, and know she –and others – would prefer dialoguing with the U.S.

And from July 10 to 12, 2026, North Korean Premier Pak Thae Song was in Beijing meeting with Wang Huning, Chairman of the National Committee of the Chinese People’s Political Consultative Conference, the fourth highest member of the Politburo Bureau Standing Committee of the Chinese Communist Party, for the 65th anniversary of China’s defense treaty with North Korea – The Treaty of Friendship, Cooperation and Mutual Defense.

The visit of North Korean leader Kim Jong Un to Beijing in September 2025 to meet with Chinese President Xi Jinping and participate in the Victory Day parade with Mr. Xi and Mr. Putin, followed by the June 2026, visit of Mr. Xi to North Korea for a state visit are clear indicators that North Korea is working hard to improve relations with China, while maintaining a close military relationship with Russia.

Russia reportedly is asking for another 30,000 troops and ballistic missile launchers from North Korea. The additional North Korean troops would reinforce frontline operations, doubling previous deployment estimates. This, while North Korea prepares to transfer new ballistic missile launches to Russia. The deepening military cooperation with Russia, pursuant to the 2024 mutual defense pact between Russia and North Korea, is not only a growing threat to Ukraine but, also, to the nations in Asia within range of North Korean missiles.

I have written often in this column about Norea’s growing arsenal of nuclear weapons – over 100 by 2030 – and the sophistication of their ballistic missiles, especially the long-range missiles – Hwasong 15, 17,18,19 and 20 – all capable of targeting the U.S. and their progress with short-range missiles that can target South Korea and Japan. Recently, we talked about progress with nuclear-powered submarines, but we didn’t discuss the progress North Korea is making with establishing a nuclear triad – land, sea and air-based nuclear weapons. And with Russia’s assistance, this is achievable in the not-too-distant future.

What are we doing to address this real and expanding threat? We’re watching the Axis of Authoritarian States become more united and seemingly forgetting that since 1994 North Korea wanted a normal relationship with the U.S. (The Agreed Framework); in September 2005 with the Six Party Talks Joint Statement and the historic June 2018 Singapore Summit of President Donald Trump with Chairman Kim Jong Un. Since then, and after the failed February 2019 failed Hanoi Summit and the June 2019 symbolic DMZ meeting, there were no further substantive developments with North Korea.

Since 2020, our failed policy of “strategic Patience” kicked in and we’ve seen North Korea exponentially increase its arsenal of nuclear weapons and ballistic missiles, while embracing Russia with a Mutual Defense Treaty and military assistance to Russia for its invasion of and war with Ukraine.

It’s time for the U.S., with support from its allies in South Korea and Japan, to decide if we want a normal relationship with North Korea; a relationship that will weaken the Axis of Authoritarian States, or if we want to persist with a “do-nothing” policy toward North Korea.

And if we want to do something, that means de facto recognition of North Korea as a nuclear weapons state – a reality we can’t deny – and entering into negotiators with Pyongyang to get North Korea to stop building more nuclear weapons and ballistic missiles in exchange for the lifting of sanctions, economic development assistance and a path to normal bilateral relations.

It’s time to address the North Korean nuclear threat.

The author is the former Special Envoy for Six Party Talks negotiations with North Korea (2003-2006) and the former Associate Director of National Intelligence. All statements of fact, opinion or analysis expressed are those of the author and do not reflect the official positions or views of the U.S. government.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Cyber Fraud, Banks, and What America Can Do About It

Your phone buzzes with a text from your bank: “Did you authorize a $2,400 transfer? Reply NO to stop it.” You reply, and seconds later a calm “fraud agent” calls, knows your name and the last four digits of your card, and walks you through “securing” your money by moving it into an account under the criminal’s control. No password was stolen, no malware installed. You handed over the money yourself, because everything looked and sounded real.

This is the new face of bank fraud and business is booming. Behind these scams sit organized adversaries: nation-state actors who treat theft as state revenue, criminal gangs running industrial-scale scam operations, and hacktivists out to embarrass institutions increasingly armed with AI that makes their lies cheap, fast, and tailored to you.

The problem: scams have gone industrial

Banks have spent decades hardening their vaults and networks, so attackers shifted to the softest target: the customer. Rather than breaking in, they trick people into transferring funds themselves. This is “authorized push payment” fraud where the victim approves the payment and it is far harder to claw back than a stolen card number. To hear how a typical scam call actually unfolds, watch the FTC’s short imposter-scam explainer.

With the age of AI, three key forces have turbocharged these threats. Payments now move instantly and irreversibly, so money is gone before anyone notices. Decades of data breaches let criminals buy your name, address, and account details cheaply, making their scripts eerily accurate. And generative AI has industrialized deception where more than half of fraud is now estimated to involve AI. A criminal can clone a familiar or family voice from seconds of audio, write flawless phishing emails in any language, and even deepfake a bank officer on a video call.

The people behind it are not lone hackers in hoodies. They range from sanctioned nation-state groups that steal to fund their governments, to criminal syndicates running scam centers staffed by trafficked workers, to hacktivists attacking banks to make a political point. For them, fraud is a scalable business and it is outrunning the banks, telcos, and Big Tech.

The real-world cost

The damage is measured in real households. The Federal Trade Commission reports Americans lost roughly $16 billion to fraud of all kinds in 2025 the highest on record and about 25% more than the year before. Imposter scams alone accounted for $3.5 billion, nearly tripling since 2020, and the single most lucrative version is the fake bank-security alert that convinces people to “protect” their savings by moving them.

These losses fall unevenly. Americans aged 50 and older reported $4.3 billion in losses in 2025, often life-altering sums drained from retirement accounts. The official numbers are almost certainly a fraction of reality, since many victims never report out of shame. Beyond the dollars, the human cost is real emptied college funds, missed mortgage payments, and a corrosive loss of trust in the financial system people rely on every day. One Florida couple lost $42,000 of their savings this way watch how it happened. In fact, this happens so often that Hollywood created an action movie about it with the Bee Keeper.

A National Security issue

Fraud and scams are not just a nuisance but far more dangerous. Fraud and scams in the United States have escalated into a national security issue because they are no longer isolated consumer crimes. They are large‑scale, foreign‑run operations that drain billions of dollars from the U.S. economy and undermine public trust in financial and digital systems. Federal agencies increasingly link these schemes to transnational criminal organizations, some of which also engage in human trafficking, money laundering, and other activities that threaten national stability. The financial impact is massive, with losses rivaling major illicit industries, and the proceeds often flowing to adversarial nations or criminal networks abroad.

The rules already on the books

The U.S. is not starting from zero. Along with the growth of the early Internet, in 1999 the Gramm-Leach-Bliley Act went into effect and its Safeguards Rule in requiring banks to protect customer data, and guidance from the Federal Financial Institutions Examination Council (FFIEC) pushes them toward stronger, multi-factor login security. The Bank Secrecy Act and anti-money-laundering rules, enforced by the Treasury’s FinCEN, require banks to flag suspicious transactions — a key tool for tracing stolen funds. New York’s Department of Financial Services Part 500 cybersecurity rule has become a de facto national standard.

Regulators are also targeting the scams themselves. The FTC’s Impersonation Rule, in force since April 2024, lets the agency go after fraudsters who pose as businesses or government agencies; in its first stretch it produced more than $70 million in consumer refunds. Voluntary frameworks like the NIST Cybersecurity Framework give institutions a common playbook.

The gap is not the absence of rules it is that attackers move faster than rules can be written, and that liability for scam losses remains murky when a customer is tricked into approving the payment. So, with all these rules and regulations, why are scams and fraud occurring faster?

The innovators fighting back

A fast-growing wave of companies is using the same AI that empowers criminals to stop them.

· Feedzai builds real-time systems that score billions of transactions as they happen, spotting the subtle patterns of a scam in under a second.

· Alloy helps banks and fintechs verify who is really opening an account, choking off the synthetic and stolen identities fraudsters depend on.

· Arkose Labs specializes in blocking automated bot attacks and account takeovers, while SEON, Lexus Nexus, and Sumsub offer identity-verification and fraud-screening tools that smaller banks and startups can plug in affordably.

· Netcraft is a company which doesn’t only detect scams but does something about it. It is very good at “take downs” of scam networks.

· Others are racing to build deepfake and voice-clone detection to catch fakes that fool the human ear and eye. Others get creative: UK carrier Virgin Media O2 built “Daisy,” a lifelike AI “granny” that answers scam calls and keeps fraudsters rambling for up to 40 minutes to tie them up so they have no time for real victims. Watch “Daisy” turn the tables on scam groups.

What unites all these is adaptive defense models that learn daily, because last month’s fraud pattern is already obsolete. All these point solutions are modeled on Intellectual Property that slows sharing. This model is not working.

What America should do

As scams become more sophisticated, especially with AI‑driven impersonation, deepfakes, and automated fraud, their ability to destabilize institutions, exploit citizens, and weaken economic resilience has pushed policymakers and security experts to treat fraud not just as a consumer protection problem, but as a strategic threat to national security. Staying safe will take coordinated effort. Everyone has a role.

Lawmakers and regulators

Fraud and scam laws in the United States, the United Kingdom, and Australia share the same objective: to protect consumers and disrupting criminal activity but each country approaches the problem with a very different regulatory philosophy.

In the U.S., the system is fragmented and enforcement‑driven, with no mandatory reimbursement for most scam victims and a heavy reliance on agencies like the FTC, CFPB, and FBI to pursue wrongdoing after the fact. By contrast, the U.K. has built the world’s most proactive framework, requiring banks to reimburse victims of authorized push‑payment scams, enforcing account‑name verification through Confirmation of Payee, and placing clear accountability on financial institutions to prevent fraud before it occurs. Australia sits between the two models, adopting U.K.‑style protections while expanding responsibility beyond banks to include telcos and digital platforms through its emerging Scams Prevention Framework. While the U.K. emphasizes consumer protection and the U.S. emphasizes enforcement, Australia is moving toward a shared‑liability, cross‑industry approach that recognizes scams as a systemic risk requiring coordinated prevention across the entire digital ecosystem.

A typical scam today uses several pieces of technology working together to make the criminal look real. It often starts with:

1. the scammer creating a fake website that looks almost identical to a bank or delivery company. They buy a cheap web address from a service like GoDaddy and change just one letter so most people won’t notice the difference.

2. Then they setup email accounts on services like Microsoft & Gmail to send out massive emails.

3. They use AI tools to scrape millions of social media profiles from Facebook, Instagram, etc. to collect data about YOU.

4. They use tools that let them fake a phone number (telco), so when they call you, your phone shows the name of your bank or a government agency.

5. After that, they send out text messages to iPhone and Android users that look official, things like “Your account is locked” or “You have a package waiting.” The link in the text takes you to the fake website, where the scammer collects your login details. If you call the number instead, it goes to a call center where the scammer pretends to be a bank employee.

All of this: fake websites, spoofed phone numbers, and realistic text messages works together to trick people into believing they’re talking to a trusted company when they’re actually dealing with a criminal.

What should the Critical Infrastructure do?

In the U.S., we have failed because we have not worked together across these technologies at scale & at the speed of AI. Why? Because we (collectively) do not have the incentives or requirements to do so. For the CEOs of these companies, they do not want to spend money & resources which do not drive revenue. Period.

There are glimpses of hope. A working model already exists:

· We have the Financial Services Information Sharing and Analysis Center (FS‑ISAC) is a global, nonprofit organization that helps protect banks and other financial institutions from cyberattacks by enabling them to quickly share information about threats. It was created in 1999 (26 years!) to strengthen the safety and resilience of the financial system by collecting, analyzing, and distributing timely intelligence about cyber and physical risks so that member institutions can defend themselves and their customers more effectively. I am hopeful that they new CEO, Valerie Abend will drive more effective solutions.

· In 2026, eight major carriers: AT&T, Verizon, T-Mobile and others just launched the Communications Cybersecurity Information Sharing and Analysis Center (C2 ISAC), chaired by longtime cyber expert, AT&T security chief Rich Baich, to share real-time threat intelligence across competitors. Because most scams ride phone and text networks before they ever reach a bank, telecom and banking defenses should connect through the same kind of collective-defense sharing. But the C2 ISAC cannot do this alone.

· In 2025, the Global Anti‑Scam Alliance (GASA) was formed to bring together governments, financial institutions, technology companies, law‑enforcement agencies, and consumer groups to fight scams on a global scale. GASA acts like a global “anti‑scam task force,” uniting experts and institutions so people everywhere are better protected from online fraud.

These have proven to not operate effectively to get ahead of scams and fraud. We need a better way – mandates of sharing, legal risks support, cross ISAC/intel which is tailored/aware, good native ML & AI models (not rules), and others working at speed and context with more transparent sharing.

In the meantime,

What should consumers do?

Treat any unexpected “urgent” message about your money as a warning sign, not a command. Banks will never ask you to move funds to “protect” them. Hang up and call the number on the back of your card. Turn on multi-factor authentication and agree on a private “safe word” with family so a cloned voice can’t fake an emergency. Report scams to ReportFraud.ftc.gov, even unsuccessful attempts, because the data helps train good AI/ML models to protect everyone.

What should all companies do?

Adopt adaptive, AI-native detection rather than yesterday’s rules, and design apps that help customers pause before they act. Investors should back the firms building deepfake detection and identity verification, and banks should partner with them quickly instead of waiting years to build in-house.

Conclusion:

With fast innovation, fraud & scams will not disappear, but it can be better contained. The criminals have industrialized deception; the answer is to industrialize defense with smarter rules, sharper technology, and a public that knows the warning signs.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

When Hackers Get AI Co-Pilots: Frontier AI and the National Security Clock

Five intelligence services rarely speak with one voice. When they warn the window of vulnerability has narrowed to months, the real question is whether the defenders can move as fast as the threat.

Throughout my years in the intelligence world, I don’t recall a single instance in which the Five Eyes partners jointly issued a public warning, so when they do, the message lies in the act as much as the words. Intelligence agencies guard their assessments and share them sparingly, almost never in the open. So, when the United States, United Kingdom, Canada, Australia, and New Zealand jointly warned on June 22 that frontier AI models capable of serious cyber exploitation are only "months away" from broad availability, the unanimity was itself a clear message. "The timeline is not years, it is months," they wrote.

The warning the Five Eyes partners shared is specific. These are systems that let a non-expert coordinate a complex intrusion (work that until recently required a trained team fluent in reconnaissance, exploitation, and stealth). That capability is moving out of the hands of advanced nation states and into the reach of mid-tier criminal groups and other adversaries. As the barrier to a sophisticated operation fall, the target list grows, and the systems most exposed are the ones a country cannot do without hospitals, water and power utilities, community banks, ports, and the contractors that serve them.

There is one caveat to mention. Outside experts who examined the models argued they do not represent a wholly novel threat, and the agencies concede their core remedy is familiar: fix the basics, patch faster, control identity and access. The fundamentals still decide most outcomes. What has changed is speed and, with speed, potential volume. The vulnerability was always there, and AI simply finds it faster and puts that reach into more hands.

For national security planners, "months" is the word that should capture attention. Strategy assumes time, and much of the architecture protecting critical infrastructure was built for an era when a capable intrusion took a capable organization. AI collapses that assumption. A defensive posture written to last three years can be overtaken before its first review, and the slowest links (legacy systems and sluggish patching) are the points an adversary will reach first.

Washington has begun to respond. Executive Order 14409, signed June 2, is best read as the opening move in a national security framework for frontier AI. It directs the NSA and CISA to benchmark in classified settings when a model's cyber capabilities make it a "covered frontier model," and it asks developers to voluntarily give the government up to 30 days of access to such models before release. It stands up an AI cybersecurity clearinghouse — led by Treasury — to coordinate the discovery and patching of vulnerabilities, and it directs the Justice Department to prosecute those who turn AI against American computer systems. It also pushes to put defensive AI into the hands of the institutions least able to defend themselves: rural hospitals, community banks, and local utilities.

The order is also a move in a broader contest. Representative Andrew Garbarino, who chairs the House Homeland Security Committee, said the same week that China is "months, if not now weeks, away from achieving frontier AI capabilities comparable to those of the United States." Washington has already moved to restrict the export of a leading frontier model on national security grounds. Whoever fields these capabilities first, and whoever sets the terms for evaluating and controlling them, will shape the rules others must live by. That competition runs straight through the private companies that build the models and the critical infrastructure an adversary would target.

All of this points to the real test. If frontier AI can accelerate attacks, it can accelerate defense, and the side that equips its defenders faster holds an advantage. Programs that put defensive AI into the hands of critical-infrastructure operators, such as Anthropic's Project Glasswing and OpenAI's cyber-defense access effort, are early attempts to give defenders a head start in finding and fixing flaws before they are exploited. The harder problem is people. Models do not run themselves, and the expertise to direct them, in a utility control room or a hospital network, is scarce and unevenly spread across exactly the sectors most at risk.

This is where national security and the private sector stop being separate conversations. Most critical infrastructure is privately owned and operated, which means the front line of national defense now runs through companies whose first duty is to investors and shareholders. The operators that can name the AI systems they rely on, assume their adversaries now carry capable co-pilots, and test their defenses against machine-speed intrusion are the ones that will fare best.

All of this argues for a different compact between government and industry, grounded in shared purpose. Major developers, critical-sector operators, and the national security agencies need to engage early and honestly on the most dangerous capabilities, the way Executive Order 14409 suggests. And the country must invest in defensive AI and in the people who wield it, so the defenders of American systems keep pace with their attackers.

I spent decades in the world of intelligence, much of it managing risk where the cost of getting it wrong was measured in much more than money. The warning the Five Eyes issued this month is the kind that professionals will take seriously. The timeline is tight, and the targets are the systems a society runs on. Frontier AI will define the next era of national power, and the open question is whether the defenders get their co-pilots before the attackers’ finish deploying theirs.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

❌