Red Kraken: The Coming Age of Agentic Cyber Strategy

The month of July saw two harbingers of a new age of cyber strategy. OpenAI revealed that models undergoing a cyber evaluation had found internet access, combined stolen credentials and previous unknown vulnerabilities, and compromised popular online AI community Hugging Face in order to accomplish its original test objective. Just one day later, Xi Jinping gave a landmark speech casting Beijing as the leader of a new global AI order. The People’s Republic of China (PRC), the world’s most prolific state-based hacker, just declared its intentions to dominate the United States in the AI race. Given how rapidly AI-enabled cyber threats are evolving, these harbingers suggest a need to better understand how to augment U.S. cyber defenses.

To that end, on July 21, CSIS led a tabletop exercise with members of the House Committee on Homeland Security and the House Select Committee on Strategic Competition with the Chinese Communist Party. A bipartisan group played Washington. Red Kraken, a custom agent trained on Chinese doctrine and more than 150 documented PRC cyber operations, played Beijing. The scenario began in summer 2027 during a crisis over Taiwan. The People’s Liberation Army (PLA) conducted its largest Joint Sword exercise, effectively quarantining the island, while U.S. intelligence detected preparations for cyberattacks against U.S. transportation networks needed for mobilization. Beijing sought to move against Taiwan while delaying U.S. deployment and creating domestic political pressure for the U.S. administration.

The game forced each side to allocate finite resources, represented by tokens, across 10 attack surfaces. Five were traditional targets: ports, maritime awareness, freight rail, airports, and roads. The other five addressed the emerging AI layer: credential targeting, misinformation, sensor manipulation, logistics optimization, and prompt injection. These latter elements are increasingly running critical transportation infrastructure and would be a tempting target for cyberattack. One side “won” the move if it had three more tokens on an attack surface than the other side.

In the first move, the U.S. team set up its defenses, spreading them between traditional infrastructure and emerging AI vulnerabilities. In response, Red Kraken concentrated its attacks on West Coast ports. China produced port disruptions lasting roughly three to five days, while rail and aviation continued operating. The pattern recalled PRC-backed cyber actor Volt Typhoon, whose persistent access to communications, energy, transportation, and water systems was assessed as preparation for disruption during a crisis.

A three-day disruption can matter when forces, munitions, and supplies must move from installations to ports. Congestion at a few terminals can ripple into trucking, rail schedules, warehouses, and military contracts. It can consume senior attention while leaders determine whether Beijing is signaling, preparing for war, or beginning an attack. The payoff comes from delay and uncertainty at the moment when Washington must decide and mobilize. Red Kraken’s theory of victory was therefore measured less by permanent damage than by the time China could buy while the United States brought port operations back online and untangled logistics networks.

In the second move, the U.S. team protected major transportation nodes but left key commercial services exposed. Red Kraken adapted. Drawing on the U.S. move and training data (i.e., past PRC-linked cyber incidents; PLA doctrine; studies on cyber strategy, including the CSIS Cyber Playbook series; and an intelligence agent to predict U.S. moves), it returned to attacking ports while opening campaigns against logistics software and the information technology services connecting shippers, carriers, terminals, and government customers. The AI agent playing the PRC focused on disrupting contracted logistics on which the military depends. The move has precedent in real-world Chinese cyber activity: Microsoft reported in 2025 that PRC-sponsored espionage group Silk Typhoon had attempted to penetrate IT supply chain firms, remote management tools, and cloud applications, using stolen credentials to reach downstream customers.

In the third move, the U.S. side continued to defend a broad attack surface, and the Red Kraken agent responded by attacking undefended AI-enabled logistics software, including the data and workflows used to forecast demand, schedule cargo, and route scarce capacity. In other words, the adversary shifted from directly disrupting systems to corrupting the information used for decisions. Red Kraken went after training data, model inputs, vendor connections, API keys, workflow permissions, and human approval processes.

The exercise revealed a theory of cyber coercion suited to a Taiwan crisis. Beijing can combine persistent access, selective disruption, and data manipulation to slow U.S. mobilization while preserving ambiguity. An adaptive agent also made the game more realistic and more dynamic: Each defensive choice revealed priorities, allowing the attacker to move toward underprotected dependencies.

What Congress Should Do

Congress should first incentivize agent-driven gaming across the Cybersecurity and Infrastructure Security Agency (CISA), the intelligence community, the Department of War, and transportation agencies through oversight and additional funding. Properly trained agents can test alternative PRC, Russian, and Iranian campaigns and expose assumptions.

Congress should also pass legislation that will strengthen the connective tissue between federal warning and local defense. The Cybersecurity Information Sharing Act needs durable reauthorization rather than recurring short-term extensions, which have become increasingly common. The Guaranteeing Universal Access to Cybersecurity Act, introduced in June 2026, seeks to boost federal funding and restore the Multi-State Information Sharing and Analysis Center. The PILLAR Act would extend state and local cybersecurity grants through FY 2035, which could include matching incentives for ports and transportation authorities that would directly address issues that emerged during the tabletop exercise.

Urgent Priorities for the Executive Branch

Policy elements should use these new resources and authorities to lean into agentic gaming. In-depth exercises should play with variables like warning time, attack sequencing, private sector cooperation, and escalation risk to judge how an adversary is likely to respond. The wargame demonstrated how effective a trained agent can be at mimicking Beijing; the same approach could apply to Tehran, Moscow, Pyongyang, or nonstate actors.

The U.S. intelligence community should increase efforts to understand how U.S. adversaries are using AI. The advent of capable, scalable AI models like Mythos reinforces how necessary early warning of adversary capabilities will be. The intelligence community needs extensive indications and warning lists to track adversary adoption of AI systems, and it needs experts on AI in-house or a phone call away to help understand the implications of those developments.

Policy must also protect the logistics stack, not only the facility. CISA and sector risk management agencies should work with the Department of War to map the commercial software, cloud providers, managed services, and AI systems supporting military mobilization. Federal contracts and grants should require phishing-resistant authentication, data lineage, immutable backups, tested model rollback, constrained agent permissions, and manual continuity procedures.

The Coming Race

Cyber coercion is a key component of modern statecraft that will only accelerate with the introduction of AI agents into hacker tool kits. The only way to stay ahead of the threat is to model it, identifying potential attack surfaces and vulnerabilities faster than authoritarian states like the PRC can exploit them. That will require new approaches to policy research. Congress should work with nonpartisan think tanks like CSIS and use AI-enabled games as legislative test ranges. A bill’s relevant provisions should be tested against a capable red agent in the drafting process, and the executive branch should continue to test new authorities against a red agent during implementation. That practice would move cyber policy beyond reacting to the last intrusion and instead anticipate how an adaptive adversary might act in the future.

Benjamin Jensen is director of the Futures Lab and senior fellow in the Defense and Security Department at the Center for Strategic and International Studies (CSIS) in Washington, D.C. Emily Harding is director of the Intelligence, National Security, and Technology Program and vice president of the Defense and Security Department at CSIS.

Image
Benjamin Jensen
Director, Futures Lab and Senior Fellow, Defense and Security Department
Image
Emily Harding
Vice President, Defense and Security Department; Director, Intelligence, National Security, and Technology Program