In a recent piece, we made a case that most people find surprising: that the United States is not the passive punching bag it appears to be in the cybersecurity headlines, and that the reason you rarely hear about American offense is that a successful operation is, by design, one nobody ever learns about. A number of you wrote back with the same question — so what CAN we actually point to? Which operations are real, named, and on the record?
Fair question. So here is the catalogue: a tour of the offensive cyber operations conducted by the United States and its closest allies that have been officially acknowledged or solidly reported. Two honest caveats before we start, because they matter to how you read the whole thing. First, this list is the visible tip of a much larger iceberg — these are the operations that surfaced, for specific reasons, out of a body of work that is otherwise deliberately invisible. Second, we sort each entry carefully into what a government has actually admitted versus what has been reported by credible outlets citing officials. That distinction is the whole discipline of writing about this subject responsibly, and we hold to it. Nothing here is speculation dressed as fact.
This is not about politics, and it is not cheerleading. These operations span multiple administrations of both parties, and the capability keeps growing regardless of who holds office. It is simply the other half of a story you have only ever been shown one side of.
A quick map before the tour
Here is the whole catalogue at a glance, sorted by how firmly each is established. We will walk through them in turn.
| Operation | Who | Target | Status |
|---|---|---|---|
| Glowing Symphony / JTF-ARES | United States | ISIS propaganda network | Officially acknowledged |
| Hive takedown | United States + partners | Ransomware gang | Officially acknowledged |
| Operation Cronos | UK-led, US + 8 others | LockBit ransomware gang | Officially acknowledged |
| NCF campaign vs. Daesh | United Kingdom | ISIS online ops & drones | Officially acknowledged |
| NCF vaccine-disinfo op | United Kingdom | Russian disinformation | Officially acknowledged |
| Election defense ops | United States | Russian influence actors | Confirmed (2020) / reported (2018) |
| Iran missile-system strike | United States | IRGC targeting systems | Reported via officials |
| Stuxnet | US-Israeli (reported) | Iranian nuclear centrifuges | Never acknowledged |
Part one: the operations governments have admitted
Start with the firmest ground — operations a government has officially put its name to. There are fewer of these than of the reported kind, precisely because admission is rare, which makes each one significant.
Operation Glowing Symphony — the first one America admitted (2016)
This is the landmark, and it deserves the top spot for a reason beyond its scale: the documents describing it, later released under the Freedom of Information Act, represent the first time the U.S. government officially acknowledged conducting offensive cyber operations at all. Before this, American cyber offense was something everyone assumed and no one confirmed. Glowing Symphony ended that.
Launched on November 10, 2016, and executed by a dedicated unit called Joint Task Force ARES, the operation set out to dismantle ISIS’s online propaganda machine. Analysts had realized that the group’s media empire ran through a surprisingly small number of chokepoints — roughly ten key nodes. The task force gained administrator access to ISIS networks, then quietly seized control: they obtained the passwords to key administrator accounts, locked the group’s own propagandists out, changed the passwords, and deleted the material — battlefield videos, propaganda archives, the works. Academic research afterward showed a measurable, lasting drop in ISIS’s online output that lines up with the operation’s timing.
The declassified after-action reviews are candid about the friction, too, which is part of what makes them valuable: operators nearly ran out of storage space for all the data they were pulling from ISIS networks, and the targeting-approval process was slow because ISIS infrastructure sat in dozens of countries, including allied ones. Even the world’s premier cyber force, it turns out, fights paperwork. But the mission worked, and JTF-ARES became the template for later American cyber task forces.
The Hive takedown — “we hacked the hackers” (2023)
We covered this one in the previous piece, but it belongs in any catalogue. Hive was among the most prolific ransomware gangs on earth, having extorted more than $100 million from over 1,500 victims across 80-plus countries. Rather than simply seize its servers, the FBI infiltrated Hive’s own network and lived inside it, undetected, for roughly seven months — quietly stealing decryption keys and handing them to more than 300 victims under active attack, plus over a thousand past victims, sparing them an estimated $130 million in ransom demands. The Deputy Attorney General’s summary is the line that stuck: “using lawful means, we hacked the hackers.”
Operation Cronos — an allied gang-dismantling (2024)
Cronos is the best example on this list of allies operating as one, and notably it was not American-led — the United Kingdom’s National Crime Agency ran it, with the FBI and eight other countries’ agencies alongside. Together they dismantled LockBit, at the time the most active ransomware operation in the world: 34 servers seized, 14,000 rogue accounts taken down, 200 cryptocurrency wallets frozen, roughly 1,000 decryption keys recovered, indictments unsealed. The flourish that made it famous was psychological — rather than post a dull seizure notice, law enforcement kept LockBit’s own leak site running and turned it against the gang, using the criminals’ signature countdown-timer format to tease the release of their arrests and exposure. A gang that specialized in humiliating its victims got a taste of the treatment.
Britain’s campaign against Daesh — and the drones (2016-2018)
The United Kingdom has been unusually willing to talk about its offense, and its acknowledged campaign against ISIS — which the British call Daesh — is the standout. In a 2018 speech, the director of GCHQ, Britain’s signals-intelligence agency, revealed that GCHQ in partnership with the Ministry of Defence had run a major offensive cyber campaign against the group. He described it, in a striking phrase, as the first time the UK had “systematically and persistently degraded an adversary’s online efforts as part of a wider military campaign.”
The effects were concrete: blocked social media accounts, hacked computers, destroyed databases, and disrupted communications, to the point where — in the director’s words — there were stretches in 2017 when ISIS members found it almost impossible to spread their message online or trust their own publications. British officials later added an especially vivid detail: they used cyber techniques to interfere with ISIS’s drones, affecting how the drones operated to neutralize a battlefield threat to coalition forces. This campaign’s success is what led Britain to formally stand up its National Cyber Force.
Britain vs. vaccine disinformation (2020)
Here is one that shows how broad “offense” can be. During the pandemic, according to reporting later reflected in official acknowledgments of the National Cyber Force’s remit, British cyber operators moved against a Russian disinformation campaign that was trying to undermine confidence in the Oxford-AstraZeneca COVID-19 vaccine — including, reportedly, disrupting the operations and servers of the actors spreading the falsehoods, using tools similar to those deployed against ISIS. When GCHQ later confirmed the National Cyber Force’s work publicly, it stated plainly that the force had countered state disinformation campaigns and worked to reduce foreign interference in democratic elections. Offense here did not mean breaking things; it meant switching off a lie factory.
What part one has in common: notice the pattern in the operations governments are willing to admit. They are the ones with a clear, defensible villain — terrorists, ransomware gangs, disinformation networks — where announcing the win carries little cost and real benefit: reassuring the public, and warning the next adversary. The operations against peer nation-states, where admission would burn access and invite retaliation, stay in the dark. What you’re allowed to see is curated. The catalogue of admitted operations is, itself, a strategic choice.
Part two: the operations reported but not admitted
Now the murkier tier — operations that credible news organizations have reported in detail, citing officials, but that governments have not formally claimed. The reporting is strong; the official confirmation is partial or absent. We flag them as exactly that.
Defending the elections (2018 and 2020)
This one straddles the line, which is why it appears in both tiers of our map. Around the 2018 midterms, U.S. Cyber Command reportedly took direct action against the Internet Research Agency — the Russian troll farm from 2016 — including disrupting its internet access so it could not operate during the vote. That specific operation rests on strong reporting rather than a formal press release. But the broader effort was officially confirmed: the commander of Cyber Command told the Senate that ahead of the 2020 election, the command conducted more than two dozen operations to get ahead of foreign election threats. The elections ran without meaningful cyber disruption. You are asked to take the specific troll-farm strike on reporting, and the general campaign on the congressional record.
The Iran missile-system strike — cyber instead of missiles (2019)
In June 2019, after Iran shot down an American surveillance drone over the Strait of Hormuz, the United States prepared a conventional military strike in response — and then called it off. In its place, according to reporting from multiple major outlets citing U.S. officials, the president authorized U.S. Cyber Command to launch a retaliatory cyber strike instead, targeting computer systems used by Iran’s Islamic Revolutionary Guard Corps — reported variously as systems tied to missile and rocket launchers, and a database used to plan attacks on Gulf oil tankers.
What makes this one genuinely important is the strategic choice it reveals. A leader chose a cyber operation as a deliberate off-ramp from a shooting war — a way to impose a real cost and send a firm message without the casualties and escalation of a missile strike. It is one of the clearest public illustrations of how cyber capability gives decision-makers options that sit between doing nothing and dropping bombs. We note, in fairness, that Iranian officials disputed that the attack was successful, and that the operation has never been officially detailed on the record.
Stuxnet — the one that started it all (discovered 2010)
And the famous one, included here with the firmest caveat of all: it has never been officially acknowledged by any government, and its attribution to a joint U.S.-Israeli effort, while reported for well over a decade, remains unconfirmed. What is not in dispute is the code itself, which was discovered in 2010 and has been dissected publicly ever since. Stuxnet quietly sabotaged the centrifuges at an Iranian nuclear enrichment facility — making the machines tear themselves apart while telling their operators everything was fine. Its importance is foundational: it was the moment the world learned that software could reach out of the digital realm and physically destroy heavy industrial equipment. Every conversation about cyber weapons since has been held in Stuxnet’s shadow. It is, in a sense, the reason a catalogue like this one exists at all.
A word on the allies you don’t see named here: the closest allied cyber powers operate as a tight intelligence-sharing group, and several — Australia and Canada among them — have publicly acknowledged having offensive cyber capabilities and, in Australia’s case, using them against ISIS and cybercriminals. We have focused on the operations with the richest public record; the absence of a given country from this list reflects what has been disclosed, not what exists. As with everything in this subject, the published record is a floor, not a ceiling.
What the whole catalogue tells us
Step back from the individual entries and a few things come into focus. These operations are real, they are diverse — from wrecking centrifuges to jamming drones to robbing a ransomware gang of its own keys to switching off a disinformation network — and they are the acknowledged handful standing in for a vastly larger body of work that stays hidden. The West is not sitting still in cyberspace. It is extremely active. You simply see only the sliver that serves a purpose to reveal.
And there’s a thread here worth pulling for anyone who runs a business, which we’ll close on the same note as last time. Look again at the tools in this catalogue — the account takeovers, the infrastructure seizures, the code that breaks physical equipment. None of it stays the exclusive property of nation-states. It gets studied, copied, leaked, and commoditized, and it flows downhill. The single starkest example is one we’ve written about before: a powerful hacking tool built by the National Security Agency, stolen and leaked in 2017, was strapped into ransomware within weeks and used to hammer hospitals and businesses across roughly 150 countries. The capability at the top of this page becomes, within a year or two, the criminal kit pointed at the bottom of it.
That is why a small business owner in North Carolina has any reason to care what a task force did to ISIS’s servers in 2016. You are on the same river as all of this — downstream, but the same river. The techniques being pioneered at the summit today are the everyday threats arriving at your doorstep tomorrow. Understanding that the water flows in one direction is the first step to respecting the current. The fight in the headlines feels distant. It is closer than it looks.
Sources: National Security Archive (declassified USCYBERCOM documents on Operation Glowing Symphony / JTF-ARES); U.S. Department of Justice and FBI (Hive disruption, January 2023); UK National Crime Agency, Europol, and FBI (Operation Cronos / LockBit, February 2024); GCHQ / CyberUK remarks and UK National Cyber Force disclosures on operations against Daesh and disinformation; Senate Armed Services Committee testimony; Associated Press, The Washington Post, BBC, and others on the June 2019 Iran cyber strike; and more than a decade of public technical reporting on Stuxnet and the 2017 EternalBlue leak and WannaCry outbreak. Operations are labeled “acknowledged,” “reported,” or “never acknowledged” according to their public status; those not officially confirmed are presented as reported, not as established fact.













