Three Hands, One Room
A private company, a police force, and a military reach into the same machines to run the same Disrupt Doctrine. None has to tell the others.
Part 5 of the Architectures of Cyber Power series. New here? Start with Part 1, Part 2, Part 3, and Part 4.
In Part 4, I described two allied cabinets writing themselves permission to break into other people’s computers, one year apart, each behind the slow burn of democratic process. Japan with its oversight committee, Germany with its first reading and a motion to ban the very thing the bill would allow. Tokyo enacted. Berlin is still arguing. I left you with two keys cut in two different shops, both fitting the same lock, and nobody keeping the ring they hang on.
The busiest operator in this whole story never went to either parliament. It has been breaking into criminal infrastructure for fifteen years, and last month it took down more than two hundred servers in one day. It is a software company. You are probably running its operating system right now. It calls Redmond, Washington home.
The Disrupt Doctrine I named in Part 4 (operating on a machine you do not own, and breaking it) is one act performed by three completely different kinds of actor. A private company. A law enforcement agency. A military. Each reaches through a different legal instrument, and none of them has ever been required to tell the others they were coming.
The warrant: law enforcement already went into your router
The policy fight over all of this is almost always framed as a question about foreign machines. Should the state be allowed to reach into an adversary’s systems? Meanwhile, with far less argument, the FBI has been reaching into our own machines for at least five years.
The instrument is Rule 41 of the Federal Rules of Criminal Procedure, the one that governs search warrants. It was amended in 2016 to drop the old geographic limit on a digital search when a device’s location is hidden, or when the device has been, in the rule’s antiseptic phrasing, “damaged without authorization.” That last clause is legalese for “the device has malware on it.” It is the hinge that lets a single warrant reach into a machine the government does not own.
In April 2021, a federal warrant let the FBI remotely pull malicious code off privately owned Microsoft Exchange servers (the machines that run corporate email) sitting inside US domestic businesses. Nobody asked the owners and nobody told them first. They woke up to find the government had already been inside and gone, like a housekeeper who climbs through the back window at 1AM, does the dishes you left soaking, and lets herself out. The only sign anyone came is a clean sink. In late 2023, another court-authorized operation deleted Chinese state malware, planted by a hacking group called Volt Typhoon, off hundreds of our home and small-office routers. Same move: reach into a private device the government does not own, pull the bad code out, close the door on the way out.
The same agency runs a coalition version. In March 2026, prosecutors out of the District of Alaska of all places ran a court-authorized disruption of a cluster of botnets (armies of hijacked internet-connected devices like smart TVs and over-engineered toasters) behind a record-breaking denial-of-service attack. More than three million machines in the swarm. They ran this disruption operation alongside police in Germany and Canada.
Whatever you think of all that, it happens here in the US on machines sitting in our closets and home offices. They don’t even buy us dinner first.
The civil suit: the private army that files a press release
The second actor is the one some people at the FBI quietly wish they could be.
On June 24, 2026, Microsoft’s Digital Crimes Unit, the company’s in-house team of takedown lawyers and investigators, dismantled the infrastructure behind two password-stealing malware families called StealC and Amadey. More than two hundred of the addresses the criminals used to control infected machines were knocked out in a single court-authorized action with thousands more seized around the world. A private company did that. Microsoft is comfortable in a courtroom, and they used this one to reach onto other continents with a civil complaint. The same basic legal instrument you would use to sue a contractor who cracked your foundation and skipped town.
The astonishing part is that it’s now totally routine. Microsoft has been running civil-process botnet takedowns since the Rustock operation in March 2011 when its lawyers walked into US data centers alongside federal marshals to unplug a spam machine. That was fifteen years ago. In the spring of 2011 I was a high school senior headed for the Naval Academy, far more interested in the Game of Thrones premiere with my boarding-school friends than in anything happening in class, let alone Redmond.
Two hundred domains in an afternoon barely registers for this team, and it reframes Part 4 entirely. When Japan enacts a law and Germany drafts one to give the state this infrastructure-disruption power, they are legislating their careful constitutional way toward a capability a software company has been exercising on a monthly cadence since 2011.
The state is trying to catch up to its own vendor.
One detail to hold onto: when Microsoft (or Google, AWS, etc) finishes one of these operations, the law requires it to notify nobody at all. The only time we ever hear about it is when their legal team assesses that it’s good marketing and even better for their stock price.
The military: the actor we expect to punch back
The third actor is the one Part 4 was about, and the only one that can start a war.
State active cyber defense, the Japanese and German kind, means intelligence services or a military reaching onto foreign systems. Aim it at the wrong server in the wrong country and you have committed an act of aggression against another state. Tokyo built an oversight committee to hold that authority. Berlin is still fighting about the Trennungsgebot (the constitutional wall between its police and its spies) to work out who is even allowed to hold the authority. Washington skipped all of that. We have run this doctrine longer than anyone and written almost none of it into law because military and intelligence authority already exist and don’t require a public vote.
So, three actors. A police force operating under a warrant; a software company operating under a civil complaint; a military operating under authorities most of us have never read. These are genuinely different risks, and most of the people who flatten them together, policymakers especially, don’t actually understand the difference. A civil takedown of a criminal botnet is a different animal from a military strike on a rival’s power grid.
All three now travel under one word: Disrupt. And that word is doing quiet, dangerous work, sanding the edge off the difference between a police takedown and an offensive military operation, until the only thing separating them is which lawyer signed which order.
In March 2026, Google stood up a dedicated threat disruption unit and its executives went almost immediately to the microphones to explain that the unit is not offensive, that pulling infrastructure out from under hackers is defensive because it impedes their forward operations onto our systems. They may well be right. They also rehearsed and delivered that denial before anyone made an accusation, which tells you everything you need to know. The line is blurry-to-nonexistent.
Everybody was following the rules
Take any one of these actors alone and they make perfect rational sense.
The old passive cybersecurity posture has failed on its own terms: adversaries live inside infrastructure that defenders can see perfectly well and are not allowed to touch. Routine disruption is the only thing that has ever made those adversaries pay for anything. Operation Endgame, the big multinational takedown in May 2024, put a dozen countries through more than a hundred servers in a week, and it worked. The Microsoft cadence works. Democracies are bolting on oversight as they go, from Japan’s committee to the Die Linke motion in Germany.
Every one of those defenses rests on the same foundation: each actor, evaluated on its own, is behaving lawfully and competently. Which is true. It is also how the wreck happens.
A system in which every hand is individually accountable, and no hand is accountable to any other hand, produces collisions that no individual audit will ever catch.
In June 2013, Microsoft ran Operation b54, a takedown against a botnet called Citadel. It seized about four thousand domains. Roughly a thousand of them were already sinkholed by security researchers, which means the researchers had quietly taken over those addresses themselves so that infected computers would phone home to them instead of to the criminals. This allowed the good guys to count the victims and preemptively warn the world. Three hundred of those domains belonged to Roman Hüssy, a Swiss researcher who runs a tracking outfit called abuse.ch, which for most of its life has essentially been Hüssy and some servers.
Microsoft took his infrastructure. It siphoned his data. It pushed configuration files onto infected machines whose owners had not consented to that either. And it still missed a large share of the actual malicious command servers it had been aiming at.
Every step of that was lawful. Microsoft had its court order, the researchers had their sinkholes, and nobody broke a rule because there was no rule to break.
After an earlier mix-up during the ZeuS takedowns two years before, Hüssy had built a sinkhole registry. A non-public list maintained for law enforcement and security organizations so that anyone about to seize a domain could check whether one of the good guys was already sitting on it.
Microsoft did not check the list.
What the list was for
Nobody in that Microsoft story was reckless, or malicious, or wrong. Microsoft had a judge’s signature and a botnet to kill. Hüssy had a sinkhole to help the good guys and a deconfliction list. The largest software company on earth drove straight over a Swiss researcher’s servers, and the reason is not that anyone behaved badly.
The reason is that checking the list was optional.
That was one actor running the Disrupt Doctrine alone thirteen years ago before any of this became routine. There are three kinds of hand in the room now, and the newest of them is being written into law this summer. A few weeks ago, a US Senator introduced a bill that would let the Pentagon hire a private company to break into machines on its behalf. The reaction was immediate and loud, and most of it used the word privateer.
Because of my time at Cyber Command running offensive operations, I read the bill expecting to hate it. What I actually read made me realize that Microsoft, and Google, and the FBI, and our international partners have all been running with scissors in the dark.
Part 6 next week.
If you enjoy A Discipline of Seeing, it would mean the world to me if you shared it with others. Please use the button below to send my Substack to someone who might find my work interesting. Thanks!
— Brandon


