QTFY campaign forces U.S. cyber strategy shift

QTFY campaign forces U.S. cyber strategy shift

Estimated reading time: 5 minutes · Last updated:

The QTFY campaign, which Rich Kolko says dates to 2018, illustrates why U.S. cyber strategy is moving from a prevention-first posture toward detection, resilience and tighter public-private cooperation. Kolko, a retired FBI special agent and U.S. Navy commander who spoke on The Federal Drive with Terry Gerton, described persistent intrusions that embed in small networks and local systems and can sit for years before detection. He warned that those footholds give attackers an operational advantage against government agencies and critical services. The need to harden 16 critical infrastructure sectors and to build shared detection capabilities is now a central focus, as first reported by Federal News Network.

If that happens, if we can see an attack coming from China, there are entities in the U.S. government that can quickly put a stop to that,

Rich Kolko

Key takeaways

  • Campaign duration: Rich Kolko said the QTFY campaign dates back to 2018 and has operated for years before detection.
  • Operational risk: Kolko warned attackers embedded in local networks can gain advance access to government playbooks and potentially affect critical services.
  • Strategy shift: Federal cybersecurity emphasis is moving toward detection, resilience and stronger public-private partnerships involving FBI, NSA, DHS and other agencies.
  • Critical infrastructure: Kolko said there are 16 critical infrastructure sectors that the U.S. must prioritise for protection and continuity.

What the QTFY campaign looks like and why it matters

The intrusion campaign labelled QTFY has shown a consistent pattern: long-term, low-profile access to many different networks rather than obvious, noisy breaches. Rich Kolko described operators who embed themselves inside smaller systems — home machines, local businesses and less-protected networks — so their traffic does not trace cleanly back to an overseas origin. That persistence lets them accumulate operational intelligence over time, Kolko said, giving them advance notice of policies, testimony and planning that can advantage an adversary.

That stealth makes detection slow. Kolko pointed to the campaign’s multi-year run, which he dates to 2018, and argued that the practical consequence is a shift in federal priorities: agencies must not only try to block intrusions but also invest in faster detection, containment and the ability to operate while under attack.

Why detection and resilience are rising to the top

Kolko framed the problem as one of resource and scale: government entities lack the personnel and funding to find every vulnerability, so some intrusions will persist. From that starting point, he argues detection and continuity become primary defenses. Detection narrows dwell time — the interval an attacker has inside a network — and continuity planning ensures services keep running even when intrusions occur.

He also raised the post-quantum concern: encrypted data can be stolen now and decrypted later, so immediate breach prevention alone may not stop future exploitation. In practice, that means agencies and companies should adopt layered measures that combine faster telemetry and logging, agreed contingency playbooks, and investments in recovery so critical functions remain available during an incident.

How federal agencies and industry are changing how they work

Kolko described a practical shift in how government and private actors cooperate. Cyber task forces increasingly bring cleared company personnel into government spaces so the FBI, NSA, DHS and industry partners share intelligence in near real time. Those co‑located arrangements let defenders correlate signals and act more quickly than when information is siloed.

He credited that collaboration with improving defensive posture but stressed it is not a cure-all: attackers still often remain several steps ahead, and personnel shortages and pay differentials that draw staff to private firms reduce government capacity. The result is an emphasis on capability-building inside both public and private organisations rather than relying solely on external enforcement.

What organisations at all levels should prioritise now

Kolko advised organisations to balance spending across prevention, detection and recovery. If a CIO can buy only one capability, detection and the ability to respond fast will reduce overall harm from long-running intrusions. He noted that many smaller operators underinvest because they assume attacks will hit someone else, a gap that leaves entire sectors vulnerable.

Practically, the priorities Kolko outlined are shared threat intelligence with cleared partners, improved monitoring that reduces dwell time, and rehearsed continuity plans for critical services. He gave examples including government agencies such as NASA and the Federal Reserve as entities whose processes and planning could be undermined by the long-term access these campaigns provide to adversaries.

Targets and examples cited in the interview
Target type Examples named Why Kolko flagged them
Government agencies NASA; Department of Justice; Federal Reserve Attackers can view internal planning and testimony in advance
Critical infrastructure sectors Banking; water; energy; internet Embedding access could disrupt services during a conflict
Local systems and companies Home computers; small firms; municipal networks Used as footholds that mask origin and lengthen dwell time

Cases for and against the strategy shift

The case for

  • Stronger public-private partnerships and shared clearances speed threat intelligence sharing and joint responses.
  • Investing in detection and continuity shortens attacker dwell time and limits operational damage even when prevention fails.

The case against

  • Persistent intrusions that date back to 2018 show defenders still struggle to find long‑standing footholds.
  • Personnel shortfalls and private-sector pay differentials reduce government capacity to sustain the multi‑agency effort Kolko describes.

What to be careful about

  • Embedded access in small, distributed networks increases risk of unnoticed data exfiltration and future decryption.
  • If adversaries can affect multiple targets inside 16 critical infrastructure sectors, outages could cascade across services such as water or energy.
  • Slow detection increases the likelihood attackers collect sensitive operational intelligence before defenders act.

The bottom line

The QTFY campaign underlines a hard lesson: some adversary operations will persist despite improved defenses, and long dwell times magnify strategic harm. Rich Kolko’s account points to a practical recalibration — invest in faster detection, rehearse continuity for critical services, and expand trusted, cleared partnerships between government and industry. Those steps do not eliminate intrusion risk, but they reduce the operational payoff attackers gain from embedding in networks over years and strengthen the ability of agencies to keep key systems running during incidents.

What to watch

  • Watch for DOJ or CISA to publish technical findings or mitigation guidance related to the QTFY intrusions; no date has been set.
  • Watch for agencies to announce expanded co‑location or clearance arrangements with private companies to accelerate threat sharing; no date has been set.
  • Watch for post-incident continuity exercises or sector-specific playbooks that focus on the 16 critical infrastructure sectors; no date has been set.

Frequently asked questions

When did the QTFY campaign begin?

Rich Kolko said the campaign goes back to 2018; he described multi‑year, low-profile intrusions that often remained undetected for years.

Which sectors are most at risk from these persistent intrusions?

Kolko named government agencies such as NASA, the Department of Justice and the Federal Reserve and warned that attackers could target services across the 16 critical infrastructure sectors, including banking, water and energy.

How are federal agencies changing their approach?

Kolko described increased co-operation between FBI, NSA, DHS and private companies, with cleared industry staff working alongside government teams to share intelligence and speed detection.



Share:

Categories

Newest course every month

Advertise your offline course to a wider audience with our landing page.

You May Also Like

QTFY campaign dates to 2018 and has embedded in local networks, pushing U.S. agencies to shift cyber strategy toward detection,...
FBI cyber strategy shifts from defense to disruption, pairing operational intelligence with victim support and private-sector data sharing to stop
Easy-to-guess passwords are widespread: '123456' shows up nearly 210 million times; experts recommend blocking leaked passwords, MFA and passkeys.