
Aug 6, 2026 · 3h 18m
Mandia traces China’s cyber campaign from espionage to AI
#328 Kevin Mandia - The Man Who Exposed China's Military Hackers
The conversation connects nation-state hacking, critical-infrastructure risk, surveillance and artificial intelligence to the institutions and systems Americans rely on.
- 1China’s APT1 campaign showed how persistent nation-state espionage could target American companies and defense contractors.
- 2SolarWinds and Colonial Pipeline exposed different paths from cyber intrusion to organizational crisis and public disruption.
- 3AI will accelerate both vulnerability discovery and attacks, forcing defenders to build systems designed for machine-speed threats.
Don't miss
Mandia recounts how Mandiant’s investigation culminated in publicly identifying China’s PLA Unit 61398 through the APT1 report.
The brief
Kevin Mandia recounts a path from Pittsburgh and the Air Force to Mandiant, where forensic methods turned scattered intrusions into evidence of organized nation-state campaigns.
The APT1 report publicly tied a Chinese military unit to industrial espionage, showing how China’s cyber operation targeted American organizations at a scale individual companies struggled to withstand.
Mandia contrasts China, Russia, Iran and North Korea while examining SolarWinds, Colonial Pipeline, critical infrastructure and the ways attackers exploit trusted systems rather than simply break encryption.
The discussion broadens from surveillance and privacy to psychological warfare, where hacked emails, leaks and disinformation can weaken public trust without taking down a network.
Mandia’s new venture, Armadin, reflects his central forecast: AI will speed vulnerability discovery and automate more attacks, demanding defensive systems built specifically for AI-enabled threats.
Featuring
Listen to the full episode and explore every guest, topic, and moment on PodLume.

Kevin Mandia
Russian Federation
Google
Federal Bureau of Investigation
The New York Times