France did something this month that most victims of cyber-espionage never manage. It did not merely say "Russia." It named the unit. APT28, operating out of GRU military intelligence, attributed by France's own agencies, and tied to two decades of intrusions into French targets: the 2015 wiping of TV5Monde, the 2017 election interference, a body tied to the 2024 Olympics, ministries, aerospace, research and think tanks. Naming and locating a specific military unit is a fundamentally different act than blaming a country, and it is worth understanding what it actually takes, because it is the whole point.
Attribution is the trophy that detection capital wins
You cannot name and locate a unit you can only vaguely detect. Attribution at that resolution is the output of deep, correlated, sustained detection intelligence, years of it, stitched across incidents that looked unrelated at the time: the same infrastructure reused, the same tradecraft, the same operational rhythm, seen again and again until a pattern becomes a fingerprint and a fingerprint becomes a name.
France's agencies, ANSSI and CERT-FR, could point at that unit because they had accumulated the detection capital to recognise the same hand across twenty years of otherwise disconnected events. That is not a lucky break or a convenient leak. It is a national capability compounding over time. This is what detection capital is ultimately for. Not only catching the attack in front of you, but eventually knowing whose it was, precisely enough to say so out loud and stand behind it.
Why saying the name in public is power
Naming a unit turns intelligence into a lever. Vague attribution, "a state-sponsored actor," is noise, and everyone knows it. "This unit, here, for twenty years" is a policy instrument. It supports sanctions, indictments and expulsions. It lets allies coordinate around shared indicators and joint advisories, the way the US has published its own detail on the same GRU activity. And it changes the calculus of a service that trades on deniability, because deniability is the product, and precise public attribution is what takes it off the shelf.
But you can only wield that instrument if your detection is good enough to survive scrutiny, because a wrong public attribution is worse than saying nothing at all. The confidence to name a unit in a diplomatic statement is downstream of years of quiet, rigorous detection work. The politics are the easy part. The seeing is the hard part.
The mirror image: the edge is where the twenty years happened
Here is the uncomfortable other half of the story. That unit did not last two decades through dazzling zero-days, although it used them, including the Outlook flaw CVE-2023-23397. It lasted by living where nobody looks: poorly supervised edge devices, webmail, forgotten appliances, quietly brute-forced and quietly held. Twenty years of access through the unwatched perimeter.
So the same detection capital that eventually named them is exactly what could have shortened those twenty years, if it had been pointed at the boring edge instead of only the shiny centre. Attribution is detection capital cashed out at the very end. Watching the edge is detection capital spent at the start. The adversary bets, correctly and for two decades, that most organisations will do neither, and will keep their best eyes on the systems that were never the way in.
What this means for the rest of us
Almost no organisation will ever publish an attribution, and none needs to. But both truths translate straight down from the nation-state to the enterprise.
One: your ability to know what happened, and whose it was, is a function of the detection intelligence you have accumulated, not the tool you bought last quarter. It is the same lesson a researcher proved recently in a single file, the structured, owned knowledge is the asset, and here it is at national scale.
Two: the adversary is in the place you are not watching. APT28 did not live in the SOC's dashboards. It lived in the edge device nobody owned. World-class defence is not more alerts on the monitored core. It is visibility over the unglamorous, unwatched edge where long intrusions actually live and wait.
Credit where it belongs: this is French cyber agencies doing patient, world-class work. Naming and locating a GRU unit in public, with the evidence to back it, is the hard and unglamorous end of this field, detection capital accumulated until it becomes something you can say out loud. The best detection work is measured in years, not dashboards.
You cannot name what you cannot see. France naming that unit after twenty years is a flex of detection capital most nations cannot match, and a quiet indictment of how long the unit survived by living where no one was looking. The two lessons are one coin. Build the detection intelligence to know your adversary by name, and point it at the edge where they actually live, or one day someone will be writing "for twenty years" about you.
