Category Archives: Energy

Thiel and Musk “Colonize Greenland” Project Started

The thing about reading African history is that when you hear Peter Thiel or Elon Musk talk about their ideal “colony” it sounds just like a Rhodesia fever dream. Musk was raised in apartheid Pretoria. Thiel was born in Frankfurt and partly raised in apartheid-administered South West Africa. The documented apartheid enthusiast in this story is Musk’s grandfather Joshua Haldeman, who moved his family from Canada to Pretoria in 1950 to live under the newly elected National Party government and praised South Africa as the leader of “White Christian Civilization.” This is the white nationalist nonsense of their grandparents. Heidi Beirich of the Southern Poverty Law Center described the revival to the New York Times in April 2018.

All the talk right now among people in the alt-right and the broader white supremacist movement is about the need for a white ethno-state. And when you praise Rhodesia, in this context, what you’re praising is violence to that end.

Now that their network staffs the American federal government, with Thiel protege JD Vance in the vice presidency, Thiel’s Founders Fund co-founder Ken Howery in the Copenhagen embassy, and David Sacks running AI policy, the “colony” plan just became a taxpayer-funded project called “Colonize Greenland”.

Yes, I know Musk wears “Occupy Mars” shirts, despite announcing in April 2016 that SpaceX would land a Dragon capsule on Mars as soon as 2018, a mission cancelled the following year.

Source: Twitter

Yes, I know “Occupy Mars” really means find a territory without laws to create a white nationalist enclave, not unlike Swakopmund, the former German colonial town in South African-occupied Namibia where Peter Thiel spent part of his boyhood while his father worked as an engineer on the Rossing uranium mine under apartheid labor rules. Swakopmund held a concentration camp during the 1904 to 1908 genocide of the Herero and Nama, and its German community was still known for celebrating Hitler’s birthday and giving Hitler salutes when the Thiels arrived.

On 20 April 1989 (Hitler’s 100th birthday) the Nazi flag was flown in Swakopmund (Woermannhaus Tower, at the corner of Bismarck and Kaiser Wilhelm), twelve years after the Thiels fled approaching Black majority rule for a white flight enclave in California.

Fast-forward to now and a one-year-old Texas SPAC has landed its drilling containers on the East Greenland coast without permission, after falsely telling a village meeting it had approval, as if it has landed on Mars. Its chairman is a serial SPAC promoter with over ten shell companies behind him. Its budget is $60 million for what is now a single well. To put this in perspective, it’s in a basin where Cairn Energy drilled eight wells in 2010 and 2011, spent over a billion dollars, and found nothing commercial. And its media strategy is a Dr. Phil documentary.

In other words, this has absolutely nothing to do with oil.

Greenland is the new Mars for the white nationalists. The oil story is just a retail tranche of a much older propaganda circuit: the continent as a single engineered resource unit, run by experts and capital instead of voters. “Technocracy Inc.” drew that map in the 1930s and called it the Technate of America. It included Greenland.

Keep in mind how much it matters that Musk’s grandfather led the movement in Canada until his 1940 arrest. Thiel wrote in 2009 that he no longer believed democracy and freedom were compatible. Their people now hold the Greenland portfolio and it’s all about “colonization”.

Player Position Technocracy Aim
Peter Thiel Founders Fund; backer of Praxis and seasteading Exit from democracy; declared it incompatible with freedom in 2009; sovereignty for capital
Elon Musk Grandson of Joshua Haldeman, Technocracy Inc. leader in Canada, arrested 1940 The Technate inheritance; engineered governance from DOGE to a Mars city he calls Terminus
Ken Howery Co-founded Founders Fund with Thiel; US Ambassador to Denmark, holding the Greenland portfolio Reported by Reuters to take the Greenland “freedom city” seriously while leading acquisition talks
Dryden Brown Praxis co-founder, Thiel-backed network state venture Flew to Greenland to buy it in November 2024; pitched a “mythical city in the north”; Praxis posted “According to plan” when Howery was named
Marc Andreessen, Joe Lonsdale Venture capital, DOGE advisers Reported backers of the freedom city; Lonsdale called for “expanding our country to Greenland”
Larry Swets Chairman, Greenland Energy (GLND); ten-plus SPACs sponsored The retail tranche: a $215 million Nasdaq listing sold on a $1 trillion claim from reprocessed legacy seismic
Jeff Landry Louisiana governor, Trump’s Greenland envoy Promises oil pumping next year, a physical impossibility on any Arctic timeline, because the promise is the product

The connections run through two men.

  1. Howery co-founded Founders Fund with Thiel and now sits in the embassy that governs American interests in Greenland. Thiel backs Praxis, whose founder tried to buy the island and celebrated Howery’s appointment as part of the plan.
  2. Musk carries the Technate by blood and by conduct: his grandfather mapped Greenland into an expert-ruled superstate ninety years ago, and the grandson built the unaccountable efficiency directorate that treats elections as legacy code.

The SPAC, the freedom city, and the missile defense basing are three products written against one underlying asset, which is valued more for what it lacks than what it has: only 57,000 people on 2.1 million square kilometers, and sovereignty fractured three ways between Nuuk, Copenhagen, and Washington.

It’s all just “terra nullius“.

Everyone keeps asking what is the economic or military justification, what’s under the ice or in the geographic vicinity. Wrong questions. It’s a trick.

White nationalist Rhodesian soldiers wore “blackface” paint to terrorize the public while claiming to be the good guys

The asset is the absence of voters. It’s the absence of laws. It’s the suitability for repopulating the white race, the Rhodesian fantasy Thiel and Musk were raised on.

Admitting the Elephantine Void Between Kinetic and Cyber Threats

Dr. Stuxlove, my presentation at BSidesSF on February 15, 2011, placed Stuxnet within a documented lineage of control-system compromises. Was Stuxnet the “First”? followed in 2015 with an incident list back to 1992 and a study of how the press likes to manufacture firsts and seconds.

Today I was asked about a threat-intelligence vision for physical and hybrid attacks together. Good question! While we record anecdotes and press coverage easily as qualitative points, the structured qualitative incident data still remains scarce. MITRE ATT&CK offers us only the high level T1200, Hardware Additions for physical entry, with T1195, Supply Chain Compromise next door and a separate ATT&CK for ICS matrix covering cyber operations that produce physical effect, while kinetic acts stay outside every matrix. That reveals an old structure we need to update.

How many sides to an elephant?

The phrase “physical and hybrid” is like answering trunk and tail when asked what’s filling up the room we are in.

One end is all about what’s getting inside hardware: implants, additions, supply-chain access. ATT&CK treats these as an entry vector because ATT&CK models adversary behavior inside networks that ride on, but especially terminate somewhere in, the physical. Kinetic acts thus get framed outside its scope, which explains the single technique for entry by hardware. The ICS matrix is on the extreme end, as it only records what a compromise does to a physical process and kinetic tools aren’t mentioned.

The other end is the kinetic field: severed cables, damaged pipelines, attacked substations, drone incursions, arson. Conflict-event and hybrid-threat researchers talk about this as its own discipline. Remember the pipeline blast threads? I once met with a White House official who brushed me aside when I suggested the PG&E San Bruno deadly blast is a natsec concern that cyber crosses with. Shortest meeting ever.

Each field sits at the end of a much more interesting whole picture that we should be putting back together. A cross-domain incident falls naturally between them.

Provenance isn’t always in Provence

Honestly, we benefit most by fleshing out the middle so that we have one to talk about comfortably. Reporting on verified infrastructure attacks carries the kind of accuracy that helps deflate political fear mongering thriving in a middle void.

Vulkangruppe attacks showing Russian indicators across fifteen years without a single conviction? Who does that void serve? Kommando Angry Birds fitting the Russian paid-recruitment template the BKA, BND, BfV, and BAMAD jointly warned about? The evidence helps a lot, but apparently the void helps someone even more.

The Tehama-Colusa canal case ended in dismissal. The 2008 BTC Turkey pipeline explosion rests on single sourcing. The 1982 Trans-Siberian pipeline story rests on one memoir. Maroochy Shire in 2000 predates Stuxnet by a decade and was prosecuted. The verified record is smaller and older than the vastly increasing reported one. But the hard facts live in blog posts like this one and engineering reports rather than proper threat research tables. Vendors and the press prefer the loose record because they hunt firsts and seconds as “news”.

Today a thing happened again, which we have seen before and could have prevented, doesn’t get the attention it deserves.

Ingredients

Existing databases each hold a piece of the whole picture. Assembling them is the practical path to a working dataset.

EuRepoC is a free European academic database of cyber incidents. It starts at 2000, codes each incident across roughly sixty fields, and runs separate trackers for critical infrastructure and for attribution. Use it for the cyber side and for the overlap where cyber operations touch physical infrastructure.

The Soufan Center report on Russian hybrid tactics carries an incident list covering 2022 through 2025. Each entry names the incident, the country, the target type, and a confidence level for the attribution. Use it for the recent kinetic and hybrid record in Europe.

OE-417 is the disturbance report US utilities must file with the Department of Energy. The filings go back to 2000 and include a category for physical attack. Use it for structured data on attacks against the US grid, the one infrastructure sector with mandatory public reporting.

That leaves the giant void.

Triad of Encoding

Incident analysis should record three separate facts: who was there, who did the damage, and who gave the order. Call them presence, attribution, and tasking. Each rests on different evidence, and each deserves its own confidence rating.

Presence is who was at the scene. The Baltic record shows us Chinese-flagged or Chinese-owned vessels over repeated cable breaks: Newnew Polar Bear crossed the Balticconnector and two cables in 2023, Yi Peng 3 dragged across C-Lion1 and the Sweden-Lithuania link in 2024, and comparable incidents followed off Taiwan in early 2025. Ship tracks prove the presence. They prove only presence, but that’s the point.

Attribution is who caused the damage. Western investigators treat the hulls as flags of convenience and pursue Russian indicators, while Beijing declined to cooperate with the Balticconnector inquiry and every Baltic case remains open, leaving the void.

Tasking is who ordered the operation. No Baltic case seems to be getting close. I’ve argued a few times we have some clear Chinese indicators yet seen almost zero interest in public pursuit. Talk about void.

Merging the three into a single actor field turns a database into a story lacking the support it deserves. A ship at the scene becomes “China cut the cable” begging what evidence lands. The merged field also overstates the cases where only presence exists, and it understates the cases where tasking evidence exists but the execution was outsourced, a leased hull, a paid recruit, a contractor. Downstream this gets worse when a policy maker cites the weak field as a finding, a vendor report cites the policy maker, and the original evidence base, one AIS track, goes unverified. The Soufan and EuRepoC designs avoid the triad risk because they record confidence per variable, a leg of a table instead of the whole thing. Keeping them separate while connected means something like high confidence on presence, moderate on attribution, and none on tasking.

The physical table needs the same separation. Bloomberg’s 2018 Supermicro report is still unverified, denied by everyone involved, and instructive for exactly this reason: it merged a hardware claim, an actor claim, and a tasking claim into one. Then the hardware claim was weak and it made a decade of serious supply-chain concern look unsteady. The documented Chinese activity is different in kind: supply-chain access and pre-positioning inside operational technology. My old friends over at Dragos tracked it as VOLTZITE, overlapping the group others call Volt Typhoon, living inside critical-infrastructure OT. Planning and execution get their own columns. A group pre sabotage is NOT post sabotage, and the database has to know what time it is.

I’m old enough to remember hacking critical infrastructure in the 1990s by compromising Cisco routers at mass scale. The pre-2000 layer of ICS and infrastructure incidents, across sectors and across borders, still remains old timer lore instead of a proper ledger. Meanwhile, we have these resources:

Resource Access Coverage
Hybrid CoE Open Research publications and the Hybrid CoE and EU-JRC conceptual model, the closest existing document to a shared hybrid-threat vocabulary
The Soufan Center, Russian Hybrid Tactics in Europe 2022-2025 Open Incident-level dataset, 2022-2025, attribution-confidence coded
EuRepoC Open Cyber incidents from 2000, roughly sixty variables, critical-infrastructure and attribution trackers
DOE OE-417 annual summaries Open US grid disturbances including physical attacks, archived to 2000
PNNL event-correlated outage dataset Open OE-417 joined to EAGLE-I county-level outage data on OEDI
Michael Mabee’s OE-417 consolidation Open The DOE summaries cleaned into a single CSV
ACLED Open Political-violence and sabotage event data, codeable for kinetic incidents
GDELT Open Global event database, broad and noisy, minable for physical incidents
Global Terrorism Database (START) Open Over 200,000 terrorist attacks worldwide from 1970, more than 100 coded variables including infrastructure target types, coverage through 2020, access by request
ICPC Open Submarine cable protection, infrastructure and international-law reference
TeleGeography Submarine Cable Map Open The geography under the cable-cut attribution work
NATO StratCom COE Open The influence and information side of the hybrid picture
NERC E-ISAC Member Grid physical-security reporting
Janes Paid The strongest structured coverage of the kinetic and military-hybrid side
Recorded Future, Geopolitical Intelligence Paid Facility and physical-threat monitoring in real time
Dragos (Accenture majority stake, June 2026) Paid OT and ICS, where cyber produces physical effect
Nozomi Networks Paid OT and ICS, where cyber produces physical effect
Claroty Paid OT and ICS, where cyber produces physical effect
Control Risks Paid Geopolitical and physical risk with incident feeds
Crisis24 Paid Geopolitical and physical risk with incident feeds
S-RM Paid Geopolitical and physical risk with incident feeds
Sibylline Paid Geopolitical and physical risk with incident feeds
Eclypsium Paid Firmware and hardware integrity, the T1200 corner directly
Interos Paid Supply-chain exposure mapping
Fortress Information Security Paid Supply-chain exposure mapping

Now ask yourself where is the middle dataset. A hybrid operation is distinct in how it works both ends of the attribution threshold, begging a path between them.

You can run it like this: pick a hull that implicates a third country, a flag that hands jurisdiction to an uncooperative state, damage that reads as plausible accident, a crew that can be abandoned. Each variable of the triad gets degraded on purpose. Presence is arranged to point sideways, attribution is split across jurisdictions that struggle to share a case file, and tasking stays offshore behind a broker and a payment. The operation succeeds when the incident, inverse to any good history book, leaves the reader confused about “both sides”.

That inverts the usual data problem. An incident we label cleanly, with an actor confirmed and tasking established, failed as an operation, means our more sparse database is the one to measure adversary success. The empty cells become the evidence, our findings. A record that says presence high, attribution open, tasking unknown documents the adversary’s investment in staying unresolved, and a column counting years-unresolved per incident would measure the campaign better than any actor label.

Waiting for resolution before recording anything means waiting for the adversary to justify being recorded, which becomes ennoblement of those “unseen”. The middle path records the incident at the confidence the evidence supports and lets the confidence describe what’s outside the middle.

Classification does the same work domestically in Germany, for example, let alone Italy. It drops politically accelerant violence into a bucket of simple crime to look away from when the victims are migrants. German state interior ministries registered 2,558 politically motivated attacks on asylum shelters between 2015 and 2018, producing 206 convictions. In other words, the German infrastructure treats a burning federal housing center that displaces people as a routine police crime report. Burning critical infrastructure that displaces people, however, gets a false-flag report of domestic terror, bemoaning another year of dead-ends.

The cables are exposed, easily damaged, and the ambiguity haunts investigators: a disposable hull switching flags, a disputed captain, and a Swedish prosecutor refused permission to board the Yi Peng 3. The Chinese team ran the inspection instead with Europeans only as observers. Meanwhile the evidence has changed character.

Cyber threat intelligence is coders scripting quantitative telemetry, machine-generated and repeatable with integrity checks. Physical and hybrid evidence instead is qualitative testimony from interested sources, with forgery assumed on every record. The discipline required to handle the latter is called a historical method. The security field is simply, predictably lacking in that database because it is short of trained historians.

Berlin Mayor Drops Out, Sorry for “Mess” of Russia Burning the City

The longest blackout in Berlin, since Hitler killed himself, was last January as temperatures hovered below freezing. The Russian-directed “Vulkan” arson attack on a cable bridge in the city’s southwest Lichterfelde stopped electricity to 45,000 households and 2,200 businesses, with some 100,000 residents left without heat.

The Mayor basically played tennis from the start of crisis, with another member of government and his partner Katharina Günther-Wünsch, claiming he needed to avoid work stress. And he delayed making visits to the people suffering. That performance predictably has negatively affected his ability to lead the government, although it’s still unclear if he understands why.

Berlin Mayor Kai Wegner with Education Senator Katharina Günther-Wünsch in the Berlin House of Representatives. The two spent January 3 on a tennis court while 100,000 of their constituents lost heat in freezing temperatures.

Now Kai Wegner has abandoned his candidacy for the September 20 election, because his own party has demanded he go further and resign the office itself.

Wegner conceded to communication errors in his handling of the major electricity outages after sabotage in Berlin a few months ago. He had come under fire for repeatedly misrepresenting his personal role in the crisis management process.

Reports of him playing tennis amid the blackout, in particular, grabbed the headlines.

“Yes I made communcations [sic] errors. And that was a mess. Therefore I apologize,” Wegner said.

A mess. He apologized for making a mess. Not to the people. Not for what the people suffered. For the abstract concept of making a mess. That’s virtue signaling to the group attacking infrastructure that next time they should submit a better disinformation playbook.

The CDU party thought he did a great job being on the court, but not later in court. It had confirmed him as lead candidate with 93% of the vote after the January blackout non-apology. The party gladly ran on his literally cold and cruel platform all the way to July 1, when a poll showed their out-for-tennis man had dropped the to ball to fourth place, with a Left party in the lead. Days later, a court filing had netted exactly how the Mayor had lied about his role on the day of the attack. By Friday, five members of his own base (presumably themselves taking a break from taking a break) circulated an open letter demanding he resign immediately and abandon the candidacy.

The signers are a who’s-who of the elitist CDU, an elitist investor, an elitist market lobbyist, an elitist tobacco lobbyist, and then two officials from the districts that froze. Notably, the letter explicitly forgave the tennis decision and condemned only getting caught for it. So much for those two officials from the district showing they care. Their core argument was to spare the CDU a campaign in which every billboard reminds voters that he got caught lying about January 3. Since Wegner has only conceded the candidacy, he apparently intends to stay on until a new coalition forms.

The letter says nothing about who attacked the city, or how to stop anyone from doing it again. The saboteurs burned a cable bridge, and when the Mayor got caught treating it like business as usual, his party burned him. Everyone involved seems to argue that the real damage was to their messaging, not the 100,000 people being represented by a heated tennis ball.

Europe No Longer Can Deny Moscow Routinely Ripping Up Sea Cables

As a life-long sailor, with extensive open water experience, let me try to explain why the Russian sabotage of sea cables is obvious. This is a story about large ships that “accidentally” drag an anchor across undersea cables, in the same way a large truck could “accidentally” run over a Volkswagen and drag it 100 miles.

On 11 May 1898, crews from the cruiser Marblehead and gunboat Nashville set out in two steam launches and two working launches to drag for and sever two telegraph cables running out of Cienfuegos.

The story today comes from a particular tanker called the Eagle S, taken to court over dragging its anchor. On a tanker of its size, anchor and chain together weigh roughly 100 metric tons. Dragging that load demands extra sustained engine power and generates continuous noise through the chain into the hull. The anchor mass and leverage, even swinging free undersea, works erratically against the rudder control and bleeds speed. Prosecutors in court argued that the Eagle S had all these signatures: they experienced falling speed and engine RPM. The crew came up with no plausible excuse to miss these factors. Even more to the point, fuel consumption is an unavoidable concern and anchor drag raises fuel consumption dramatically. On a shadow-fleet voyage that loss is a dominant variable always monitored.

The Eagle S ran one defense in court: the crew never knew the anchor was down, blamed it on winch failure made worse by weather. Basic physics make their claim impossible to believe, and the court did not let it float.

The more annoying line did not come from the ship at all. It came from a European official giving a strange excuse to The Record why drags like this could be an accident: an incompetent master knows the anchor is dragging and will not send crew onto an exposed foredeck in a storm to weigh it. A life-saving heroic decision. On a shadow fleet oil tanker. With disposable crew.

Are you f$%R#%ng kidding me?

The danger of the official European line is what it tries to drop on the unsuspecting reader. It concedes damage was noticed on board, concedes damage was unwanted, and then blames it all on a concern for human safety. They are weaponizing crew welfare on the least maintained, least caring vessels in the world. A tanker arguing they had an accident “because of how much we care about life” is a cynical joke.

Look at it like this: Swedish investigators have reconstructed an incident from the Vezhen ship’s voyage recorder and onboard video. They reported how three independent securing devices held an anchor, with two inoperative for some time. When the last one failed from a wave strike during a storm, the physics described above started to impact the ship. The Swedes say the autopilot compensated for the heavy yaw, and no alarm sounded. Sweden called it an accident of weather, mechanical failure, and poor seamanship. The accident was linked to a lack of care, where safeguards were failing and then gone, buried by ongoing negligence. That’s at least plausible.

The “we cared so much we didn’t care” is absurd on its face.

Now look at it like this: Dragged anchors account for about 30 percent of cable faults worldwide. It’s a thing we have a lot of data on already. A 2008 incident saw a ship drag anchor 180 miles across six cables. That sucked. A single long accidental drag is plausible, but it’s outside the norm because it’s negligent and counter to the variables the captain’s care about like fuel consumption (drag and direction). That’s why five cable drags in just eighteen months in one very particular sea of interest to Moscow is not plausible.

There is an expected baseline near 0.6 per year. One analyst put the observed cluster of five incidents at a once-in-108,000-years coincidence. Any attempt to look at these clustered anchor drags as isolated accidents is ignoring that they are collectively impossible. That’s what makes the “we cared about crew” so much worse as a defense. The high rate cluster isn’t an accident, and neither is “we cared”.

The legal record explains why cause becomes somewhat irrelevant to the undersea cable threat. The Helsinki court did not find the Eagle S crew innocent. It classified the event as an incident of navigation under UNCLOS Article 97 and assigned jurisdiction to the ship’s flag state. The damage fell inside Finland’s exclusive economic zone but outside its territorial sea, which stopped prosecution. Anchor-dragging is indistinguishable from negligence by official accounts, and the coastal-state had to admit incidents are outside their reach.

The Fitburg case gives us a comparison to weigh, because it was caught in the act and inside territorial waters. Their anchor was already damaged before the 130-kilometer drag. Prosecutors allege eight further cables were targeted before the ship was stopped. The coast guard intercepted it in the act, anchor still down, moving from the Estonian into the Finnish zone. Its case proceeds because it had two technical legal conditions the Eagle S did not.

The bottom line is that sailors could understand how incompetence such as lack of care accounts for any one ship in a storm. What does not add up is the regular sequence that indicates someone cares.

The persistence of the accident framing is the thing that dismisses the accident framing. Leaving these cases as unresolved only serves Moscow, which runs its flimsy deniability. European governments apparently want to avoid calling out that there has been a sustained campaign against their infrastructure, and it’s unclear why.