US Accuses China of Cyber Espionage Targeting Critical Infrastructure
POLICY WIRE — Washington, DC — US authorities have unveiled a significant cyber-espionage operation allegedly orchestrated by Chinese military and intelligence services. The campaign purportedly...
POLICY WIRE — Washington, DC — US authorities have unveiled a significant cyber-espionage operation allegedly orchestrated by Chinese military and intelligence services. The campaign purportedly compromised several federal agencies, including NASA, the Federal Reserve, the Departments of Justice and Energy, and the US Senate.
The hackers are said to have utilized a Chinese technology company to mask their activities, infiltrate target networks, and enhance the efficiency of their attacks. Additional targets encompassed US military networks, hospitals, power companies, and defense contractors, as disclosed by the Justice Department.
In an effort to mitigate further damage, the department seized three internet domains linked to the Chinese company. Federal agencies are also set to issue an advisory on the hackers’ methods to aid victim companies in expelling the intruders.
The extent of the espionage’s impact remains unclear, and any assessments of the damage by US officials are expected to be kept confidential for security reasons. This revelation underscores the ongoing alleged Chinese hacking campaigns against vital American infrastructure, such as power plants and banks.
Cybersecurity has been a persistent point of contention in US-China relations, particularly during high-profile hacks. In 2023, US officials accused China of hacking military transportation networks, water plants, and power firms, potentially to sabotage any US response to a Chinese invasion of Taiwan. China denied these allegations.
In 2024, US officials and major phone companies grappled with the aftermath of China’s alleged infiltration of telecom networks, with then-presidential candidate Donald Trump and his running mate JD Vance among the targets. When questioned about whether Trump would address the latest alleged hacking activity with Chinese leader Xi Jinping during his upcoming visit to the US, Attorney General Blanche declined to comment on the specifics of their discussion.
Blanche emphasized the longstanding dialogue between the US and China regarding these activities, stating, ‘This is something that we have talked about with our counterparts in China for many, many years. And we know that it’s happening. And they know that we know that it’s happening. And it has to stop.’
The Chinese Embassy in Washington has been requested for comment. The Chinese government typically denies US hacking allegations and accuses US spy agencies of cyberattacks in return.
The announcement marks the culmination of an extensive investigation by the FBI and likely the National Security Agency, which unraveled a sophisticated deception operation allegedly employed by China for hacking. The operation purportedly involved a Chinese firm based in Nanjing, established in 2018 with 17 employees as of last year.
📄 POLICY WIRE WHITEPAPER PUBLISHED: PAKISTAN’S NATIONAL SECURITY POLICY PRIORITIES
US officials claim that China’s military and Ministry of State Security used the company’s services to blend in with routine internet traffic. The hackers are said to have systematically profiled and interacted with target infrastructure globally while remaining concealed within routine consumer network traffic, according to Lumen Technologies.
While the use of the Chinese firm may have allowed the hackers to hide their activities, it also potentially left a paper trail for investigators to follow, noted Damon Rouse, a senior security engineer at Lumen’s Black Lotus Labs threat intelligence division.
This is not the first instance of Chinese spy agencies allegedly leveraging the country’s tech sector to facilitate global computer intrusions. A 2024 leak from another Chinese company revealed a client list that included Chinese police, intelligence, and military organizations, as well as victims such as Tibetan exile-run political groups and hospitals in Taiwan.
Dakota Cary, a China analyst at security firm SentinelOne, observed that China’s hackers have significantly professionalized over the past decade. ‘Companies offering services to the state have proliferated and now offer niche services. Not only do these companies make China’s hackers more effective, they make it harder for defenders to cluster activity,’ Cary stated.
Cary also noted that while the US government’s actions are necessary to disrupt China’s operations on a large scale, the robust market for offensive services in China ensures their eventual return to operations.
Reporting by Policy-Wire (PW)




