6 days ago
US Disrupts Alleged China-Linked Cyber-Espionage Operation Targeting Sensitive American Networks
US officials say hackers linked to China secretly entered or targeted important computer networks.
These included NASA, the US Senate and several government departments.
Hospitals, phone companies, power firms, banks and defense companies were also reportedly targeted.
The FBI says the activity began in 2018 and lasted through 2026.
Investigators connected the hackers to a Chinese technology company called Nanjing Xinjiuwei Network Technology Company.
Officials say the company helped hide the hackers inside normal internet traffic.
US agencies blocked three internet domains connected to the company.
They may also publish advice to help other organizations defend themselves.
China has denied the accusations.
US authorities disrupted an alleged Chinese state-sponsored cyber-espionage operation targeting NASA, the US Senate and other sensitive networks.
Targets allegedly included the Federal Reserve, Justice and Energy departments, hospitals, telecom providers, power companies and defense contractors.
An FBI affidavit said the campaign began in 2018 and continued through 2026.
Authorities linked the operation to Nanjing Xinjiuwei Network Technology Company, which allegedly served Chinese intelligence and military customers.
US agencies blocked three domains tied to the company and are considering an advisory to help potential victims protect their networks.
- Who
- US authorities, including the Federal Bureau of Investigation and National Security Agency, said hackers linked to China carried out the operation; China denied the allegations.
- What
- An alleged Chinese state-sponsored cyber-espionage campaign targeted or breached sensitive government, commercial and critical-infrastructure networks.
- Where
- Targets included networks in the United States and infrastructure that the hackers interacted with globally.
- When
- The FBI affidavit said the campaign began in 2018 and continued through 2026; US authorities blocked affiliated domains on Wednesday.
- Why
- US officials said the operation was intended to conduct cyber-espionage, while investigators said the hackers concealed their activity within ordinary internet traffic.
US Authorities’ Assessment
China’s Position
Responsibility for the operation
US Authorities’ Assessment
US authorities alleged that the campaign was Chinese state-sponsored and linked the technology company to China’s Ministry of State Security and People’s Liberation Army.
China’s Position
China has consistently denied US allegations of cyber-espionage.
Purpose and impact
US Authorities’ Assessment
US officials described the activity as espionage targeting sensitive government, commercial and critical-infrastructure networks, although the full damage was not immediately clear.
China’s Position
China’s denial rejects the US characterization of the activity; the article provides no further Chinese explanation of the specific operation.
Nature of the technology company’s role
US Authorities’ Assessment
US investigators alleged that Nanjing Xinjiuwei provided offensive cyber capabilities and helped hackers blend into routine consumer internet traffic.
China’s Position
China has not publicly accepted the US account in the article.
Key facts
- Alleged operator
- Nanjing Xinjiuwei Network Technology Company, a China-based technology firm.
- Alleged customers
- China’s Ministry of State Security and the People’s Liberation Army.
- Reported campaign period
- 2018 through 2026, according to an FBI affidavit.
- Government targets
- The National Aeronautics and Space Administration, United States Senate, Federal Reserve, Department of Justice and Department of Energy.
- Other targets
- Hospitals, telecommunications providers, power companies, financial institutions and defense contractors.
- US response
- Authorities blocked three internet domains affiliated with the Chinese company.
- Potential next step
- Federal agencies are considering an advisory describing the hackers’ techniques.
Quotes
Damon Rouse
Senior security engineer at Lumen Technologies’ Black Lotus Labs threat intelligence division
“I hadn’t seen a fully self-contained ecosystem like this in my career.”
indianexpress.com
“If you’re getting paying customers, you have a paper trail.”
indianexpress.com







