US Exposes Major Chinese Cyber-Espionage Campaign Targeting Critical Infrastructure
US officials revealed a sweeping Chinese cyber-espionage operation on Wednesday, alleging that hackers linked to China’s military and intelligence services compromised or targeted multiple federal agencies, including NASA, the Federal Reserve, the Departments of Justice and Energy, and the US Senate. The campaign, active from at least 2018 through 2026, also breached military networks, hospitals, power companies, and defense contractors, according to the Justice Department.
To disrupt the operation, authorities seized three internet domains tied to a Chinese tech firm, Nanjing Xinjiuwei Network Technology Company, which allegedly helped conceal the hackers’ activities. The company, founded in 2018 and employing former members of China’s People’s Liberation Army (PLA), reportedly provided infrastructure to blend malicious traffic with legitimate internet activity. Investigators noted the firm’s job postings for cybersecurity engineers capable of "large-scale penetration projects," further linking it to offensive operations.
The affidavit supporting the domain seizures identified successful intrusions at three unnamed Department of Energy national laboratories, the National Institutes of Health, and a Department of Health and Human Services agency. Other targets included the Department of Justice, the Federal Reserve, NASA, and the Senate, though the full extent of the damage remains classified.
A Chinese Embassy spokesperson denied the allegations, stating that China "opposes and combats all forms of cyberattacks in accordance with the law" and urged the US to cease "smearing" China over cybersecurity issues. The disclosure underscores long-standing tensions between the two nations, with US officials previously accusing China of infiltrating military transportation networks, water plants, and telecom systems allegations Beijing has repeatedly denied.
The operation’s sophistication was highlighted by cybersecurity firm Lumen Technologies, which observed the hackers systematically profiling global infrastructure while evading detection. Analysts noted the use of a "fully self-contained ecosystem" to obscure attacks, though financial and contractual records may have aided investigators in tracing the activity.
Experts warned that China’s growing market for offensive cyber services including private firms offering specialized hacking tools has made its operations more effective and harder to attribute. While Wednesday’s actions disrupted the campaign, analysts cautioned that such measures are unlikely to halt future attacks, given the scale of China’s cyber capabilities.
Source: https://www.cnn.com/2026/08/26/politics/us-alleged-chinese-cyber-spying-campaign
United States Senate Select Committee on Intelligence cybersecurity rating report: https://www.rankiteo.com/company/united-states-senate-select-committee-on-intelligence
"id": "UNI1790153634",
"linkid": "united-states-senate-select-committee-on-intelligence",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Aerospace, Research',
'location': 'United States',
'name': 'NASA',
'type': 'Government Agency'},
{'industry': 'Finance, Central Banking',
'location': 'United States',
'name': 'Federal Reserve',
'type': 'Government Agency'},
{'industry': 'Law Enforcement, Legal',
'location': 'United States',
'name': 'Department of Justice',
'type': 'Government Agency'},
{'industry': 'Energy, Research',
'location': 'United States',
'name': 'Department of Energy',
'type': 'Government Agency'},
{'industry': 'Legislative',
'location': 'United States',
'name': 'US Senate',
'type': 'Government Agency'},
{'industry': 'Healthcare, Research',
'location': 'United States',
'name': 'National Institutes of Health',
'type': 'Government Agency'},
{'industry': 'Healthcare, Public Health',
'location': 'United States',
'name': 'Department of Health and Human Services',
'type': 'Government Agency'},
{'industry': 'Energy, Research',
'location': 'United States',
'name': 'Unnamed Department of Energy National '
'Laboratories (3)',
'type': 'Research Institution'},
{'industry': 'Defense',
'location': 'United States',
'name': 'Military networks',
'type': 'Government Agency'},
{'industry': 'Healthcare',
'location': 'United States',
'name': 'Hospitals',
'type': 'Healthcare Provider'},
{'industry': 'Energy',
'location': 'United States',
'name': 'Power companies',
'type': 'Utility Company'},
{'industry': 'Defense, Aerospace',
'location': 'United States',
'name': 'Defense contractors',
'type': 'Private Company'}],
'attack_vector': 'Network intrusion, domain exploitation',
'data_breach': {'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Classified, intelligence, '
'operational data'},
'date_publicly_disclosed': '2023-11-29',
'description': 'US officials revealed a sweeping Chinese cyber-espionage '
'operation alleging that hackers linked to China’s military '
'and intelligence services compromised or targeted multiple '
'federal agencies, military networks, hospitals, power '
'companies, and defense contractors. The campaign, active from '
'at least 2018 through 2026, was disrupted by seizing three '
'internet domains tied to a Chinese tech firm, Nanjing '
'Xinjiuwei Network Technology Company, which allegedly helped '
'conceal the hackers’ activities.',
'impact': {'data_compromised': 'Classified (extent unknown)',
'operational_impact': 'Potential disruption of critical '
'infrastructure operations',
'systems_affected': ['Federal agencies',
'Military networks',
'Hospitals',
'Power companies',
'Defense contractors']},
'initial_access_broker': {'high_value_targets': ['Federal agencies',
'Military networks',
'Critical infrastructure'],
'reconnaissance_period': '2018-2026'},
'investigation_status': 'Ongoing',
'lessons_learned': 'China’s growing market for offensive cyber services and '
'private firms offering specialized hacking tools has '
'increased the sophistication and difficulty of '
'attributing cyber-espionage operations. Disruptive '
'measures like domain seizures may not halt future attacks '
'due to the scale of China’s cyber capabilities.',
'motivation': 'Espionage, intelligence gathering, critical infrastructure '
'profiling',
'post_incident_analysis': {'corrective_actions': 'Domain seizures, ongoing '
'investigation, potential '
'policy responses to counter '
'state-sponsored cyber '
'threats',
'root_causes': 'State-sponsored cyber-espionage, '
'use of private firms to obscure '
'malicious activities, exploitation '
'of internet domains for blending '
'malicious traffic with legitimate '
'activity'},
'recommendations': 'Enhance monitoring of critical infrastructure, improve '
'threat intelligence sharing, and develop strategies to '
'counter state-sponsored cyber-espionage operations. '
'Strengthen defenses against supply chain and third-party '
'risks.',
'references': [{'source': 'US Justice Department'},
{'source': 'Lumen Technologies'},
{'source': 'Chinese Embassy Statement'}],
'regulatory_compliance': {'legal_actions': 'Domain seizures, investigation '
'ongoing'},
'response': {'containment_measures': 'Seizure of three internet domains tied '
'to Nanjing Xinjiuwei Network Technology '
'Company',
'law_enforcement_notified': 'Yes (US Justice Department)',
'third_party_assistance': 'Lumen Technologies (cybersecurity '
'firm)'},
'threat_actor': 'Chinese military and intelligence services, Nanjing '
'Xinjiuwei Network Technology Company',
'title': 'US Exposes Major Chinese Cyber-Espionage Campaign Targeting '
'Critical Infrastructure',
'type': 'Cyber-Espionage'}