US says Chinese cyber spies targeted hospitals, government agencies and the military
US Says Chinese Cyber Spies Targeted US Institutions
Activelifezero.com – The US says Chinese cyber spies ran a prolonged operation that reached into NASA, the Federal Reserve, the Department of Justice, the Department of Energy, the US Senate, military command networks, hospital systems, electric utilities, and major defense contractors. Federal officials laid out the details on Wednesday, describing a sustained campaign in which Chinese military and intelligence personnel allegedly exploited the services of a commercial intermediary to embed themselves inside American networks while appearing as ordinary consumer web traffic.
The Justice Department moved the same day to seize three internet domains connected to the intermediary, a step designed to sever ongoing access and contain further exposure. Officials also announced that a public advisory will follow, outlining the specific techniques employed so that affected organizations can identify and remove any residual footholds. The full scope of compromise, however, remains unclear; a classified counterintelligence assessment is expected to quantify the damage.
The Nanjing Firm at the Center of the Operation
At the heart of the disclosure is Nanjing Xinjiuwei Network Technology Company, a firm registered in the eastern Chinese city of Nanjing. Chinese business records indicate it was founded in 2018 and employed 17 people as of last year. US officials stated that China’s military and the Ministry of State Security used the company’s commercial services to blend surveillance traffic into the background noise of everyday internet use, giving the arrangement a private-sector veneer while preserving plausible deniability.
Lumen Technologies, a US-based provider with extensive visibility into global internet backbone routing, published a technical blog post on Wednesday describing the operation in detail. Damon Rouse, a senior security engineer at Lumen’s Black Lotus Labs threat intelligence division, called the arrangement the most comprehensive concealment ecosystem he has encountered in his career.
“I hadn’t seen a fully self-contained ecosystem like this in my career,” Rouse told CNN. “If you’re getting paying customers, you have a paper trail.”
That paper trail, investigators noted, is precisely what makes the commercial model both a shield and a vulnerability: the billing and customer-relationship records inherent to a paying-client arrangement created an audit path that pure state-directed traffic would not have left behind.
Broader Context and Diplomatic Timing
The US says Chinese cyber spies have been probing American critical infrastructure for years. In 2023, Washington accused Beijing of targeting military transportation systems, municipal water treatment plants, and power-generation facilities — assets that, officials argued, could be sabotaged to blunt any US response to a hypothetical Chinese invasion of Taiwan. China rejected those claims. The following year, American officials and the country’s largest telecommunications carriers spent months working to extract what they described as Chinese infiltration of telecom backbone networks. Former presidential candidate Donald Trump and his running mate JD Vance were reportedly among those whose communications were touched by that effort.
The timing of the latest disclosure also carries diplomatic weight. Chinese President Xi Jinping is scheduled to visit the United States next month, and questions arose as to whether President Trump would raise the allegations directly with his counterpart. Speaking on Fox News on Wednesday, Attorney General Blanche declined to preview the administration’s negotiating posture.
“I’m not going to tell President Trump what he needs to talk to the leadership about in China,” Blanche said.
Frequently Asked Questions
Which US institutions were named as targets? NASA, the Federal Reserve, the Department of Justice, the Department of Energy, the US Senate, military command networks, hospital systems, electric utilities, and major defense contractors were all identified in the Wednesday disclosure.
What immediate action did the government take? The Justice Department seized three internet domains linked to the commercial intermediary and announced that a public advisory detailing the hackers’ techniques would follow so victim organizations can expel lingering footholds.
Who is the commercial intermediary at the center of the operation? Nanjing Xinjiuwei Network Technology Company, a 17-person firm registered in Nanjing, China, and founded in 2018, allegedly used by Chinese military and intelligence personnel