U.S. Alleges Chinese Hackers Compromised Hospitals, NASA, Senate

0
1

Key Takeaways

  • U.S. officials allege a sustained Chinese cyber‑espionage campaign that began in 2018 and ran through at least 2026, targeting federal agencies, critical infrastructure, and private sector entities.
  • The hackers are said to have used a Nanjing‑based technology firm, Nanjing Xinjiuwei Network Technology, to mask their activity and create a “self‑contained ecosystem” for offensive operations.
  • Affected organizations include NASA, the Federal Reserve, the Departments of Justice and Energy, the U.S. Senate, several Department of Energy National Laboratories, the National Institutes of Health, and various health‑and‑human‑services agencies.
  • The Justice Department seized three internet domains linked to the Chinese firm and plans to release an advisory detailing the attackers’ techniques to help victims expel the intruders.
  • China denies the allegations, stating it opposes all forms of cyberattacks and urging the U.S. to stop using cybersecurity issues to smear Beijing.
  • Experts note that the campaign reflects a broader trend of Chinese state‑linked hackers outsourcing work to domestic tech companies, making attacks more effective and harder to trace.
  • The incident adds to a series of recent accusations against China involving telecom infiltrations, power‑grid probes, and attempts to sabotage U.S. defenses in a potential Taiwan scenario.

Overview of the Alleged Chinese Cyber‑Espionage Campaign
On Wednesday, U.S. officials disclosed what they describe as a major Chinese state‑backed cyber‑espionage effort that has compromised or attacked numerous federal agencies and critical‑infrastructure sectors. The campaign, which allegedly began in 2018 and persisted through 2026, involved hackers tied to the Chinese military and intelligence services who used a Chinese technology company to obscure their tracks, gain efficient access to target networks, and conduct large‑scale data exfiltration. The revelation underscores the growing sophistication and persistence of Beijing’s cyber operations against the United States.

Targeted Federal Agencies and Critical Infrastructure
The affidavit supporting the seizure of three internet domains lists a range of victims and targets. Among the confirmed victims are three unnamed Department of Energy National Laboratories, the National Institutes of Health, and a Department of Health and Human Services agency. The Department of Justice, the Federal Reserve, NASA, and the U.S. Senate are identified as entities that were “targeted” by the hackers, indicating at least attempted intrusions. Beyond government, the campaign reportedly extended to U.S. military networks, hospitals, power companies, and defense contractors, reflecting a broad aim to harvest strategic, scientific, and economic intelligence.

Timeline and Scope of the Intrusions
According to the FBI affidavit, the hacking activity started in 2018 and continued through at least 2026, representing an eight‑year window of sustained access. The document notes successful break‑ins at the aforementioned laboratories and health agencies, while other high‑profile institutions were listed as targets, suggesting the actors attempted—or may have succeeded—in penetrating those networks as well. The long duration implies the attackers maintained persistent footholds, periodically exfiltrating data while evading detection through sophisticated tradecraft.

Role of the Chinese Tech Firm Nanjing Xinjiuwei Network Technology
U.S. investigators allege that the hackers leveraged services from Nanjing Xinjiuwei Network Technology Company, a Nanjing‑based firm established in 2018 with roughly 17 employees as of last year. The company’s workforce reportedly includes former members of China’s People’s Liberation Army, who use their PLA connections to secure contracts supporting offensive cyber operations. By routing malicious traffic through the firm’s legitimate‑seeking infrastructure, the actors sought to blend with ordinary consumer internet traffic, thereby reducing the likelihood of detection by network defenders.

How the Hackers Concealed Their Activity
The hackers employed a technique described by Lumen Technologies as “systematically profil[ing] and interact[ing] with target infrastructure on a global scale while remaining safely hidden within routine consumer network traffic.” This approach allowed them to mask command‑and‑control communications and data exfiltration as benign traffic. Senior security engineer Damon Rouse of Lumen’s Black Lotus Labs noted that the use of a paying customer relationship with the Chinese firm created a traceable paper trail, which ultimately aided investigators in linking the activity to the alleged state sponsors.

U.S. Government Response: Domain Seizures and Advisory
In an effort to halt further damage, the Justice Department seized three internet domains affiliated with Nanjing Xinjiuwei Network Technology on Wednesday. Federal agencies also announced plans to release an advisory detailing the hackers’ tactics, techniques, and procedures (TTPs) so that victim organizations can detect and eject the intruders. The advisory is intended to serve as a practical guide for network defenders, highlighting indicators of compromise and recommending mitigation steps such as password resets, network segmentation, and enhanced monitoring of anomalous traffic patterns.

China’s Official Denial and Diplomatic Context
When approached for comment, a spokesperson for the Chinese Embassy in Washington, D.C., stated that “The Chinese government firmly opposes and combats all forms of cyberattacks in accordance with the law,” and urged the U.S. to cease using cybersecurity issues to smear or discredit China. The denial mirrors previous Chinese responses to similar allegations, reflecting a broader diplomatic pattern in which Beijing rejects accusations of state‑sponsored hacking while urging dialogue and mutual respect. The timing of the disclosure coincides with an upcoming visit by Chinese leader Xi Jinping to the United States, adding a layer of geopolitical sensitivity to the announcement.

Historical Pattern of Chinese Hacking and Telecom Intrusions
This latest disclosure is part of a series of alleged Chinese cyber campaigns targeting U.S. infrastructure. In 2023, U.S. officials accused China of hacking military transportation networks, water plants, and power firms to potentially impede a U.S. response to a Taiwan contingency. In 2024, American telecom providers and the Trump‑Vance campaign reported efforts to expel Chinese actors from telecommunications networks. A 2024 leak from another Chinese firm revealed a client list that included Chinese police, intelligence, and military organizations, with victims ranging from Tibetan exile groups to Taiwanese hospitals, further illustrating the breadth of China’s cyber‑espionage apparatus.

Expert Analysis on the Professionalization of Chinese Cyber Operations
Security analysts contend that the demonstrated use of a dedicated domestic tech firm marks a maturation of China’s cyber‑offensive capabilities. Dakota Cary, a China analyst at SentinelOne, observed that “China’s hackers have professionalized significantly in the last decade,” with proliferating companies offering niche services such as large‑scale penetration testing, exploit development, and stealthy traffic routing. These firms not only increase the effectiveness of state‑backed actors but also complicate attribution, as defenders must contend with a diffuse market of offensive services rather than a monolithic hacking unit.

Implications for U.S.–China Relations and Future Defense
The exposure of this campaign is likely to intensify scrutiny of China’s cyber practices and may prompt further diplomatic pushback, sanctions, or heightened cybersecurity investments from the United States. As both nations continue to rely heavily on digital infrastructure, the incident underscores the need for robust defensive measures, information sharing between government and private sectors, and clear norms governing state behavior in cyberspace. Moving forward, the balance between deterrence, engagement, and resilience will shape the trajectory of U.S.–China relations in an era where cyber espionage remains a persistent tool of statecraft.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here