China’s Ministry of State Security publicly accused the United States National Security Agency (NSA) of conducting a series of cyberattacks against the China National Time Service Center (NTSC), a critical institution responsible for maintaining and distributing the country’s official time standard. According to Chinese authorities, the NSA began its operations on March 25, 2022, by exploiting vulnerabilities in the messaging services of a foreign mobile phone brand used by NTSC staff. This initial compromise allegedly allowed the NSA to steal sensitive data and monitor communications from employees’ devices. On April 18, 2023, the attackers reportedly escalated their access by using stolen credentials to infiltrate the center’s computer systems and further map its network. Between August 2023 and June 2024, the NSA is said to have deployed a new cyber warfare platform, utilizing 42 specialized cyber tools to attack multiple internal network systems, target a precision timing system, and plant disruptive code within the NTSC infrastructure. Chinese officials emphasized that the NTSC provides essential timing services to sectors such as telecommunications, finance, energy, transportation, mapping, and defense, and that any disruption could have significant consequences for national infrastructure and global time standards. The Ministry of State Security claimed to have obtained “irrefutable evidence” of the NSA’s involvement, though it did not publicly release technical details or proof. The attacks reportedly occurred late at night, suggesting a deliberate attempt to avoid detection. Chinese authorities stated that they had thwarted the NSA’s attempts to steal secrets and sabotage systems, thereby safeguarding the security of “Beijing Time.” The Ministry also provided guidance to the NTSC to eliminate the identified risks and strengthen its defenses. The public accusation comes amid ongoing tensions between the US and China over cybersecurity, trade, technology, and geopolitical issues. Chinese officials framed the incident as an example of the US engaging in the same cyber activities it frequently accuses China of conducting. The US Embassy did not immediately respond to requests for comment on the allegations. The incident highlights the strategic importance of time synchronization infrastructure and the potential impact of cyberattacks on national and global systems. Western governments have previously accused Chinese state-linked hackers of targeting officials, journalists, and corporations, but this case marks a rare public accusation by China against the US for a specific cyber operation. The disclosure is likely to further strain relations between the two countries and increase scrutiny of cyber activities targeting critical infrastructure.

TTPs, infrastructure, and targeting history in one profile.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
8 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcenextgov.com
Open sourcethehackernews.com
Open sourcecyberscoop.com
Open sourcecsoonline.com
Open sourcetherecord.media
Open sourcesecurityaffairs.com
Open sourceapnews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.