A Chinese state-sponsored hacking group, identified as Salt Typhoon and linked to China’s Ministry of State Security, breached email systems used by staffers on key U.S. House committees. The targeted committees included the House Select Committee on China, as well as panels overseeing foreign affairs, intelligence, and armed services. The breach, detected in December 2025, exposed sensitive communications and raised concerns about Beijing gaining insights into U.S. policy deliberations, military strategy, and counter-espionage measures. U.S. officials and cybersecurity experts highlighted the operation’s stealth and the ongoing threat posed by Chinese cyber-espionage campaigns against American legislators and government systems.
The incident is part of a broader pattern of Chinese cyber operations targeting U.S. government entities to collect sensitive data. While the Chinese Embassy denied the allegations, the FBI and other agencies have not commented due to ongoing investigations. Previous campaigns by Salt Typhoon included intrusions into major U.S. telecommunications networks, further demonstrating the group’s capabilities and intent. The breach underscores persistent vulnerabilities in government email systems and the escalating cyber tensions between Washington and Beijing.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Following public reporting, the Chinese embassy rejected the allegations and called them unfounded. U.S. officials, including the FBI, did not provide substantive public comment because of the ongoing investigation.
News reports disclosed the incident and identified Salt Typhoon, a group linked by researchers and officials to China's Ministry of State Security, as the suspected actor behind the breach. The reporting highlighted the strategic intelligence value of congressional staff communications related to China policy, foreign affairs, intelligence, and military matters.
The compromise was discovered in December 2025, prompting investigation into the scope and impact of the intrusion on congressional staff networks. Officials indicated the full extent of exposed data remained unclear at the time of detection.
A cyberespionage operation attributed to the Chinese threat actor Salt Typhoon breached email systems used by U.S. congressional staffers supporting the House Select Committee on China and committees overseeing foreign affairs, intelligence, and armed services. The intrusion reportedly exposed sensitive but unclassified communications and metadata, though there was no public evidence that lawmakers' own accounts were accessed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcenextgov.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.