The Netherlands’ Defence Intelligence and Security Service (MIVD) said China’s offensive cyber capabilities have reached parity with those of the United States, citing a major improvement in Beijing’s cyber operations after the Strategic Support Force was replaced by a dedicated Cyberspace Force. According to the Dutch assessment, that restructuring enabled sustained refinement of tools and tradecraft, while Chinese state-backed operators continued targeting Dutch businesses, universities, and individuals. The warning aligns with broader Western intelligence reporting that China has used advanced cyber capabilities against critical infrastructure and has sharply increased its use of zero-day exploits.
Dutch officials have also described a China-linked espionage campaign exploiting FortiGate devices as more extensive than previously understood, reinforcing concerns about the scale and persistence of Beijing’s cyber activity in Europe. MIVD said current detection, response, and mitigation efforts are often insufficient against the professionalism and volume of the threat, underscoring the risk to government networks, private-sector organizations, and research institutions.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
In its public annual report, the Netherlands' Defence Intelligence and Security Service assessed that China's offensive cyber capabilities had reached parity with those of the United States. The report also warned that Chinese state-backed actors had targeted Dutch businesses, universities, and individuals, and that current detection and response measures were often inadequate.
Google Threat Intelligence Group reported that zero-day exploitation by China-linked operations doubled during the previous year. The finding underscored the increasing tempo and sophistication of Chinese cyber activity.
Dutch intelligence said Chinese state-backed hackers exploited a FortiGate vulnerability in an espionage campaign that was more extensive than previously known. The activity targeted Dutch organizations and formed part of broader Chinese cyber operations against the Netherlands.
According to the Dutch MIVD's later assessment, Beijing replaced the PLA Strategic Support Force with a dedicated Cyberspace Force about two years before April 2026. MIVD said the reorganization helped improve China's offensive cyber operations.
MIVD said China's dedicated cyber force enabled continuous refinement of offensive tooling beginning in 2025. The agency linked this sustained development to China's growing cyber capability and professionalism.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.