Suspected Chinese hackers were linked to multiple intrusions into Western government systems, including the exploitation of the SolarWinds software supply-chain compromise to access the U.S. National Finance Center, a payroll agency serving several federal departments, according to Reuters sources. In a separate case, Belgian prosecutors opened an investigation into an alleged breach of the country's intelligence service, with reports indicating Chinese state-linked actors may have accessed an external email server used for communications with public prosecutors, police, ministries, and other institutions.
The incidents add to a broader pattern of state-backed cyber espionage focused on sensitive government data and communications infrastructure. The U.S. case highlighted how attackers used a trusted software update channel to reach federal networks, while the Belgian probe underscored concerns that third-party systems connected to intelligence and law-enforcement bodies can become high-value entry points for foreign surveillance operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Russian authorities intensified their campaign against Telegram by alleging that foreign intelligence services could exploit weaknesses in the platform's encryption, claims the company rejected. The dispute added a cyber-security dimension to the broader pressure campaign against the messaging service and its founder.
Apple sent a fresh round of threat notifications to users in 84 countries, while Google also warned targeted users about suspected cyber activity. The alerts indicated continued global targeting of individuals with sophisticated spyware or related threats.
Belgium's federal prosecutor began investigating allegations that Chinese hackers breached the country's intelligence service. The probe signaled formal law-enforcement scrutiny of a suspected state-backed espionage incident.
Security experts said exploitation of Microsoft Exchange Server flaws had already compromised more than 20,000 U.S. organizations as mass hacking accelerated. The incident marked a major escalation in the impact of the Exchange vulnerabilities.
Sources told Reuters that suspected Chinese hackers exploited a SolarWinds software flaw to spy on the U.S. National Finance Center, which handles payroll for multiple federal agencies. The report identified a separate espionage operation from the Russia-linked SolarWinds compromise.
Microsoft disclosed that it had found malicious software in its environment as part of the broader SolarWinds breach investigation. The company said it found no evidence its production services or customer data were affected, but the announcement marked a major confirmation that a leading technology provider was also impacted.
Major security flaws affecting chips used in most phones and computers were publicly disclosed, exposing systems to potential data theft across vendors and platforms. The revelations prompted emergency mitigation efforts by hardware and software companies.
South Korean cryptocurrency exchange Bithumb reported that hackers stole customer data and funds, including losses tied to compromised user accounts. The incident was disclosed in early July 2017.
During the June 2017 NotPetya outbreak, a Ukrainian police official said the worldwide cyberattack was likely intended to cover installation of malware in Ukraine. The statement reframed the incident as a targeted operation rather than ordinary ransomware.
6 references tracked. Mallory keeps watching after this page renders.
reuters.com
Open sourcereuters.com
Open sourcereuters.com
Open sourcereuters.com
Open sourcereuters.com
Open sourcereuters.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.