China-linked hacking groups were reported to have penetrated a wide range of targets across the United States and allied regions, including manufacturers, U.S. government email systems, internet providers, and major telecommunications networks. Earlier reporting described broad economic espionage aimed at stealing trade secrets from manufacturing sectors in the U.S., Europe, and Asia, while later disclosures said Chinese operators breached U.S. government email accounts through Microsoft cloud infrastructure and infiltrated American internet providers for surveillance. Subsequent investigations tied the telecom intrusions to the Salt Typhoon campaign, which officials said exposed sensitive metadata and provided insight into U.S. surveillance targets.
U.S. officials characterized the activity, alongside related operations such as Volt Typhoon, as one of the most serious cyber threats to American critical infrastructure in recent years. Reporting said investigators believed the attackers may have retained access to at least eight telecom firms, including Verizon and AT&T, and that the campaign extended to dozens of telecoms and government agencies. In response, the Biden administration moved to bar the remaining U.S. operations of China Telecom Americas, citing national security risks and signaling the first public retaliatory step tied to the telecom compromises, even as debate continued over broader sanctions, technology restrictions, and offensive cyber responses.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Reporting in early 2026 said China-linked hackers had breached dozens of telecommunications companies and government agencies, showing the scope of the campaign had expanded well beyond the initially disclosed victims.
The Biden administration announced a first public retaliatory step against the China-linked telecom hacking campaign by moving to ban the remaining U.S. operations of China Telecom Americas, citing national security risks tied to its network presence and cloud services.
By December 2024, U.S. officials had concluded that China's Salt Typhoon campaign broadly compromised American telecommunications networks, with investigators believing the hackers may still have access to at least eight telecom firms, including Verizon and AT&T, and had obtained sensitive metadata and insight into U.S. surveillance targets.
AP reported that China-linked hackers targeted cellphones used by Donald Trump, JD Vance, and individuals associated with Kamala Harris’s campaign as part of a broader intrusion into commercial telecommunications infrastructure. U.S. officials were still investigating what data, if any, had been accessed.
The Washington Post reported that Chinese government hackers had infiltrated U.S. internet service providers to conduct espionage, indicating a deeper compromise of core communications infrastructure.
Chinese hackers penetrated U.S. government email accounts through Microsoft's cloud environment, exposing communications from federal agencies and marking a significant escalation in Beijing-linked cyber espionage against U.S. institutions.
Researchers reported that China-linked hackers had conducted a wide-ranging economic espionage campaign targeting manufacturing organizations in the United States, Europe, and Asia to steal trade secrets and other sensitive business information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritydive.com
Open sourceapnews.com
Open sourcewashingtonpost.com
Open sourcewashingtonpost.com
Open sourcecnn.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.