China’s Military Procurement Network suspended or banned several prominent domestic cybersecurity companies from PLA-related contracts in the first half of 2026 over alleged procurement violations, with collusive bidding cited as a central concern. Companies named in reporting include TopSec, Venustech, and subsidiaries of Qi An Xin, all of which are described as significant players in China’s cybersecurity sector and part of the broader ecosystem that has supported government and military cyber activity.
The action has drawn added scrutiny because it follows earlier reporting on leaked i-SOON documents that allegedly detailed bid-rigging and coordinated bidding practices among Chinese cybersecurity vendors competing for state contracts. The measures suggest tighter military procurement oversight in China and could disrupt firms with close links to state security work, while exposing governance and compliance risks inside a sector long intertwined with official cyber operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Beijing TopSec Network Security was given a lifetime ban from PLA procurement in January 2026 following a two-year investigation into collusive bidding. The action was part of the PLA's enforcement against procurement misconduct among Chinese cybersecurity vendors.
In the first half of 2026, China's Military Procurement Network suspended or banned numerous major Chinese cybersecurity companies from PLA-related contracts over alleged procurement violations, especially collusive bidding. Companies specifically named in the reporting include TopSec, Venustech, and Qi An Xin subsidiaries.
Earlier reporting cited leaked i-SOON documents that described bid-rigging and cooperative bidding practices among Chinese cybersecurity firms pursuing government and military contracts. The leaks were also said to show close ties between some vendors and state or military clients.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcemalware.news
Open sourcenattothoughts.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.