Chinese hackers are spying on America’s critical infrastructure

And they could be doing it worldwide
A Joint Cybersecurity Advisory
The Cybersecurity and Infrastructure Security Agency (CISA)
Volt Typhoon
Comments from the National Cyber Security Centre (NCSC)
Discovered by private partners
Malicious hacking activity
Disrupting communications
What did Volt Typhoon access?
Even more victims
They will try to stay hidden
Comments from China’s Foreign Ministry
“The world’s biggest hacking group”
“A report filled with disinformation”
“The champion of hacking”
Active since 2021
And they could be doing it worldwide

A group of Chinese state-sponsored hackers have been spying on critical infrastructure in the United States and their espionage activities could be happening on a global scale.

A Joint Cybersecurity Advisory

The National Security Agency and a group of allied Western intelligence partners issued a Joint Cybersecurity Advisory on May 24th warning of Chinese-backed hacking activity. 

The Cybersecurity and Infrastructure Security Agency (CISA)

“Today’s advisory highlights China’s continued use of sophisticated means to target our nation’s critical infrastructure,” said Jen Easterly, the Director of (CISA)

Volt Typhoon

In the advisory, western intelligence agencies warned that a state-sponsored group of hackers known as Volt Typhoon had accessed America’s critical infrastructure sectors. 

Comments from the National Cyber Security Centre (NCSC)

“It is vital that operators of critical national infrastructure take action to prevent attackers hiding on their systems,” said Paul Chichester, the Director of Operations for the NCSC. 

Discovered by private partners

The western intelligence agencies said private sector partners had identified the activity and warned Volt Typhoon could target other critical infrastructure sectors worldwide. 

Malicious hacking activity

Microsoft was the private sector partner that first identified the malicious hacking activity and issued its own statement explaining the situation and what Volt Typhoon accessed. 

Disrupting communications

Volt Typhoon was likely looking to develop the ability to disrupt critical communications infrastructure between the U.S. and Asia in the event of a crisis according to Microsoft. 

What did Volt Typhoon access?

A variety of organizations fell victim to the hacking groups campaign and Microsoft said that the communication, manufacturing, utility, and transportation sectors were affected. 

Even more victims

Maritime, government, information technology, and education sectors were accessed as well and Microsoft said it chose to highlight the activity over concerns it would affect customers, adding that "detecting and mitigating this attack could be challenging."

They will try to stay hidden

Microsoft’s statement noted, “observed behavior suggests that the threat actor intends to perform espionage and maintain access without being detected for as long as possible.”

Comments from China’s Foreign Ministry

Chinese Foreign Ministry spokesperson Mao Ning called the allegations from western intelligence and Microsoft a “collective disinformation campaign” according to Reuters.

 

“The world’s biggest hacking group”

“It’s widely known that the Five Eyes is the world’s biggest intelligence association and the NSA the world’s biggest hacking group,” Ning told reporters at a press conference. 

“A report filled with disinformation”

“It is ironic that the Five Eyes jointly released a report filled with disinformation,” Ning added according to an English translation from the Chinese Ministry of Foreign Affairs. 

“The champion of hacking”

Mao went on to say that the involvement of a “certain company” showed that the United States expanded its channels for spreading disinformation and added that “whatever their subterfuge, it will not change the fact that the US is the champion of hacking.” 

Active since 2021

Volt Typhoon has been active since mid-2021 according to Microsoft and noted that the group targeted critical infrastructure Guam, which is the home of several important military facilities that would be crucial during a crisis in Asia according to The Guardian. 

More for you