Three Chinese state-sponsored campaigns disclosed in 2023 and 2024 represent a qualitative shift in the publicly documented threat from Beijing. Previous Chinese cyber operations — APT-10, APT-40, APT-41, and their predecessors — were primarily collection operations: enter a network, extract intellectual property or credentials, exit before detection. The Typhoon campaigns … [Read more...] about Salt Typhoon, Volt Typhoon, Flax Typhoon: China’s 2024 Campaign Against U.S. Infrastructure
News
Foreign Criminal Cyberattacks Against the United States: Ransomware, Botnets, and Financial Fraud
The Congressional Research Service's inventory of foreign criminal cyberattacks against the United States runs from 2003 through 2025 and documents operations by individuals and groups from Russia, Ukraine, Romania, Iran, Nigeria, Latvia, China, North Korea, and elsewhere. These actors are distinguished from nation-state operators by one criterion: the U.S. government has … [Read more...] about Foreign Criminal Cyberattacks Against the United States: Ransomware, Botnets, and Financial Fraud
Iran’s Cyber Operations: Infrastructure Attacks, Election Interference, and IRGC Proxies
Iran's documented cyber operations against the United States are distinguished by their breadth of target selection and their use of both the Islamic Revolutionary Guard Corps and the Ministry of Intelligence and Security as operational entities. The Congressional Research Service record covers Iranian campaigns from 2011 through 2022, with operations targeting financial … [Read more...] about Iran’s Cyber Operations: Infrastructure Attacks, Election Interference, and IRGC Proxies
North Korea’s Cyber Program: From Sony to Blockchain Theft
North Korea's cyber program is unlike any other nation-state operation in the CRS record. Where China steals intellectual property to fuel industrial development and Russia uses cyberspace for political warfare, Pyongyang uses its hacking apparatus as a revenue-generation mechanism for a sanctions-constrained state. The Reconnaissance General Bureau's APT-38 is the primary … [Read more...] about North Korea’s Cyber Program: From Sony to Blockchain Theft
Russia’s State Cyber Operations: From SolarWinds to Logistics Warfare
Russia's documented cyber operations against the United States and its allies span three distinct intelligence and military organizations — the FSB, the GRU, and the SVR — each with a different operational mandate and target profile. The Congressional Research Service's updated inventory covers Russian campaigns from 2003 through 2025, a record that encompasses election … [Read more...] about Russia’s State Cyber Operations: From SolarWinds to Logistics Warfare
China’s Cyber Campaigns Against the United States: Two Decades of Documented Operations
The People's Republic of China runs the most sustained documented cyber espionage program targeting the United States. The Congressional Research Service's updated cyberattack compendium covers Chinese state-linked operations beginning as far back as 2006 and running through 2024, with the Ministry of State Security and the People's Liberation Army serving as the primary … [Read more...] about China’s Cyber Campaigns Against the United States: Two Decades of Documented Operations
How the U.S. Government Attributes Cyberattacks — and Why It Is Harder Than It Looks
Attributing a cyberattack to a specific actor or nation is an analytic exercise that combines forensic investigation with intelligence tradecraft, and the U.S. government has formalized both the process and the language for expressing confidence in its conclusions. The Office of the Director of National Intelligence published a public guide to cyber attribution in 2018 that … [Read more...] about How the U.S. Government Attributes Cyberattacks — and Why It Is Harder Than It Looks
Thirteen Years of Cyberattacks Against the United States: The CRS Record
The Congressional Research Service released an updated inventory of significant cyberattacks against the United States spanning 2012 through 2025. The document, R46974, catalogues operations attributed to nation-states and foreign criminal actors with primary-source citations, drawing on indictments, grand jury findings, and official government statements. It is not a … [Read more...] about Thirteen Years of Cyberattacks Against the United States: The CRS Record
Billington Critical Infrastructure CyberSecurity Summit, Nov. 17–18, 2026, San Antonio, Texas
Billington CyberSecurity is launching its first dedicated Critical Infrastructure CyberSecurity Summit on Nov. 17–18, 2026 at Henry B. Gonzalez Convention Center, bringing together government officials, infrastructure operators, cybersecurity leaders, and industry stakeholders at a moment when attacks on essential systems are becoming both more frequent and more geopolitically … [Read more...] about Billington Critical Infrastructure CyberSecurity Summit, Nov. 17–18, 2026, San Antonio, Texas
ShinyHunters Breaches Canvas LMS, Threatening Data on 275 Million Users
The criminal extortion group ShinyHunters has claimed responsibility for a sweeping breach of Instructure's Canvas learning management system, one of the most widely deployed academic platforms in the world. The attack, which surfaced publicly on May 7, 2026, threatens to expose data tied to as many as 275 million individuals across nearly 9,000 institutions, including Harvard, … [Read more...] about ShinyHunters Breaches Canvas LMS, Threatening Data on 275 Million Users