• Skip to main content
  • Skip to secondary menu
  • Skip to footer

Cybersecurity Market

Cybersecurity Technologies & Markets

  • Cybersecurity Events 2026-2027
  • Sponsored Post
  • Market Reports
  • About
    • GDPR
  • Contact

China’s Cyber Campaigns Against the United States: Two Decades of Documented Operations

May 19, 2026 By admin

The People’s Republic of China runs the most sustained documented cyber espionage program targeting the United States. The Congressional Research Service’s updated cyberattack compendium covers Chinese state-linked operations beginning as far back as 2006 and running through 2024, with the Ministry of State Security and the People’s Liberation Army serving as the primary perpetrating entities across campaigns that targeted intellectual property, critical infrastructure, telecommunications networks, and the personal data of tens of millions of Americans.

The Intellectual Property Campaign

The dominant throughline across China’s documented operations is the systematic theft of intellectual property. APT-10, attributed to the Ministry of State Security and active from at least 2006 through 2018, targeted transportation, technology, shipping, consulting, healthcare, and energy companies by exploiting cloud and managed service providers as access vectors — a supply-chain approach that gave the group leverage over multiple downstream targets through a single compromised intermediary. APT-40, active from 2011 through 2018, focused specifically on submersibles, autonomous vehicles, chemicals, aircraft, genetics, and infectious disease research. APT-41, running from 2014 through 2020, cast a wider net across IT companies, telecommunications firms, academic institutions, and NGOs, combining intellectual property theft with ransomware deployment and cryptocurrency mining on illegally accessed machines.

MSS-linked actors also ran a parallel campaign from 2009 through 2020 targeting technology manufacturing, healthcare, energy, defense, and educational institutions, with the campaign ultimately expanding to include theft of COVID-19 research. DOJ charged two hackers associated with that operation in July 2020. The operational span — over a decade of continuous activity in a single campaign — reflects the patient, long-duration approach that distinguishes state intelligence programs from criminal operations.

Military and Defense Targeting

PLA-attributed operations ran alongside the MSS campaigns with a harder military focus. A campaign running from 2006 through 2014 targeted U.S. manufacturers to steal sensitive information benefiting Chinese state enterprises. The 2017 Equifax hack, attributed to PLA actors, resulted in the theft of personally identifiable information on nearly 150 million Americans — one of the largest PII breaches in history, with obvious downstream counterintelligence applications. Aerospace remained a persistent target: MSS-linked actors ran a campaign from 2010 through 2015 specifically against turbofan engine technology, and a separate Chinese national admitted to stealing jet engine technology from United Technologies across 2008 through 2014.

The Typhoon Campaigns

The most recent and strategically significant Chinese operations documented in the CRS report are the Typhoon-branded campaigns of 2023 and 2024. Volt Typhoon, attributed to state-sponsored actors and active from 2023 through 2024, did not steal data. It established persistent access to U.S. critical infrastructure — positioning for disruption if ordered to execute in a future conflict scenario. The CISA advisory describing Volt Typhoon framed it explicitly as pre-positioning for potential wartime use. Salt Typhoon, active in 2024, compromised commercial telecommunications companies to access customer communications. Flax Typhoon, also 2024, targeted internet-connected devices — cameras, storage systems — to build a botnet from which further attacks could be launched. BlackTech, documented in 2023, compromised routers to attack targets in the United States and Japan simultaneously.

The pattern across two decades is consistent: China uses its intelligence apparatus and military cyber units to extract technological advantage from U.S. private and government entities, and it has more recently expanded from collection toward access operations targeting infrastructure. The transition from espionage to pre-positioned disruption capability is the development that matters most to any organization operating systems that could be considered critical infrastructure in a conflict context.

Filed Under: News

Footer

Recent Posts

  • Google’s $32 Billion Wiz Bet Meets the OT Grid: Hitachi Becomes Its Critical-Infrastructure Channel
  • Cybersecurity Stocks Fall Friday as Nasdaq’s 4.2% Tech Rout Sweeps Up CrowdStrike and Palo Alto
  • IdentityTheft.org Sells for $30,000 on Sedo
  • Infosecurity Europe 2026, June 2–4, London
  • Ocean Launches From Stealth With $28 Million to Reinvent Email Security Using AI Agents
  • Salt Typhoon, Volt Typhoon, Flax Typhoon: China’s 2024 Campaign Against U.S. Infrastructure
  • Foreign Criminal Cyberattacks Against the United States: Ransomware, Botnets, and Financial Fraud
  • Iran’s Cyber Operations: Infrastructure Attacks, Election Interference, and IRGC Proxies
  • North Korea’s Cyber Program: From Sony to Blockchain Theft
  • Russia’s State Cyber Operations: From SolarWinds to Logistics Warfare

Media Partners

  • Defense Market
  • Technologies.org
  • Technology Conferences
Teledyne FLIR Defense Selected by U.S. Army for LASSO Loitering Munition Program
Heaviside Industries Raises $28M to Push Autonomous Warfare Into Its Next Phase
Israel Approves F-35 and F-15IA Squadron Purchases Worth Tens of Billions
DEFSEC Pushes Battlefield Awareness Forward with BLISS Deployment to Yuma
Farnborough International Airshow 2026, July 20–24, Farnborough, England
6K Energy and CRG Defense Form Seven-Year Pact to Build U.S. Defense Battery Supply Chain
Boeing MQ-25A Stingray First Operational Flight Advances U.S. Navy Carrier Aviation
L3Harris Secures $1 Billion Pentagon-Style Backing Ahead of Missile Solutions IPO
DFEN Unwinds the War Premium
The Industrial Gap Behind Europe’s Rearmament Numbers
Itera Emerges From Stealth With Fluid Circuit Board That Rewires in Under a Minute
Quantum Computing Stocks Are Down. They Are Not at the Bottom.
The Humanoid Trap: Form Factor as Distraction in Industrial Robotics
Hark Raises $700M Series A at $6B: The Vertical Integration Bet on Personal AI
Apple Brings Apple Intelligence to Accessibility, Adds Wheelchair Eye Control for Vision Pro
RADAR Raises $170M to Bring Real-Time Inventory Intelligence to Physical Retail
Anthropic’s Stainless Acquisition Is an Infrastructure Seizure Disguised as a Developer Tools Deal
Blackstone and Google Are Building an AI Infrastructure Giant Outside the Traditional Cloud Model
Mind Robotics Crosses $1B in Total Funding; Rivian Is the Quiet Disclosure
Quantum Motion Raises $160 Million Series C to Scale Silicon-Based Quantum Computing
WWDC 2026 Keynote, June 8, 2026, Apple Park, Cupertino
Baird 2026 Global Consumer, Technology & Services Conference, June 2–4, New York
D.A. Davidson Technology Conference, June 11, 2026, Nashville
Bank of America Global Technology Conference, June 4, 2026, San Francisco
William Blair Growth Stock Conference, June 3, 2026, Chicago
TD Cowen Technology, Media & Telecom Conference, May 27, 2026, New York
J.P. Morgan Global Technology, Media and Communications Conference, May 18–20, 2026, Boston
Technology Investor Conference Circuit, May–June 2026
Automate 2026 Sets Its Agenda Around AI’s Role in Industrial Transformation, June 22–25, 2026, McCormick Place in Chicago
IBM Think 2026, May 5–8, Boston, Massachusetts, USA

Media Partners

  • Market Analysis
  • Market Research Media
  • Analysis.org
The Repricing and the Drain: How SpaceX, OpenAI, and Anthropic Rewire the Index
Quantum Computing Equities: Market Segment Memo
Quantum Computing Stocks Face Violent Selloff the Moment Markets Reopen Tuesday
The $2.6 Trillion Signal: What Gartner’s AI Spending Forecast Actually Tells You
The Productivity Is Already Here. The Bubble Narrative Is Not.
The Collingridge Dilemma
Why Memory Prices Won’t Come Down
The Bill Comes Due
The Software-Defined Camera Won. The Open OS Did Not.
Cars Are Computers Now, and Most Carmakers Aren’t
Tuesday Open: AI Earnings Engine Holds the Line as Iran Overhang Fades to Noise
China’s U.S. Treasury Holdings: The Great Repositioning (2021–2025)
Infographic: Why the 2025 CIPA Data Proves the APS-C Renaissance is Real
How WiFi Changed Media
Canva Acquires Simtheory and Ortto to Build End-to-End Work Platform
Netflix Price Hikes, The Economics of Dominance in a Saturated Streaming Market
America’s Brands Keep Winning Even as America Itself Slips
Kioxia’s Storage Gambit: Flash Steps Into the AI Memory Hierarchy
Mamdani Strangling New York
The Rise of Faceless Creators: Picsart Launches Persona and Storyline for AI Character-Driven Content
After the 4.18% Rout: Why Next Week’s CPI Matters More Than the Selloff, and What the SpaceX IPO Does to the Recovery
The Nasdaq’s 4.18% Collapse: Worst Day Since the Tariff Shock, and What History Says Comes Next
Broadcom’s AI Revenue Grew 143% and the Stock Fell 12% — The Selloff Has No Basis
The Market Is Selling Hardware, Not the AI Trade
Broadcom Fiscal Q2 2026: The 143% the Tape Ignored
Micron Has Earned Its Place in AI Infrastructure. Its Stock Price Has Not.
Snowflake Q1 FY27: The Sequential Growth Number That Ended the Deceleration Narrative
D-Wave Q1 2026: $11 Billion for a Company That Recognized $2.9 Million in Revenue
The Quantum Rally Playbook Is Running Again. It Ends the Same Way.
After the Euphoria Fades: Quantum Stocks Face a 25% Fall

Copyright © 2026 CybersecurityMarket.com

Media Partners: Technologies · Market Analysis · Market Research · Photography · API Coding · App Coding · Blockchaining · Referently