Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
state-sponsored-espionagegovernment-diplomatic-threatvendor-distribution-compromisethird-party-vendor-breach

Suspected Chinese Cyber Operations Targeted U.S. and Belgian Government Networks

Updated 1mo agoFirst seen May 25, 20266 sources

Suspected Chinese hackers were linked to multiple intrusions into Western government systems, including the exploitation of the SolarWinds software supply-chain compromise to access the U.S. National Finance Center, a payroll agency serving several federal departments, according to Reuters sources. In a separate case, Belgian prosecutors opened an investigation into an alleged breach of the country's intelligence service, with reports indicating Chinese state-linked actors may have accessed an external email server used for communications with public prosecutors, police, ministries, and other institutions.

The incidents add to a broader pattern of state-backed cyber espionage focused on sensitive government data and communications infrastructure. The U.S. case highlighted how attackers used a trusted software update channel to reach federal networks, while the Belgian probe underscored concerns that third-party systems connected to intelligence and law-enforcement bodies can become high-value entry points for foreign surveillance operations.

Share:
Suspected Chinese Cyber Operations Targeted U.S. and Belgian Government Networks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Feb 19, 20264mo ago

Russia escalates pressure on Telegram with encryption breach allegations

Russian authorities intensified their campaign against Telegram by alleging that foreign intelligence services could exploit weaknesses in the platform's encryption, claims the company rejected. The dispute added a cyber-security dimension to the broader pressure campaign against the messaging service and its founder.

Dec 5, 20257mo ago

Apple and Google issue new cyber threat alerts to users worldwide

Apple sent a fresh round of threat notifications to users in 84 countries, while Google also warned targeted users about suspected cyber activity. The alerts indicated continued global targeting of individuals with sophisticated spyware or related threats.

Feb 26, 20251y ago

Belgian prosecutor opens probe into alleged hack of state security service

Belgium's federal prosecutor began investigating allegations that Chinese hackers breached the country's intelligence service. The probe signaled formal law-enforcement scrutiny of a suspected state-backed espionage incident.

Mar 6, 20215y ago

Microsoft Exchange hack compromises over 20,000 U.S. organizations

Security experts said exploitation of Microsoft Exchange Server flaws had already compromised more than 20,000 U.S. organizations as mass hacking accelerated. The incident marked a major escalation in the impact of the Exchange vulnerabilities.

Feb 2, 20215y ago

Suspected Chinese hackers used SolarWinds access to target U.S. payroll agency

Sources told Reuters that suspected Chinese hackers exploited a SolarWinds software flaw to spy on the U.S. National Finance Center, which handles payroll for multiple federal agencies. The report identified a separate espionage operation from the Russia-linked SolarWinds compromise.

Dec 18, 20206y ago

Microsoft says malicious SolarWinds-linked software reached its systems

Microsoft disclosed that it had found malicious software in its environment as part of the broader SolarWinds breach investigation. The company said it found no evidence its production services or customer data were affected, but the announcement marked a major confirmation that a leading technology provider was also impacted.

Microsoft says it found malicious software in its systems | Reuters
Jan 4, 20188y ago

Researchers disclose Spectre and Meltdown processor flaws

Major security flaws affecting chips used in most phones and computers were publicly disclosed, exposing systems to potential data theft across vendors and platforms. The revelations prompted emergency mitigation efforts by hardware and software companies.

Jul 5, 20179y ago

Bithumb discloses hack affecting user accounts and funds

South Korean cryptocurrency exchange Bithumb reported that hackers stole customer data and funds, including losses tied to compromised user accounts. The incident was disclosed in early July 2017.

Jun 29, 20179y ago

Ukrainian officials say global cyberattack masked malware deployment

During the June 2017 NotPetya outbreak, a Ukrainian police official said the worldwide cyberattack was likely intended to cover installation of malware in Ukraine. The statement reframed the incident as a targeted operation rather than ordinary ransomware.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.