Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
state-sponsored-espionagetelecommunications-sector-threatgovernment-diplomatic-threatcritical-infrastructure-threat

China-Linked Espionage Campaign Hit Telecoms, Cloud Email, and Manufacturers

Updated 1mo agoFirst seen May 25, 20265 sources

China-linked hacking groups were reported to have penetrated a wide range of targets across the United States and allied regions, including manufacturers, U.S. government email systems, internet providers, and major telecommunications networks. Earlier reporting described broad economic espionage aimed at stealing trade secrets from manufacturing sectors in the U.S., Europe, and Asia, while later disclosures said Chinese operators breached U.S. government email accounts through Microsoft cloud infrastructure and infiltrated American internet providers for surveillance. Subsequent investigations tied the telecom intrusions to the Salt Typhoon campaign, which officials said exposed sensitive metadata and provided insight into U.S. surveillance targets.

U.S. officials characterized the activity, alongside related operations such as Volt Typhoon, as one of the most serious cyber threats to American critical infrastructure in recent years. Reporting said investigators believed the attackers may have retained access to at least eight telecom firms, including Verizon and AT&T, and that the campaign extended to dozens of telecoms and government agencies. In response, the Biden administration moved to bar the remaining U.S. operations of China Telecom Americas, citing national security risks and signaling the first public retaliatory step tied to the telecom compromises, even as debate continued over broader sanctions, technology restrictions, and offensive cyber responses.

Share:
China-Linked Espionage Campaign Hit Telecoms, Cloud Email, and Manufacturers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Feb 25, 20264mo ago

China-linked hackers reported to have breached dozens of telecoms and agencies

Reporting in early 2026 said China-linked hackers had breached dozens of telecommunications companies and government agencies, showing the scope of the campaign had expanded well beyond the initially disclosed victims.

Dec 16, 20242y ago

Biden administration moves to ban remaining China Telecom Americas operations

The Biden administration announced a first public retaliatory step against the China-linked telecom hacking campaign by moving to ban the remaining U.S. operations of China Telecom Americas, citing national security risks tied to its network presence and cloud services.

U.S. identifies Salt Typhoon telecom compromise as major espionage campaign

By December 2024, U.S. officials had concluded that China's Salt Typhoon campaign broadly compromised American telecommunications networks, with investigators believing the hackers may still have access to at least eight telecom firms, including Verizon and AT&T, and had obtained sensitive metadata and insight into U.S. surveillance targets.

Oct 25, 20242y ago

Chinese hackers target phones tied to Trump, Vance, and Harris associates

AP reported that China-linked hackers targeted cellphones used by Donald Trump, JD Vance, and individuals associated with Kamala Harris’s campaign as part of a broader intrusion into commercial telecommunications infrastructure. U.S. officials were still investigating what data, if any, had been accessed.

Chinese hackers targeted cellphones used by Trump and Vance, AP sources say | AP News
Aug 27, 20242y ago

Chinese government hackers penetrate U.S. internet providers

The Washington Post reported that Chinese government hackers had infiltrated U.S. internet service providers to conduct espionage, indicating a deeper compromise of core communications infrastructure.

Jul 12, 20233y ago

Chinese hackers breach U.S. government email via Microsoft cloud

Chinese hackers penetrated U.S. government email accounts through Microsoft's cloud environment, exposing communications from federal agencies and marking a significant escalation in Beijing-linked cyber espionage against U.S. institutions.

May 4, 20224y ago

Researchers detail broad Chinese espionage against manufacturers

Researchers reported that China-linked hackers had conducted a wide-ranging economic espionage campaign targeting manufacturing organizations in the United States, Europe, and Asia to steal trade secrets and other sensitive business information.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.