Chinese Hackers Spying on US Critical Infrastructure, Western Intelligence Says

REUTERS/Kacper Pempel
REUTERS/Kacper Pempel
TT

Chinese Hackers Spying on US Critical Infrastructure, Western Intelligence Says

REUTERS/Kacper Pempel
REUTERS/Kacper Pempel

A state-sponsored Chinese hacking group has been spying on a wide range of US critical infrastructure organizations, from telecommunications to transportation hubs, Western intelligence agencies and Microsoft said on Wednesday.

The espionage has also targeted the US island territory of Guam, home to strategically important American military bases, Microsoft said in a report, adding that "mitigating this attack could be challenging."

While China and the United States routinely spy on each other, analysts say this is one of the largest known Chinese cyber-espionage campaigns against American critical infrastructure, Reuters said.

The Chinese embassy in Washington did not immediately respond to a Reuters request for comment.

It was not immediately clear how many organizations were affected, but the US National Security Agency (NSA) said it was working with partners including Canada, New Zealand, Australia, and the UK, as well as the US Federal Bureau of Investigation to identify breaches. Canada, UK, Australia and New Zealand warned they could be targeted by the hackers too.

Microsoft analysts said they had "moderate confidence" this Chinese group, which it dubbed as 'Volt Typhoon', was developing capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises.

"It means they are preparing for that possibility," added said John Hultquist, who heads threat analysis at Google's Mandiant Intelligence.

The Chinese activity is unique and worrying also because analysts don't yet have enough visibility on what this group might be capable of, he added.

"There is greater interest in this actor because of the geopolitical situation."

As China has stepped up military and diplomatic pressure in its claim to democratically governed Taiwan, US President Joe Biden has said he would be willing to use force to defend Taiwan.

Security analysts expect Chinese hackers could target US military networks and other critical infrastructure if China invades Taiwan.

The NSA and other Western cyber agencies urged companies that operate critical infrastructure to identify malicious activity using the technical guidance they issued.

"It is vital that operators of critical national infrastructure take action to prevent attackers hiding on their systems," Paul Chichester, director at the UK's National Cyber Security Center said in a joint statement with the NSA.

Microsoft said the Chinese hacking group has been active since at least 2021 and has targeted several industries including communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education.

NSA cybersecurity director Rob Joyce said the Chinese campaign was using "built-in network tools to evade our defenses and leaving no trace behind." Such techniques are harder to detect as they use "capabilities already built into critical infrastructure environments," he added.

As opposed to using traditional hacking techniques, which often involve tricking a victim into downloading malicious files, Microsoft said this group infects a victim's existing systems to find information and extract data.

Guam is home to US military facilities that would be key to responding to any conflict in the Asia-Pacific region. It is also a major communications hub connecting Asia and Australia to the United States by multiple submarine cables.

Bart Hoggeveen, a senior analyst at the Australian Strategic Policy Institute who specializes in state-sponsored cyber attacks in the region, said the submarine cables made Guam "a logical target for the Chinese government" to seek intelligence.

"There is high vulnerability when cables land on shore," he said.

New Zealand said it would work towards identifying any such malicious cyber activity in its country.

"It's important for the national security of our country that we're transparent and upfront with Australians about the threats that we face," Australia's Minister for Home Affairs and Cyber Security Clare O'Neil said.

Canada's cybersecurity agency said it had no reports of Canadian victims of this hacking as yet. "However, Western economies are deeply interconnected," it added. "Much of our infrastructure is closely integrated and an attack on one can impact the other."



Thousands of Somalis Protest Israeli Recognition of Somaliland

This picture taken on November 7, 2024 shows a general view of the city of Hargeisa, capital and largest city of the self-proclaimed Republic of Somaliland. (Photo by LUIS TATO / AFP)
This picture taken on November 7, 2024 shows a general view of the city of Hargeisa, capital and largest city of the self-proclaimed Republic of Somaliland. (Photo by LUIS TATO / AFP)
TT

Thousands of Somalis Protest Israeli Recognition of Somaliland

This picture taken on November 7, 2024 shows a general view of the city of Hargeisa, capital and largest city of the self-proclaimed Republic of Somaliland. (Photo by LUIS TATO / AFP)
This picture taken on November 7, 2024 shows a general view of the city of Hargeisa, capital and largest city of the self-proclaimed Republic of Somaliland. (Photo by LUIS TATO / AFP)

Large protests broke out in several towns and cities across Somalia on Tuesday in opposition to Israel's recognition of the breakaway region of Somaliland.

Israel announced on Friday that it viewed Somaliland -- which declared independence in 1991 but has never been recognized by any other country -- as an "independent and sovereign state".

Somali President Hassan Sheikh Mohamud has condemned the move as a threat to stability in the Horn of Africa. He travelled Tuesday to Türkiye, a close ally, to discuss the situation, AFP reported.

Thousands of protesters marched through the streets of Somali capital Mogadishu and gathered at a stadium, waving placards with anti-Israeli slogans alongside Somali and Palestinian flags.

"We will never allow anyone to violate our sovereignty," one attendee, Adan Muhidin, told AFP, adding that Israel's move was "a blatant violation of international law".

Demonstrations also took place in Lascanod in the northeast, Guriceel in central Somalia, and Baidoa in the southwest.

"There is nothing we have in common with Israel. We say to the people of Somaliland, don't bring them close to you," said Sheikh Ahmed Moalim, a local religious leader, in Guriceel.

Somaliland has long been a haven of stability and democracy in the conflict-scarred country, with its own money, passport and army.

It also has a strategic position on the Gulf of Aden that makes it an attractive trade and military partner for regional and international allies.

But Israel's decision to recognize its statehood has brought rebukes from across the Muslim and African world, with many fearing it will stoke conflict and division.

There have been celebrations in Somaliland's capital Hargeisa, with the rare sight of Israeli flags being waved in a Muslim-majority nation.


Iranian Students Protest in Tehran and Isfahan, Says Local Media

Shopkeepers and traders walk over a bridge during a protest against the economic conditions and Iran's embattled currency in Tehran on December 29, 2025. (Handout / Fars News Agency / AFP)
Shopkeepers and traders walk over a bridge during a protest against the economic conditions and Iran's embattled currency in Tehran on December 29, 2025. (Handout / Fars News Agency / AFP)
TT

Iranian Students Protest in Tehran and Isfahan, Says Local Media

Shopkeepers and traders walk over a bridge during a protest against the economic conditions and Iran's embattled currency in Tehran on December 29, 2025. (Handout / Fars News Agency / AFP)
Shopkeepers and traders walk over a bridge during a protest against the economic conditions and Iran's embattled currency in Tehran on December 29, 2025. (Handout / Fars News Agency / AFP)

Student protests erupted on Tuesday at universities in the capital Tehran and the central city of Isfahan, decrying declining living standards following demonstrations by shopkeepers, local media reported.

"Demonstrations took place in Tehran at the universities of Beheshti, Khajeh Nasir, Sharif, Amir Kabir, Science and Culture, and Science and Technology, as well as the Isfahan University of Technology," reported Ilna, a news agency affiliated with the labor movement.


Iran Designates Royal Canadian Navy a Terrorist Organization

Iranians drive past a huge banner of former Iranian Revolutionary Guard Corps (IRGC) Quds Force commander Qassem Soleimani ahead of the sixth anniversary of his assassination at Valiasr Square in Tehran, Iran, 30 December 2025. (EPA)
Iranians drive past a huge banner of former Iranian Revolutionary Guard Corps (IRGC) Quds Force commander Qassem Soleimani ahead of the sixth anniversary of his assassination at Valiasr Square in Tehran, Iran, 30 December 2025. (EPA)
TT

Iran Designates Royal Canadian Navy a Terrorist Organization

Iranians drive past a huge banner of former Iranian Revolutionary Guard Corps (IRGC) Quds Force commander Qassem Soleimani ahead of the sixth anniversary of his assassination at Valiasr Square in Tehran, Iran, 30 December 2025. (EPA)
Iranians drive past a huge banner of former Iranian Revolutionary Guard Corps (IRGC) Quds Force commander Qassem Soleimani ahead of the sixth anniversary of his assassination at Valiasr Square in Tehran, Iran, 30 December 2025. (EPA)

The Iranian foreign ministry designated the Royal Canadian Navy a terrorist organization on Tuesday in what it said was retaliation for Canada's 2024 blacklisting of Iran's Revolutionary Guards.

In a statement, the ministry said that the move was in reaction to Ottawa declaring the Guards, the ideological arm of Iran's military, a terror group "contrary to the fundamental principles of international law".

Iran "within the framework of reciprocity, identifies and declares the Royal Canadian Navy as a terrorist organization," the statement added, without specifying what ramifications if any the force will face.

On June 19, 2024, Canada declared the IRGC a terror group. This bars its members from entering the country and Canadians from having any dealings with individual members or the group.

Additionally, any assets the Guards or its members hold in Canada could also be seized.
Canada accused the Guards of "having consistently displayed disregard for human rights both inside and outside of Iran, as well as a willingness to destabilize the international rules-based order."

One of the reasons behind Ottawa's decision to designate the force as a terror group was the Flight PS752 incident.

The flight was show down shortly after takeoff from Tehran in January 2020, killing all 176 passengers and crew, including 85 Canadian citizens and permanent residents.

The IRGC admitted its forces downed the jet, but claimed their controllers had mistaken it for a hostile target.

Ottawa broke off diplomatic ties with Tehran in 2012, calling Iran "the most significant threat to global peace".

Iran's archenemy, the United States, listed the Guards as a foreign terrorist organization in April 2019 while Australia did the same last month, accusing the force of being behind attacks on Australian soil.