Chinese Hackers Spying on US Critical Infrastructure, Western Intelligence Says

REUTERS/Kacper Pempel
REUTERS/Kacper Pempel
TT

Chinese Hackers Spying on US Critical Infrastructure, Western Intelligence Says

REUTERS/Kacper Pempel
REUTERS/Kacper Pempel

A state-sponsored Chinese hacking group has been spying on a wide range of US critical infrastructure organizations, from telecommunications to transportation hubs, Western intelligence agencies and Microsoft said on Wednesday.

The espionage has also targeted the US island territory of Guam, home to strategically important American military bases, Microsoft said in a report, adding that "mitigating this attack could be challenging."

While China and the United States routinely spy on each other, analysts say this is one of the largest known Chinese cyber-espionage campaigns against American critical infrastructure, Reuters said.

The Chinese embassy in Washington did not immediately respond to a Reuters request for comment.

It was not immediately clear how many organizations were affected, but the US National Security Agency (NSA) said it was working with partners including Canada, New Zealand, Australia, and the UK, as well as the US Federal Bureau of Investigation to identify breaches. Canada, UK, Australia and New Zealand warned they could be targeted by the hackers too.

Microsoft analysts said they had "moderate confidence" this Chinese group, which it dubbed as 'Volt Typhoon', was developing capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises.

"It means they are preparing for that possibility," added said John Hultquist, who heads threat analysis at Google's Mandiant Intelligence.

The Chinese activity is unique and worrying also because analysts don't yet have enough visibility on what this group might be capable of, he added.

"There is greater interest in this actor because of the geopolitical situation."

As China has stepped up military and diplomatic pressure in its claim to democratically governed Taiwan, US President Joe Biden has said he would be willing to use force to defend Taiwan.

Security analysts expect Chinese hackers could target US military networks and other critical infrastructure if China invades Taiwan.

The NSA and other Western cyber agencies urged companies that operate critical infrastructure to identify malicious activity using the technical guidance they issued.

"It is vital that operators of critical national infrastructure take action to prevent attackers hiding on their systems," Paul Chichester, director at the UK's National Cyber Security Center said in a joint statement with the NSA.

Microsoft said the Chinese hacking group has been active since at least 2021 and has targeted several industries including communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education.

NSA cybersecurity director Rob Joyce said the Chinese campaign was using "built-in network tools to evade our defenses and leaving no trace behind." Such techniques are harder to detect as they use "capabilities already built into critical infrastructure environments," he added.

As opposed to using traditional hacking techniques, which often involve tricking a victim into downloading malicious files, Microsoft said this group infects a victim's existing systems to find information and extract data.

Guam is home to US military facilities that would be key to responding to any conflict in the Asia-Pacific region. It is also a major communications hub connecting Asia and Australia to the United States by multiple submarine cables.

Bart Hoggeveen, a senior analyst at the Australian Strategic Policy Institute who specializes in state-sponsored cyber attacks in the region, said the submarine cables made Guam "a logical target for the Chinese government" to seek intelligence.

"There is high vulnerability when cables land on shore," he said.

New Zealand said it would work towards identifying any such malicious cyber activity in its country.

"It's important for the national security of our country that we're transparent and upfront with Australians about the threats that we face," Australia's Minister for Home Affairs and Cyber Security Clare O'Neil said.

Canada's cybersecurity agency said it had no reports of Canadian victims of this hacking as yet. "However, Western economies are deeply interconnected," it added. "Much of our infrastructure is closely integrated and an attack on one can impact the other."



Officials: Torrential Rains in Kenya Kill 81 in March

Officials: Torrential Rains in Kenya Kill 81 in March
TT

Officials: Torrential Rains in Kenya Kill 81 in March

Officials: Torrential Rains in Kenya Kill 81 in March

Torrential storms that have triggered flash floods in Kenya have killed at least 81 people this month, authorities said Sunday, as rain continued to pound much of the country.

"The cumulative number of fatalities has unfortunately risen to 81," national police spokesman Muchiri Nyaga said in a statement.

"Additionally, flash floods have swept through several areas, displacing approximately 2,690 families and causing widespread destruction of infrastructure and property."

The capital Nairobi is the hardest-hit region, with 37 people killed, he said.

On Friday night, authorities called on residents to evacuate several slum neighborhoods downstream from the Nairobi dam, warning of an imminent risk of flooding as rising water levels threatened to breach the dam embankment, according to local media.

The dam has held so far.

Two people drowned overnight in floods in the town of Kiambu, just outside the capital, police told AFP.

Two also died as landslides hit the western village of Kasaka, burying numerous homes, reported private broadcaster Citizen TV.

The rain is forecast to continue until Tuesday.

Authorities called for "extreme caution".

The March rains have repeatedly turned Nairobi streets to raging rivers, flooding thousands of homes and businesses.

Critics have called for the resignation of Nairobi Governor Johnson Sakaja, who had vowed to improve the capital's drainage and road infrastructure when he took office in 2022.

Scientists say human-caused climate change is increasing the probability, length and severity of extreme weather events.

Studies indicate east Africa has been hit by more extreme rains and droughts over the past two decades.


1 Dead in Istanbul after Gas Explosion Collapses 2 Buildings

Police secure the way to a site where two residential buildings collapsed in Istanbul, Sunday, March 22, 2026. (AP Photo/Khalil Hamra)
Police secure the way to a site where two residential buildings collapsed in Istanbul, Sunday, March 22, 2026. (AP Photo/Khalil Hamra)
TT

1 Dead in Istanbul after Gas Explosion Collapses 2 Buildings

Police secure the way to a site where two residential buildings collapsed in Istanbul, Sunday, March 22, 2026. (AP Photo/Khalil Hamra)
Police secure the way to a site where two residential buildings collapsed in Istanbul, Sunday, March 22, 2026. (AP Photo/Khalil Hamra)

A natural gas explosion in Istanbul’s central Fatih district brought down two buildings on Sunday, killing one person.

Search and rescue personnel pulled out 10 injured who were hospitalized, including one in critical condition, according to a statement by the Istanbul Governor’s office.

The governor, Davut Gul, visited the site of the explosion and checked on survivors at the hospital.

One of the collapsed buildings had two stories, the other one.


Iran Threatens to Retaliate against Gulf Energy and Water after Trump Ultimatum

epa12835579 Liquefied natural gas (LNG) facilities in Ras Laffan Industrial City, in Ras Laffan, Qatar, 25 February 2026 (issued 20 March 2026). Qatar has said Iranian missile attacks on the Ras Laffan Industrial City have caused significant damage to the natural gas industrial complex, located approximately 80 km north-east of Doha. It is operated by Qatar Energy and employs around 115,000 people according to the company.  EPA/HANNIBAL HANSCHKE
epa12835579 Liquefied natural gas (LNG) facilities in Ras Laffan Industrial City, in Ras Laffan, Qatar, 25 February 2026 (issued 20 March 2026). Qatar has said Iranian missile attacks on the Ras Laffan Industrial City have caused significant damage to the natural gas industrial complex, located approximately 80 km north-east of Doha. It is operated by Qatar Energy and employs around 115,000 people according to the company. EPA/HANNIBAL HANSCHKE
TT

Iran Threatens to Retaliate against Gulf Energy and Water after Trump Ultimatum

epa12835579 Liquefied natural gas (LNG) facilities in Ras Laffan Industrial City, in Ras Laffan, Qatar, 25 February 2026 (issued 20 March 2026). Qatar has said Iranian missile attacks on the Ras Laffan Industrial City have caused significant damage to the natural gas industrial complex, located approximately 80 km north-east of Doha. It is operated by Qatar Energy and employs around 115,000 people according to the company.  EPA/HANNIBAL HANSCHKE
epa12835579 Liquefied natural gas (LNG) facilities in Ras Laffan Industrial City, in Ras Laffan, Qatar, 25 February 2026 (issued 20 March 2026). Qatar has said Iranian missile attacks on the Ras Laffan Industrial City have caused significant damage to the natural gas industrial complex, located approximately 80 km north-east of Doha. It is operated by Qatar Energy and employs around 115,000 people according to the company. EPA/HANNIBAL HANSCHKE

Iran said on Sunday it would strike the energy and water systems of its Gulf neighbors in retaliation if US President Donald Trump follows through with a threat to hit Iran's electricity grid in 48 hours, escalating the three-week-old war.

The prospect of tit-for-tat strikes on civilian infrastructure could deepen the regional crisis and rattle global markets when they reopen on Monday morning, Reuters reported.

Air raid sirens sounded across Israel from the early hours of Sunday, warning of incoming missiles from Iran, after scores of people were hurt overnight in two separate attacks in the southern Israeli towns of Arad and Dimona.

The Israeli military said hours later that it was striking Tehran in response.

Trump threatened overnight to "obliterate" Iran's power plants if Tehran did not fully reopen the Strait of Hormuz within 48 hours, barely a day after he talked about "winding down" the war. He made the new threat as US Marines and heavy landing craft are heading to the region.

Iran's Parliament Speaker Mohammad Baqer Qalibaf wrote on X that critical infrastructure and energy facilities in the Middle East could be "irreversibly destroyed" should Iranian power plants be attacked.

Iran's powerful Revolutionary Guards said it would also mean the shipping lane where a fifth of global oil and liquefied natural gas normally transits along Iran's southern coast would remain shut.

"The Strait of Hormuz will be completely closed and will not be opened until our destroyed power plants are rebuilt," the Guards said in a statement.

"President Trump's threat has now placed a 48-hour ticking time bomb of elevated uncertainty over markets," said IG market analyst Tony Sycamore, who expects stock markets to fall when they reopen on Monday.

Oil prices jumped on Friday, ending the day at their highest in nearly four years.

Markets already under severe strain from blockaded shipping were further rattled last week when Israel attacked a major gas field in Iran, and Tehran responded with strikes on neighbors Saudi Arabia, Qatar and Kuwait, raising the prospect of damage hindering energy output even if tankers resume sailing.

Iranian attacks have effectively closed the Strait of Hormuz, causing the worst oil crisis since the 1970s. Its near-closure sent European gas prices surging as much as 35% last week.

"If Iran doesn't FULLY OPEN, WITHOUT THREAT, the Strait of Hormuz, within 48 HOURS from this exact point in time, the United States of America will hit and obliterate their various POWER PLANTS, STARTING WITH THE BIGGEST ONE FIRST!" Trump posted on social media around 7:45 p.m. EDT (2345 GMT) on Saturday.

Iranian media quoted the country's representative to the International Maritime Organisation as saying the strait remains open to all shipping except vessels linked to "Iran's enemies".

Ali Mousavi said passage through the waterway was possible by coordinating security and safety arrangements with Tehran.

Ship-tracking data shows some vessels, such as Indian-flagged ships and a Pakistani oil tanker, have negotiated safe passage through the strait. But the vast majority of ships have remained holed up inside.

Iran's Khatam al-Anbiya military command headquarters said on Sunday if the US hit Iran's fuel and energy infrastructure, Iran would attack all US energy, information technology and desalination infrastructure in the region.

Striking major Iranian power plants could trigger blackouts, crippling everything from pumps and refineries to export terminals and military command centres.