US moves to block Chinese hacking against hospitals, NASA, Fed, Senate, more | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


(CNN) — U.S. officials on Wednesday in Washington said they uncovered a major alleged Chinese cyberespionage campaign that they say compromised or attacked numerous federal agencies, including NASA, the Federal Reserve, the departments of Justice and Energy, and the U.S. Senate.

Officials said hackers tied to China’s military and intelligence services allegedly used a Chinese technology company to hide their activity, enter target networks and make their operations more efficient. The Justice Department also cited other targets, including U.S. military networks, hospitals, power companies and defense contractors.

The department said it sought to limit further damage Wednesday by seizing three internet domains associated with the Chinese company. Federal agencies also plan to publish an advisory describing the hackers’ methods so affected companies can remove the intruders.

Officials said the full impact of the alleged espionage was not immediately clear. They also said security concerns may lead them to keep damage assessments private.

The hacking started in 2018 and continued through 2026, the officials said, citing an FBI affidavit supporting the domain seizures. The affidavit names three unnamed Department of Energy National Laboratories, the National Institutes of Health, and a Department of Health and Human Services agency as organizations affected by the alleged activity. It also states the Justice Department, the Federal Reserve, NASA and the Senate were targeted.

“The Chinese government firmly opposes and combats all forms of cyberattacks in accordance with the law,” a spokesperson for the Chinese Embassy in Washington, D.C., said. “We urge the U.S. side to stop using cybersecurity issues to smear or discredit China.”

The announcement follows a yearslong series of alleged Chinese hacking efforts against critical U.S. infrastructure, such as power plants and banks.

Cybersecurity has fueled tension for years in U.S.-China relations. In 2023, U.S. officials accused China of targeting military transportation networks, water systems and power companies to potentially sabotage U.S. responses to a Chinese invasion of Taiwan. China denied those allegations.

U.S. officials and major U.S. phone companies also spent months in 2024 investigating alleged Chinese infiltration of telecom networks. The alleged targets included then-presidential candidate Donald Trump and running mate JD Vance.

In an interview on Fox News on Wednesday, Attorney General Blanche said she would not tell President Trump what he should raise with Chinese leader Xi Jinping during the leader’s visit next month.

“I’m not going to tell President Trump what he needs to talk to the leadership about in China,” Blanche said.

She added: “This is something that we have talked about with our counterparts in China for many, many years. And we know that it’s happening. And they know that we know that it’s happening. And it has to stop.”

Effort to unravel operation

Wednesday’s announcement followed a lengthy effort by the FBI and the National Security Agency to unwind an alleged yearslong deception operation.

Officials identified the Chinese firm as the Nanjing Xinjiuwei Network Technology Company. Chinese business records show the company formed in 2018 and had 17 employees as of last year.

Court filings allege the company employs former members of China’s People’s Liberation Army who use military connections to obtain contracts and subcontracts supporting offensive cyber operations.

CNN attempted to reach the Nanjing-based company for comment. The firm recently posted job ads for cybersecurity engineers capable of “large-scale penetration projects,” based on a review of Chinese job recruitment websites.

China’s military and the Ministry of State Security used the company’s services to blend into everyday internet traffic, according to U.S. officials.

Lumen Technologies, a U.S. firm that monitors internet activity, reported Wednesday that the hackers profiled and interacted with infrastructure globally while remaining hidden in routine consumer network traffic.

Damon Rouse, a senior security engineer at Lumen’s Black Lotus Labs, said the Chinese firm’s involvement may have left a paper trail for investigators.

“If you’re getting paying customers, you have a paper trail,” Rouse said. He added: “I hadn’t seen a fully self-contained ecosystem like this in my career.”

Rouse said he has studied multiple ways suspected Chinese hackers route their activity to avoid detection, but he said the Chinese company’s services provided the most complete arrangement he had seen.

In 2024, a major leak from another Chinese company revealed a client list that included Chinese police, intelligence and military organizations. That leak identified hospitals in Taiwan and Tibetan exile-run political groups as affected organizations.

“China’s hackers have professionalized significantly in the last decade,” said Dakota Cary, a China analyst at security firm SentinelOne. “Companies offering services to the state have proliferated and now offer niche services. Not only do these companies make China’s hackers more effective, they make it harder for defenders to cluster activity.”

Cary also said: “Wednesday’s actions from the U.S. government are necessary to disrupting China’s operations at scale, but the robust market for offensive services in China guarantees their return to operations.”

CNN’s Hannah Rabinowitz and Yong Xiong contributed reporting.





Click Here For The Original Source.

——————————————————–

..........

.

.