Tuesday 4 August, 2026
[email protected]
Resilience Media
  • News
    • Events
    • Interview
    • Startups
    • Venture
    • Weekly Digest
  • Resilience Conference
    • Resilience Conference London — Oct 2026
    • Resilience Conference Copenhagen — May 2026 (PAST)
    • Resilience Conference Warsaw — Apr 2026 (PAST)
  • About
  • Launch
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
  • News
    • Events
    • Interview
    • Startups
    • Venture
    • Weekly Digest
  • Resilience Conference
    • Resilience Conference London — Oct 2026
    • Resilience Conference Copenhagen — May 2026 (PAST)
    • Resilience Conference Warsaw — Apr 2026 (PAST)
  • About
  • Launch
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
Resilience Media
No Result
View All Result

China’s Years-Long Salt Typhoon Hack Penetrates Military And Government Networks Worldwide

Officials say Chinese state-backed hackers have accessed military networks in more than 80 countries, exposing critical weaknesses in the systems that underpin global defence

Carly PagebyCarly Page
September 4, 2025
in News
Photo by Markus Spiske on Unsplash

Photo by Markus Spiske on Unsplash

Share on Linkedin

Chinese state-backed hackers have infiltrated government and military infrastructure networks worldwide in one of the most significant cyber-espionage campaigns ever uncovered.

You Might Also Like

Ore Energy raises $43m to scale iron-air batteries for Europe’s AI boom

Taiwan’s defence plans are up in the air

Weekly Digest: Agon, Nuclear Turbines come out of stealth; Germany’s new growth stage fund; Amelia Gould joins Kraken; General Catalyst on stage at Resilience Conference

The group, known as Salt Typhoon, exploited weaknesses in networks to gain persistent access to critical systems across more than 80 countries, intelligence and cybersecurity agencies from 13 countries have warned in a joint statement, raising serious concerns about the integrity of military communications and command networks.

“People’s Republic of China (PRC) state-sponsored cyber threat actors are targeting networks globally, including, but not limited to, telecommunications, government, transportation, lodging, and military infrastructure networks,” the statement said.

The years-long campaign has been described by Western intelligence agencies as “indiscriminate” and “unprecedented” in scale. Officials believe that data relating to nearly all Americans may have been swept up in the intrusion, according to The New York Times, a reflection of just how deep the compromise ran through national telecoms infrastructure.

Salt Typhoon was first thrust into the spotlight in December 2024, when US officials disclosed that the group had pulled off what they called the worst cyber intrusion in the country’s history. The revelation that major telecom carriers and government-connected systems had been breached prompted urgent warnings in Washington and demands to treat the incident as a full-blown national security emergency.

Subsequent investigations have shown that the operation stretches back much further, with officials now believing that Salt Typhoon has been performing malicious operations globally since at least 2021.

The joint advisory, issued by the US, UK, Germany, Italy, Finland, Spain, Canada, Australia, Japan, and South Korea, said that by compromising backbone, provider-edge, and customer-edge routers, the China-backed attackers were able to establish footholds deep inside networks that support day-to-day communications and military infrastructure.

The advisory noted that once inside, Salt Typhoon could intercept voice and data traffic, collect metadata, and potentially monitor or disrupt military operations.

Investigators have linked the Salt Typhoon campaign to three China-based technology firms active since at least 2019, though the scale of their activities only came to light last year. (The three firms are not recognised names. They are Sichuan Juxinhe Network Technology Co. Ltd. (四川聚信和网络科技有限公司); Beijing
Huanyu Tianqiong Information Technology Co., Ltd. (北京寰宇天穹信息技术有限公司); and Sichuan Zhixin Ruijie Network Technology Co., Ltd. (四川智信锐捷网络科技有限公司.)

According to the joint statement, these three companies were working on behalf of both China’s intelligence services, including multiple units in the People’s Liberation Army and the Ministry of State Security, to conduct overseas operations.

This equipped Chinese intelligence services with “the capability to identify and track their targets’ communications and movements around the world,” according to the statement.

“We are deeply concerned by the irresponsible behaviour of the named commercial entities based in China that has enabled an unrestrained campaign of malicious cyber activities on a global scale,” Dr Richard Horne, chief executive of the UK’s National Cyber Security Centre, said in a statement sent to Resilience Media. “It is crucial organisations in targeted critical sectors heed this international warning about the threat posed by cyber actors, who have been exploiting publicly known – and so therefore fixable – vulnerabilities.”

The technical details revealed in the joint advisory, which highlights that Salt Typhoon has been exploiting common vulnerabilities in products from major IT suppliers Ivanti, Palo Alto Networks, and Cisco — these are named in the advisory — underline the scale of the task now facing militaries and their suppliers.

Defence ministries have been urged to adopt zero-trust principles across their IT and operational technology environments, enforce stricter segmentation between critical systems, and deploy active hunt teams to search for evidence of persistent access. (We are reaching out to the three IT companies and will update this post as we learn more.)

The campaign has also underscored the importance of allied collaboration. Intelligence-sharing across NATO members and partners in Asia has been credited with helping to piece together the scale of Salt Typhoon’s activity. Officials say that the same collaborative approach must now extend to hardening networks, particularly where military operations depend on commercial telecoms and satellite links.

In response to the joint statement, the Chinese Foreign Ministry pushed back, accusing the US and its allies of “smearing” China under the guise of cybersecurity and framing the campaign as a political stunt.

Spokesperson Guo Jiaku alleged that the Salt Typhoon narrative was built to justify increased US budgets and deflect attention from America’s own cyber-intrusion practices, and urged Washington to “reflect more on what it’s doing instead of forming small groupings to smear others.”

Tags: ChinaGuo JiakuNational Cyber Security CentreRichard Horne
Previous Post

Sola Raises $35M to Ramp Up Its AI-based Cybersecurity Tooling

Next Post

How Independent Are We When It Comes to Tech?

Carly Page

Carly Page

Carly Page is a freelance journalist and copywriter with 10+ years of experience covering the technology industry, and was formerly a senior cybersecurity reporter at TechCrunch. Bylines include Forbes, IT Pro, LeadDev, The Register, TechCrunch, TechFinitive, TechRadar, TES, The Telegraph, TIME, Uswitch, WIRED, & more.

Related News

Ore Energy raises $43m to scale iron-air batteries for Europe’s AI boom

Ore Energy raises $43m to scale iron-air batteries for Europe’s AI boom

byCarly Page
August 4, 2026

Amsterdam-based Ore Energy has raised $43 million (£32 million) in Series A funding to commercialise its iron-air battery technology, betting...

Taiwan’s defence plans are up in the air

Taiwan’s defence plans are up in the air

byHarry Saunders
July 31, 2026

For an island nation with no regional ambitions and territory roughly the size of the Netherlands, Taiwan has an impressive...

Weekly Digest: Agon, Nuclear Turbines come out of stealth; Germany’s new growth stage fund; Amelia Gould joins Kraken; General Catalyst on stage at Resilience Conference

Weekly Digest: Agon, Nuclear Turbines come out of stealth; Germany’s new growth stage fund; Amelia Gould joins Kraken; General Catalyst on stage at Resilience Conference

byLeslie Hitchcock
July 30, 2026

Good afternoon from Resilience Media. Last week saw the devastating missile attack on a defence tech demo day in the Kyiv region...

Weekly Digest: Hypersonic weapons race accelerates as NATO eyes Russian and Chinese missile threats

What 100+ Defence Tech Startup Applications Reveal About Europe’s Next Wave of Innovation

byAltea Fresia
July 30, 2026

LAUNCH @ Resilience Conference is our showcase for the most exciting early-stage startups in defence, security, and resilience, where they...

Digest 46: What Netflix’s ‘A House of Dynamite’ gets right, according to defence experts

General Catalyst’s Jeannette zu Fürstenberg to Speak at Resilience Conference London 2026

byLeslie Hitchcock
July 30, 2026

Resilience Conference London is pleased to announce that Jeannette zu Fürstenberg, Managing Director and Head of Europe at General Catalyst,...

Auterion’s CEO on drone warfare, interceptors, and the operating system for autonomy

Auterion’s CEO on drone warfare, interceptors, and the operating system for autonomy

byJohn Biggs
July 29, 2026

Auterion has spent the past few years building software for the drone war. Now it is applying the same logic...

Military canvas bag and boxes on wooden crates

UK Ministry of Defence to give 22 British SMEs up to £300,000 for munitions proposals

byFiona Alston
July 29, 2026

The UK Ministry of Defence (MOD) is looking for at least six new munitions and energetics factories, by way of...

Agon emerges from stealth with $30M to build AI training models for defence

Agon emerges from stealth with $30M to build AI training models for defence

byIngrid Lunden
July 29, 2026

A new London startup, founded by a team with roots in defence and AI, is emerging from stealth this morning,...

Load More
Next Post
How Independent Are We When It Comes to Tech?

How Independent Are We When It Comes to Tech?

Stark Raises $62M For Its Strike Drones and UAV Control Systems, Offset Labs Secures Seed Funding For Its Defence and National Security AI Lab

Stark Raises $62M For Its Strike Drones and UAV Control Systems, Offset Labs Secures Seed Funding For Its Defence and National Security AI Lab

Top stories

Agon emerges from stealth with $30M to build AI training models for defence
European Defence

Agon emerges from stealth with $30M to build AI training models for defence

July 29, 2026
Ministry of Defence HQ
News

Selling to the UK MoD is full of friction for defence startups; but it doesn’t have to be like that

July 29, 2026
UK MoD tests British-built anti-Shahed system in Jordan
News

SCOOP: Cambridge Aerospace is closing in on $300M at a $3.4B valuation

July 15, 2026
Kelluu brings persistent airship surveillance to the Arctic, expands to Canada
Drones & UAS

Kelluu brings persistent airship surveillance to the Arctic, expands to Canada

July 28, 2026

Resilience Media is an independent publication covering the future of defence, security, and resilience. Our reporting focuses on emerging technologies, strategic threats, and the growing role of startups and investors in the defence of democracy.

  • About
  • News
  • Resilence Conference
    • Resilience Conference Copenhagen 2026
    • Resilience Conference Warsaw 2026
    • Resilience Conference 2026
  • Guest Posts
  • Subscribe
  • Privacy Policy
  • Terms & Conditions
  • Mission Statement & Code of Practice
  • Press

© 2026 Resilience Media

No Result
View All Result
  • Home
  • About
  • Subscribe
  • Events
  • Guest Posts
  • Interview
  • News
  • Resilience Conference London 2026
  • Resilience Conference Copenhagen 2026
  • Resilience Conference Warsaw 2026

© 2026 Resilience Media

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.