Documents and officials: the US is investigating if Rockwell Automation's facility in China is exposing critical government assets to a potential cyberattack
updating software to fix vulnerabilities—using only Chinese nationals at the facility in Dalian, a port city at the southern tip of China's Liaoning province.” https://www.wsj.com/... Matthew Pines / @matthew_pines : This is a BFD. Major natsec risk. “...Rockwell does its code development, support and patching—updating software to fix vulnerabilities—using only Chinese nationals at the facility in Dalian, a port city at the southern tip of China's Liaoning province.” https://www.wsj.com/... Bill Bishop / @niubi : A U.S. government probe is looking at whether a Rockwell Automation operation in China might allow access to critical American government and industrial infrastructure https://www.wsj.com/... via @WSJ Jonathan Cheng / @jchengwsj : The Biden administration is investigating whether industrial technology giant Rockwell Automation is exposing U.S. infrastructure and military assets through a China-based facility, according to U.S. officials and documents reviewed by the WSJ. @vmsalama https://www.wsj.com/...
Context & Ripple Effects
The probe lands in a decade-long arc of China-linked intrusions into US networks: officials traced breaches of Navy contractors stealing military technology back in 2018, Chinese hackers exploited SolarWinds software to reach a USDA payroll agency in 2020, and Microsoft warned in 2023 that [[a:840441|Chinese state-sponsored hackers were compromising critical infrastructure organizations across US industries]]. The Rockwell case differs in kind: rather than an intrusion to detect, it is a US company's own maintenance pipeline — patching done only by Chinese nationals in Dalian — under investigation as the exposure itself.
The timing matters against two later developments: the [[a:843866|Atlantic Council's finding that China's 2021 law forces companies to disclose software flaws to authorities within two days]], which turns any China-based patching operation into a potential intelligence channel, and the Salt Typhoon campaign that breached US ISPs and potentially reached wiretap systems, which showed how deep into US communications infrastructure Beijing-linked access had already run.
First-order effects
- Rockwell Automation faces a US government investigation into whether its Dalian facility — the sole site for code development, support, and patching — exposes government, industrial, and military customers to cyberattack, putting its federal-facing business under direct scrutiny.
- US government and military customers relying on Rockwell's software must now evaluate whether patches and support updates routed through Dalian represent an attack surface, not just a maintenance service.
Second-order effects
- Rival industrial-automation vendors with offshore support footprints in China face pressure to restructure where patching and code work happens, or to explain to US government buyers why their pipelines differ from Rockwell's.
- The Atlantic Council's finding that China's two-day vulnerability-disclosure law feeds its hacking operations makes any China-staffed maintenance operation a policy problem, not just a security one — procurement rules, not just firewalls, become the response.
Third-order effects
- If the pattern holds, US industrial and infrastructure software will structurally decouple from Chinese-based development and support, mirroring the chip export-control logic: the question shifts from who owns the technology to who can touch the code that keeps it running.
- Expect supply-chain security scrutiny to extend from hardware provenance to maintenance labor — audits of where patching happens could become a standing condition for vendors selling into US government and critical infrastructure.
The trend: US-China technology security is moving from defending against intrusions to auditing who maintains the software inside American infrastructure, with maintenance geography becoming a national-security variable.