US, UK, Australia, Canada, and New Zealand advisory: China-backed hacking group Volt Typhoon has had access to some major US infrastructure for over five years
The advisory escalates concern first raised when Microsoft reported compromises at critical-infrastructure organizations across US industries, making the issue one of sustained access rather than a discrete intrusion earlier reports of critical-infrastructure compromise.
US infrastructure operators and the five governments’ cyber agencies must treat Volt Typhoon exposure as a potentially long-running compromise, prioritizing threat hunting, credential review, and remediation over one-time incident cleanup.
The joint advisory aligns the US, UK, Australia, Canada, and New Zealand around a shared public assessment of the group’s access to US infrastructure.
Second-order effects
The duration of the alleged access raises pressure on infrastructure vendors and service providers to help customers determine whether old compromises persist in interconnected operational environments.
Allied attribution increases the diplomatic and security cost of China-linked activity, while giving other critical-network operators a stronger basis to review comparable exposure.
Third-order effects
If long-dwell access to infrastructure becomes a recurring pattern, critical-infrastructure security will shift further toward continuous resilience and recovery planning rather than perimeter-focused prevention.
The later reported link between Volt Typhoon activity and tensions over Taiwan suggests cyber persistence may become more tightly treated as part of geopolitical deterrence, though the operational intent in any individual intrusion remains difficult to establish reported Chinese acknowledgment of the Volt Typhoon campaign.
The trend: This is one data point in the shift from cyber espionage centered on information collection toward persistent access to strategically important networks during geopolitical competition.
Along with @NSACyber, @FBI, @ENERGY, @EPA, @TSA, @CyberGovAU, @cybercentre_ca, @NCSC & NCSC-NZ, we published an advisory on how to protect against cyber threats from People's Republic of China (PRC) state-sponsored cyber actor #VoltTyphoon 👉 https://go.dhs.gov/JxV [image]
.@CISAgov and our U.S. government partners have confirmed that a group of PRC state-sponsored cyber actors has compromised entities across multiple critical infrastructure sectors in cyberspace. Learn about how to keep your organization safe: https://www.cisa.gov/...
🚨 Today, the UK and international partners have issued a fresh warning to critical infrastructure operators about the threat of cyber attackers using sophisticated techniques to hide on victims' networks: https://www.ncsc.gov.uk/...
CISA report on Volt Typhoon reveals focus on OT systems following compromise and access at least once. Given known targeting, the threat is pretty clear. Possible that they may be reluctant to traverse into the OT systems, seeing that as escalatory. https://www.cisa.gov/...
People's Republic of China-sponsored actors are targeting U.S. critical infrastructure, pre-positioning for disruptive actions. We've joined with @CISACyber, @FBI, and others to address this activity. Read our advisory now: https://www.nsa.gov/... [image]
NEW: US #cybersecurity advisory warns activity by #China-linked hackers known as #VoltTyphoon shows #Beijing “positioning itself to launch destructive cyber-attacks that would jeopardize the physical safety of Americans” Some critical systems compromised “for at least 5 years”
🌐@CISAgov with our government and international partners released a joint guide to help network defenders mitigate and detect living off the land techniques exploited by the PRC-sponsored #VoltTyphoon group to target U.S. critical infrastructure. https://go.dhs.gov/JNb [image]
I testified to Congress last week about China's threat to our nation's critical infrastructure. Today, with our partners, we showed part of this threat in our Volt Typhoon advisory: https://go.dhs.gov/JfP What we've found to date is likely the tip of the iceberg. [image]
Important technical advisory released by US @CISAgov today and supported by our @CyberGovAU. Crucial info for network defenders to detect and mitigate LoTL techniques
Today we released a joint advisory with international partners to warn that PRC state-sponsored group Volt Typhoon has compromised the IT environments of multiple critical infrastructure organisations based in the US. Read more https://www.cyber.gov.au/... [image]