FireEye report finds sharp drop-off in Chinese cyberattacks on US over past two years
WASHINGTON — Nine months after President Obama and President Xi Jinping of China agreed to a broad crackdown on cyberespionage aimed at curbing the theft of intellectual property …
Context & Ripple Effects
This report lands at the midpoint of a decade-long arc. Weeks earlier, senior executives at security firms had already flagged that Chinese hacking of US companies was slowing ahead of the leaders' meeting, and the Obama–Xi accord on cyber theft followed within days. FireEye's data is the first hard telemetry confirming the diplomatic push produced an actual operational pause.
What makes the finding durable is what came after: Wired's account of how public indictments and an arrest in Canada gave the talks teeth (the coercion playbook behind the 2015 scale-back), and later reporting showing the lull did not hold once pressure eased.
First-order effects
- US companies holding valuable intellectual property get a measurable reprieve from Chinese intrusion attempts, and the Obama administration gains evidence its pact with Xi is being honored rather than signed and ignored.
Second-order effects
- Security vendors like FireEye must reorient threat intelligence around the possibility that Chinese operators are pausing rather than disbanding, while US negotiators can point to verifiable compliance when pressing Beijing on other economic disputes.
Third-order effects
- The pattern that emerges across the decade — a sharp drop after the 2015 pact, then the rebound US officials documented starting in 2017 — suggests bilateral cyber agreements suppress activity only as long as coercive leverage is actively applied, making espionage volume a barometer of diplomatic tension rather than a fixable policy problem.
The trend: State-sponsored Chinese cyberespionage against the US moves in cycles keyed to diplomatic pressure — suppressed by the 2015 Obama–Xi crackdown, resurgent once enforcement lapses — rather than declining structurally.