China's hacking activities are increasingly resembling those of Russia and North Korea after the Ministry of State Security largely took over operations in 2015
Andy Greenberg / Wired : Tweets: @benjamint0001 Tweets: BenjaminT / @benjamint0001 : China's hackers have gotten far more aggressive since 2015, when the Ministry of State Security largely took over the country's cyber espionage - BTW, tons of Chinese universities with American partnership have been known for stealing US IPs. https://www.wired.com/...
Context & Ripple Effects
When the Ministry of State Security absorbed most of China's cyber espionage apparatus in 2015, the reorganization looked like bureaucratic housekeeping; the decade since suggests it was a strategic pivot. Researchers had already documented a tactical drift toward attacks targeting ethnic minorities (switched tactics against ethnic minorities) before Wired reported the resulting behavioral convergence with Russia and North Korea.
Subsequent coverage fills in the mechanism: MSS-directed operations borrow from Russia and Iran and lean on private-sector hackers (borrowing from Russia and Iran while relying on private-sector hackers), while Xi Jinping invests in cultivating talent and funding security research (cultivating talent and funding security research). The story matters because it reframes Chinese intrusion activity from a diffuse collection enterprise into an institutionally driven campaign — the arc that later produced Salt Typhoon-scale operations.
First-order effects
- US targets face a more aggressive operator than the pre-2015 system produced: CrowdStrike later counted Chinese intrusions into US targets more than doubling to 330-plus incidents in 2025, with officials describing a shift toward hacking-for-hire.
- Chinese private-sector hackers are folded into state missions rather than operating independently, giving the MSS reach and deniability without having to train everything in-house.
Second-order effects
- Vulnerability disclosure laws requiring researchers to report findings to the government first (mandatory vulnerability reporting to the state) convert the domestic exploit pipeline into a state asset and push Chinese hacking breakthroughs deeper into secrecy.
- Universities with American partnerships and the domestic security-research base function as a recruitment funnel for MSS-directed work, pulling academic institutions into the espionage supply chain.
Third-order effects
- If the pattern holds, offensive cyber consolidates around a single reshaped institution — the MSS that Xi Jinping has made the primary driver of campaigns like Salt Typhoon — eroding the separation between intelligence collection and more aggressive statecraft.
- Deterrence and attribution frameworks calibrated separately for Russia's disruptive style, North Korea's revenue motives, and China's traditional collection now confront a blended adversary model, complicating how Washington assigns consequence for intrusions.
The trend: State-sponsored hacking worldwide is consolidating under central intelligence institutions that blend espionage, disruption, and profit-seeking — a convergence of previously distinct national playbooks.