orionpolicy.org Escalating Cyber Espionage Threats from China and Russia
Article Content
- •Cyber espionage incidents have increased significantly, particularly from China and Russia.
- •In May 2025, the UK linked cyber breaches to Chinese state actors.
- •The US has indicted multiple Chinese nationals for cyber espionage activities.
Cyber espionage has surged, with China and Russia leading state-sponsored attacks on sensitive data. In May 2025, the UK National Cyber Security Center linked breaches of the Electoral Commission to China, while Russian hackers targeted Tajikistan's educational and government sectors. Chinese cyber operations have increased by 150%, accounting for 11% of global cyberattacks. A US Department of Justice indictment in March 2025 charged 12 Chinese nationals with email hacking and information theft. The US Cybersecurity and Infrastructure Security Agency (CISA) defines cyber espionage as unauthorized access to sensitive data for political or economic gain. This evolving threat landscape has prompted discussions on policy responses and the need for enhanced cybersecurity measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Lockbit, APT1 and Cybersecurity and Infrastructure Security Agency in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
PaperCut NG/MF Vulnerability Under Active Exploitation On August 27, 2026, PaperCut issued an urgent advisory regarding a zero-day vulnerability affecting its NG and MF print management software. This flaw allows unauthenticated attackers to execute arbitrary Java code remotely, compromising server configurations. Emergency patches have been released for versions 25 and…