3 min read

Beijing's Deniable Army: A Breach in Rome and a Warrant in Washington- 216

Beijing's Deniable Army: A Breach in Rome and a Warrant in Washington- 216

May 10, 2026

Two stories surfaced within days of each other in the spring of 2026, on opposite sides of the Atlantic, describing what is functionally the same phenomenon from two different altitudes. In Italy, investigators quietly traced a twenty-day intrusion into a subsidiary of IBM to a group tied to Chinese state interests. In Washington, the FBI's top cyber official stood before reporters and said, in effect, that this was no longer the exception but the model: China's hacker-for-hire ecosystem, in his words, had gotten out of control. Together, the two accounts describe not an isolated breach but a system built to produce exactly this kind of breach, repeatedly, while keeping Beijing's fingerprints just far enough away to preserve deniability.

The Italian case centers on Sistemi Informativi, the IBM Italy subsidiary that manages IT infrastructure for both public agencies and strategic private companies. For approximately twenty days, attackers maintained undetected access to its systems, a duration notable less for the intrusion itself than for what it reveals about detection capability: no outages, no visible failures, nothing that would have surfaced the compromise on its own. Investigators have linked the activity to Salt Typhoon, a group active since at least 2019 whose signature is not disruption but patience, custom modular malware, discreet lateral movement, and an operating pattern built around remaining invisible for as long as possible. The group's method follows a now-familiar logic: compromise a technology provider with privileged downstream access, then use that foothold to map the networks, communications, and data flows of every client connected to it. Previous Salt Typhoon operations have followed the same template against telecommunications firms in North America and Europe, satellite-sector companies, and government infrastructure in the Netherlands and the United States, frequently entering through vulnerabilities in widely deployed platforms like Citrix and Cisco rather than through custom exploits. Compromising one integrator, in other words, is a way of compromising dozens of its clients at once.

The Washington side of the story supplies the structural explanation for why this keeps happening. FBI cyber division assistant director Brett Leatherman described a network of ostensibly private Chinese technology companies and contractors operating at the direction of Chinese intelligence services, motivated as much by profit as by state tasking. These firms, he said, cast a wide net for vulnerable systems, then sell what they extract, directly or indirectly, to the Chinese government, or, failing that, simply sell it onward to whoever else will pay. The case animating his remarks was the extradition from Italy to the United States of Xu Zewei, a Chinese national accused of directing hacking operations on behalf of Shanghai's State Security Bureau between 2020 and 2021, activity prosecutors tie to the Hafnium campaign, now known as Silk Typhoon, that exploited Microsoft Exchange zero-days to compromise more than twelve thousand organizations in the United States alone. Xu's alleged targets extended beyond infrastructure into American universities and researchers working on COVID-19 vaccines and treatments, a reminder that this ecosystem's outputs are as often scientific and economic as they are strategic.

What connects Rome and Washington is not shared attribution but shared architecture. Salt Typhoon and Silk Typhoon are tracked as distinct groups, but both operate inside the same incentive structure Leatherman described: nominally private contractors, formally deniable, materially indistinguishable in outcome from direct state action. The Italian breach shows what that architecture produces on the ground, a strategic infrastructure provider silently compromised for weeks, its downstream clients exposed by extension. The American indictment shows what happens when that architecture is finally named in a courtroom, and how difficult naming it remains, given that Xu's alleged co-conspirator, Zhang Yu, remains at large and, per the Department of Justice, likely to stay that way. Leatherman's closing line to China's contractor ecosystem, that the protection of operating inside China evaporates the moment a contractor crosses a border, is less a statement of current deterrence than an aspiration for it. For now, the more durable fact is the one Italy just relearned: the compromise of a single well-placed technology provider remains one of the most efficient tools available to state-aligned cyber operations, and detection continues to arrive weeks after the access does.