5 min read

The Long Game: How China's Cyber Harvest Became a Western Intelligence Priority- 199

The Long Game: How China's Cyber Harvest Became a Western Intelligence Priority- 199

June 19, 2026

A significant shift has occurred in how Western nations characterize Chinese cyber operations, moving away from quiet attribution toward a strategy of calibrated, public transparency. This synchronized messaging from diverse international intelligence bodies and academic researchers reveals a critical strategic assessment: China’s activities are no longer viewed as isolated incidents, but rather as a deliberate, architectural campaign. This report examines the operational logic behind this architecture, which prioritizes access to infrastructure beneath government systems—such as utility providers, telecommunications networks, and digital infrastructure firms—to establish long-term, latent capabilities for disruption and espionage.

Something has changed in how the West talks about Chinese cyber operations. The change is not in what China is doing — the operations described across a cluster of intelligence disclosures and public statements from spring 2026 reflect a campaign that has been running for years, in some cases for a decade. What has changed is that Western intelligence services, senior officials, and former agency heads are now naming it publicly, specifically, and simultaneously, in a way that reflects a deliberate shift from quiet attribution to calibrated transparency. Dutch military intelligence, Australia's ASIO, the Italian security establishment, academic and private sector researchers, and a former director of the NSA are all, within the same narrow window, saying the same thing out loud. That convergence is itself the analytical signal worth examining — it tells us something about where the West has arrived in its strategic assessment of China as a cyber adversary.

The picture those assessments collectively describe is an architecture rather than a series of incidents. Volt Typhoon has pre-positioned malware across hundreds of local American utility systems — not to extract data but to establish latent disruptive capability, software waiting in water and electrical infrastructure for a moment of strategic decision when disruption becomes the objective rather than collection. Salt Typhoon gained access to telecommunications providers serving millions of Americans and intercepted communications of senior officials, an intelligence windfall that the former NSA director Timothy Haugh, writing in the New York Times, described as a sustained campaign of access to "networks nationwide." The Dutch NCSC documented a parallel operation using a zero-day in FortiGate edge devices that achieved access to at least 20,000 systems globally before the vulnerability was publicly disclosed — with the attackers knowing about the flaw two months before Fortinet announced it, infecting roughly 14,000 devices in that window — and installing the Coathanger remote access trojan in a way that persisted even after victims applied the subsequent patch. Dutch intelligence concluded that "a significant number" of victims remained compromised, with targets including dozens of Western governments, international organisations, and defense industry firms.

target sector map — showing China's espionage architecture by sector across the documented operations: defense tech, diplomatic networks, telecoms, critical infrastructure pre-positioning, IT supply chain. A clean structural overview rather than a flow

The IBM Italy case illustrates where this architecture has arrived in its operational logic. Sistemi Informativi, an IBM subsidiary operating digital infrastructure for Italian public services, was accessed for approximately twenty days with no visible disruption — no outages, no encrypted files, no public-facing consequences of any kind. The intrusion touched environments connected to Italian social security and insurance systems and platforms supporting Italy's economic recovery programs. Attribution to Salt Typhoon remains a working hypothesis rather than a confirmed conclusion, but the operational signature — patient lateral movement, prolonged undetected presence, targeting of an IT provider precisely because of its privileged access to dozens of downstream government systems — is consistent with what Western intelligence services have been documenting across Salt Typhoon's campaign history. The strategic logic of the IBM Italy case is the same logic documented in the Dutch FortiGate campaign, in Salt Typhoon's American telecom intrusions, and in Volt Typhoon's utility pre-positioning: access to the infrastructure layer beneath government rather than to government directly, using technology providers as keys to networks they never intended to be the target.

timeline of Western public attributions — showing the escalating tempo of named disclosures from Dutch, Australian, Italian, and US officials across this window, making the calibrated transparency argument visible rather than just stated.

Proofpoint's documentation of TA416's resumed European campaigns adds the diplomatic collection dimension. The group, linked to Chinese state intelligence, returned to large-scale phishing operations against European government agencies and diplomatic missions tied to the EU and NATO between mid-2025 and early 2026, adapting its tradecraft to include fake Cloudflare verification pages, Microsoft OAuth redirect abuse, and malicious C# project files delivering customized PlugX implants. The operational logic is different from Volt Typhoon's infrastructure pre-positioning or Salt Typhoon's telecom access — this is conventional diplomatic intelligence, the collection of communications and documents from the foreign policy apparatus of European states at a moment of particular geopolitical fluidity, when EU-China tensions, the Russia-Ukraine war, and the outbreak of conflict in Iran are all simultaneously reshaping the strategic landscape TA416 is trying to understand.

The Dutch assessment provides the most explicit geopolitical framing. Vice Admiral Reesink, director of the MIVD, described Chinese cyber operations as "very capable and organised in a very complex way," and the Dutch defense minister characterised China's approach as a "whole-of-society" espionage campaign combining legal investment and research partnerships with covert cyberattacks and export control violations — a comprehensive strategy to acquire Dutch semiconductor, aerospace, and maritime technology that does not distinguish between licit and illicit means. That framing matters: it positions Chinese strategic competition not as a series of discrete hacking incidents but as a continuous, multi-channel extraction operation in which cyber espionage is one instrument among many, calibrated to what each target can yield.

Australia's ASIO Director-General Mike Burgess chose a different register for the same message, naming Volt Typhoon and Salt Typhoon directly at a financial industry conference in Melbourne and quantifying the espionage cost to the Australian economy at AUD 12.5 billion annually. China's foreign ministry called the statements disinformation and protested formally to Canberra. The protest itself is unremarkable — Beijing's denial pattern is consistent across all these attributions. What is notable is that Burgess named the groups anyway, in public, by name, at a civilian event. That is the calibrated transparency. It signals a judgment that the cost of continued silence now exceeds the diplomatic cost of naming.

Haugh, in his New York Times piece, frames the strategic response as a problem of shared responsibility: the extraordinary concentration of technical capability and global network reach in American industry means that defense cannot be left to government alone, and that voluntary information sharing between private companies and government — the default posture until now — has proven structurally insufficient. His prescription is structural rather than tactical: rewrite opaque laws, mandate shared accountability across industry and government, and invest in countermeasures against the most dangerous emerging threats. The implied admission is that, despite a decade of documentation, Western defense against this campaign has not kept pace with the campaign itself.