Typhoon Season
The CCP's Hacking Army, Critical Infra, Trump's Texts
This is part 2 of a series on China’s Technological Playbook. Read Part 1, on cyber espionage-enabled IP theft, here (now with a new and improved cover image!).
How does a country become the world’s most dangerous cyber power? China’s answer seems to be: recruit talent by the thousands, pass laws that require discovered software flaws to be reported to the state, and then spend years pre-positioning hackers inside an adversary’s critical infrastructure.
And it seems to be a pretty good answer! So far, it’s gotten China into a Massachusetts power grid, nine major phone carriers, and the private communications of Donald Trump.
China’s Hacking Army
Around 2017–2018, the Chinese government barred its security researchers from international hacking competitions such as Pwn2Own, where “teams compete to discover critical flaws in popular software products.” The move was widely interpreted as an effort to keep knowledge of zero-day vulnerabilities inside China.
“There will be no Chinese research teams at Pwn2Own this year. The change will be especially obvious… because for the last several years Chinese teams have dominated the competition.”
Instead, the CCP shifted to:
1. Local competitions to recruit talent

“China is recruiting talented citizens through local ‘hacking competitions’ and weaponising their talents to attack Western governments, according to a report by ETH Zurich University’s Centre for Security Studies.”
In place of international contests, domestic alternatives like the Tianfu Cup are now hosted within China by companies like Alibaba, Tencent, and Baidu. Fascinatingly (and also a bit terrifyingly), vulnerabilities discovered at these events have already been used in cyber espionage. The same National Security News article from above states:
“[A] vulnerability identified in Apple iOS during one of the events was used in Chinese cyber espionage campaigns against the Uyghurs, the Chinese Muslim minority in the Xinjiang region.”
Today, the CCP’s hacking force is made up of a combination of PLA members (who work for the military full-time) and private citizens (who do this work part-time– often on top of things like running tech companies/working normal jobs– and are usually recruited via domestic hacking contests like the Tianfu Cup). The aforementioned article from National Security News calls these categories “Competition Stars” and “Government-Contracted Hackers.”
2. Requiring the reporting of zero-day vulnerabilities

In China, companies that learn of a zero-day must report it to the government within two days– and under Microsoft’s reading of the law, before the developers responsible for patching it. From there, the CCP itself chooses which should be shared and which should remain secret.
The law for this is called “Regulations on the Management of Security Vulnerabilities in Network Products (RMSV),” and it’s enforced through penalties on organizations. For example, in 2021, a security researcher named Chen Zhaojun discovered a critical vulnerability and reported it to the Apache Software Foundation, the nonprofit that maintains Log4j– a logging tool embedded in millions of applications across the internet. Chen worked for Alibaba Cloud, and the company was penalized through the suspension of a government cybersecurity partnership because he didn’t notify Chinese authorities before reporting the zero-day to Apache.
Microsoft’s Digital Defense Report from 2022 highlights concerns that RMSV “might enable elements in the Chinese government to stockpile reported vulnerabilities toward weaponizing them,” just as they did with the iOS vulnerability found at the Tianfu Cup.
So the CCP has the talent, and it has first claim on the vulnerabilities its citizens discover. The obvious question: what is all this for?
One answer surfaced, unexpectedly, in small-town Massachusetts.
Critical Infrastructure Hacking
In 2023, Chinese state-sponsored hacking group Volt Typhoon broke into Littleton Electric Light and Water Departments (LELWD), a power and water utility provider in Littleton, Massachusetts. By the time the FBI detected the breach, the hackers had already been inside Littleton’s network for “well over 300 days.”
Littleton is a town of about 10,000 people, half an hour northwest of Boston. Its utility serves two towns and has no meaningful connection to the broader grid. As a target, hacking LELWD provides no economic advantage, nor any foreign intelligence value.
Even the utility’s own general manager couldn’t explain the targeting: “I still don't know why Littleton other than we had a hole and they found it.”
According to the utility, the FBI said it was one of roughly 200 breached organizations on its list. The only coherent explanation seems to be the following:
“The consistency and scope of Volt Typhoon’s activities suggest a long-term effort to pre-position in critical systems to disrupt or destabilize operations during future geopolitical tensions.”
Why does this matter?
What can China do with access to our utilities? According to the then-director of the Department of Homeland Security’s cybersecurity arm:
“This is a world where a major crisis halfway across the planet could well endanger the lives of Americans here at home through the disruption of our pipelines, the severing of our telecommunications, the pollution of our water facilities, the crippling of our transportation modes…”
—Jen Easterly, PBS
Volt Typhoon has access built for a future conflict, held in reserve. But pre-positioning for sabotage is only half of China’s strategy.
The other half is, of course, espionage.
Reading Trump’s Texts: Operation Salt Typhoon

In the fall of 2024, CISA threat hunters discovered that a Chinese hacking group called Salt Typhoon had spent years monitoring U.S. telecommunications networks. In at least one carrier’s systems, they were present for more than three years before detection, according to a forensic investigation by Cisco.
Salt Typhoon breached at least nine US carriers, AT&T and Verizon among them, in an operation the FBI says began in 2019 at the latest. The hackers accessed call records revealing who Americans talk to and when, and they targeted the phone conversations of the country’s most senior political figures– including Donald Trump and JD Vance during the 2024 campaign. They were also able to “listen in on audio calls in real time” and access unencrypted text messages.
Senator Mark Warner called it “the worst telecom hack in our nation’s history.”
The hackers are also suspected to have breached the “lawful intercept” systems that carriers maintain for court-ordered wiretaps– the databases listing who American law enforcement is surveilling. If Beijing read those files, they may have learned which of its own spies the FBI was watching.
And the intruders have proven hard to evict. Despite sanctions and public exposure, researchers observed Salt Typhoon breaching five more telecom firms in the months after the story broke, and as of a December 2025 Senate hearing, the compromised companies still had not demonstrated the hackers were fully out of their networks.

The lights are still on in Littleton. Whether they stay on during the next Taiwan crisis may depend on how seriously America takes what it found there.
Future post(s) in this series will focus on frontier lab security and the geopolitical implications of China’s cyber access.



this is so well-written!!!!