Skip to content
payloadreport
Sunday, October 11, 2026Cybersecurity news without the noise77 reports
Cyber Attacks

FBI disrupts PRC spy infrastructure targeting global devices since 2021

Seven governments warn of ongoing data theft by Chinese state actors after US authorities dismantle hacking tools active for three years.

FBI disrupts PRC spy infrastructure targeting global devices since 2021
Illustration: Payload Report

Key points

  • US authorities disrupted Chinese hacking tools used for global data theft.
  • Seven governments issued warnings regarding the PRC spy infrastructure.
  • The malicious activity targeted devices continuously from 2021 until intervention.

Federal authorities in the United States have disrupted a network of hacking tools linked to the People’s Republic of China, according to The Register. This intervention targets infrastructure used to steal sensitive data from devices worldwide, marking a significant operational shift against state-sponsored espionage.

The disruption follows coordinated warnings from seven national governments about the extent of the data theft. These nations highlighted the global reach of the PRC spies, who exploited the compromised systems to access confidential information across multiple sectors and regions.

Operational Context and Timeline

The malicious infrastructure had been active and infecting devices since 2021, operating largely undetected for three years. The Register reports that the FBI stepped in to dismantle this specific hacking ecosystem, halting the ongoing exfiltration of sensitive data from targeted endpoints.

This long-running campaign demonstrates the persistence of state-sponsored actors in maintaining access to foreign networks. The tools were designed to remain hidden while systematically collecting intelligence, allowing the operators to maintain a foothold in target environments for an extended period before detection.

Global Impact and Scope

Seven distinct governments issued formal warnings regarding the PRC data theft, indicating a broad international impact. The Register notes that the spies were stealing sensitive data worldwide, suggesting the campaign was not limited to a single country or specific industry sector but had a wide geographic footprint.

The involvement of multiple allied nations underscores the collaborative nature of the response. By coordinating their warnings, these governments aim to alert other potential victims and share intelligence about the tactics, techniques, and procedures used by the Chinese state actors in this campaign.

What happens next

Security teams should monitor for indicators of compromise associated with the disrupted infrastructure. The Register confirms the FBI stepped in, but residual access or similar tools may remain in the wild. Organizations must verify their systems were not part of the infection chain dating back to 2021.

What to do and how to stay safe: FBI

  • Review network logs for unusual outbound traffic originating from 2021 to identify potential early-stage infections.
  • Audit remote access credentials and privileged accounts for signs of unauthorized use or persistence mechanisms.
  • Monitor threat intelligence feeds for new indicators related to the dismantled PRC infrastructure.
  • Verify that all endpoints are patched and configured to detect known malicious tooling signatures.

General security guidance from the Payload Report newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

When did this Chinese spy campaign begin?

The hacking tools were active and infecting devices starting in 2021, according to The Register.

How many countries warned about this data theft?

Seven governments issued warnings regarding the PRC spies stealing sensitive data worldwide.

Who disrupted the hacking infrastructure?

The FBI stepped in to disrupt the Chinese hacking tools used for global data theft.

Sources

  1. The Register
FBIPRCdata theftChinese hacking toolsThe Register

Related stories

Account lockout policies: stop brute force, avoid lockouts

Tighter lockout settings block attackers but also block your own staff when they mistype, creating a hidden operational cost you must manage.