Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the China Cyber Operations topic

No spam. Unsubscribe anytime.

Witnesses at Homeland Security hearing say China has prepositioned on U.S. critical infrastructure

2140550 · January 22, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Experts and former officials told the House Homeland Security Committee that Chinese state-linked cyber actors have long-established footholds inside U.S. networks that support ports, energy, telecommunications and other critical systems, and that those footholds could be used to disrupt services during a crisis.

The House Committee on Homeland Security heard testimony from private-sector experts and former federal officials who said Chinese state-linked cyber operations have ‘‘prepositioned’’ access to U.S. critical infrastructure and pose a risk of disruptive or destructive attacks.

Chairman Green opened the hearing saying the panel would “delve into the risk posed by the People’s Republic of China, which has burrowed into our critical infrastructure and compromised our telecommunications networks.” He added that cyberspace “is increasingly becoming a digital battlefield.”

Adam Myers, senior vice president for counteradversary operations at CrowdStrike, told the committee that China’s cyber programs have matured. “After over a decade of investing in programs to strengthen their cyber capabilities, China has matured to achieve at least parity with other world cyberpowers,” Myers said, citing recent campaigns aimed at upstream collection and targeting of U.S. officials and enterprises.

Rear Admiral Mark Montgomery, senior director at the Foundation for Defense of Democracies, described operations that industry and U.S. agencies have tracked as prepositioning. “This malware lies in wait, ready to disrupt and destroy U.S. systems at a time of Beijing’s choosing,” Montgomery said, adding that the campaign has affected ports, energy systems and water utilities.

Witnesses listed several tracked actor clusters by industry nickname — for example, “Vanguard/Volt Typhoon,” “Salt Typhoon,” and “Liminal Panda” — and said some activity targets telecommunications and the technology supply chain. Myers told the committee that Chinese operations have moved from espionage toward capability to conduct disruptive operations, and that intrusions indicating prepositioning increased substantially in the previous year across multiple sectors.

Panelists and members emphasized the difference between government and private ownership of infrastructure. Montgomery noted that U.S. military mobility depends on private-sector ports, airports and rail lines and said the private sector will need both technical and financial assistance to harden those systems. Kimba Walden, president of the Paladin Global Institute and former acting national cyber director, said the private sector must be part of the solution while the federal government clarifies roles and provides workforce and technical support.

Members pressed witnesses on what a credible response should look like. Myers recommended accelerating coordinated operations that disrupt adversary infrastructure and increase the tempo of defensive and offensive work. Montgomery urged public attribution and operations that remove adversary footholds even if doing so sacrifices an intelligence access, arguing public operations could deter further prepositioning.

The witnesses uniformly stressed that the activity remains ongoing: Myers told the committee that “Salt Typhoon is an ongoing activity by an adversary,” and that the United States must continuously identify and cut off access.

Why this matters: Committee members and witnesses framed the activity as more than espionage — in several witnesses’ words it is “operational preparation of the battlefield,” meaning actors have implanted capabilities in networks that could be turned to destructive ends in a crisis. Members said those findings shape congressional priorities for oversight, funding, and legislation aimed at resilience and deterrence.