Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
FBI agency official says China is "the most persistent and active" cyber threat; agency cites arrests and Operation Winter Shield
Summary
An FBI agency official said China remains "the most persistent and active cyber threat" to the United States and described recent arrests, more than 50 dismantled cyber enterprises and a 60-day campaign called Operation Winter Shield to boost private-sector cooperation.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
An agency official with the Federal Bureau of Investigation told listeners that China is "the most persistent and active cyber threat we face in the world," and outlined recent enforcement actions and a 60-day campaign to accelerate cooperation with private companies.
The official cited an interagency intelligence assessment released late last year, saying 17 organizations concluded China poses the most persistent cyber threat to the United States. "That's the entirety of the 17 organizations ... made that determination," the official said, and added that the FBI organizes its response around that assessment.
Why it matters: the official said Chinese-linked actors not only conduct large-scale espionage but also establish footholds inside critical infrastructure — including water, energy and communications systems — that could be used to cause disruptions. "They go out there and they do large-scale espionage collection," the official said, and later described adversary behavior as standing up enterprises within critical infrastructure nodes "to do disruptions at a time of inconvenience for the United States of America."
What the FBI described: the official said the agency pursued both arrests and structural dismantlement of hostile cyber operations. The official gave specific tallies: "This FBI last year arrested over 200 cyber actors, and this year we're already up to 60," and said the bureau has executed "over 50 complete dismantlements" focused on actors from China and elsewhere.
The official named actor groups the FBI targeted, saying the bureau "focused specifically on actors such as Salt Typhoon and Volt Typhoon," which the official characterized as conducting large-scale intrusion and espionage operations.
Operation Winter Shield: the official announced a coordinated 60-day campaign called "Operation Winter Shield" that paired direct FBI engagement with private-sector partners. "We launched Operation Winter Shield, which is our 60-day campaign with direct engagement with the private sector," the official said, adding the campaign logged more than 600 engagements and, the official said, had "over 2 million impressions" during the 60 days.
Appeal to industry and next steps: the official urged companies to invite FBI assistance early. "Let us in early, call us often. We will show up with our cyber action team, our CAT team, expel these bad actors, and dismantle the networks," the official said. The official added that the bureau will continue making arrests and will work with Treasury to impose sanctions on identified partners of foreign intelligence services.
The official said the FBI has identified three China-based public-private companies that have worked with the Ministry of State Security and the People's Liberation Army and that sanctions and law-enforcement measures are being used in tandem. The official cited examples of rapid FBI support to major banks and companies such as Stryker during last year's incidents.
The official concluded by reiterating that the FBI will continue dismantlements, arrests and partner engagement to reduce the threat.

