CSIDB logo
Incident

US House of Representatives committees

Incident posture

Attack window
Dec 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 15:17

Linked entities

Victim
US House of Representatives committees
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Dec 2025
Disclosed
Jan 2026
Resolved
Pending

Summary

A Chinese hacking group nicknamed Salt Typhoon compromised email accounts of staff members of US House of Representatives committees, accessing systems used by some staffers on the House China committee and by aides on panels covering foreign affairs, intelligence, and the armed services. Reuters could not immediately verify the report, while the Chinese Embassy condemned the allegations as unfounded speculation and the FBI declined to comment. The White House and the offices reportedly targeted did not respond to requests for comment. US lawmakers and their aides, particularly those overseeing military and intelligence agencies, have long been top targets for cyberespionage, with periodic reports of hacks and attempted hacks. Salt Typhoon actors have long rattled the US intelligence community and are accused of gathering data on Americans' telephone communications and intercepted conversations, including those involving prominent politicians and officials. Despite efforts to secure networks, concerns persist about the adequacy of voluntary measures against sophisticated state‑sponsored intrusions. Beijing has repeatedly denied involvement in the spying.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

A Chinese hacking group nicknamed Salt Typhoon compromised the email accounts of staff members serving on several influential committees in the US House of Representatives, according to a Financial Times report citing people familiar with the matter. The intrusions were detected in December and involved email systems used by some staffers on the House China committee as well as aides on panels covering foreign affairs, intelligence, and the armed services. The report did not identify which specific staffers were targeted, and Reuters could not immediately verify the allegations. Chinese Embassy spokesman Liu Pengyu denounced the claims as unfounded speculation and accusations, while the Federal Bureau of Investigation declined to comment on the incident. The White House and the offices of the four committees reportedly targeted in the surveillance sweep did not immediately respond to requests for comment.

The Financial Times quoted a person familiar with the campaign who said it remained unclear whether the attackers had accessed the personal email accounts of any lawmakers during the breaches. The article noted that US lawmakers and their aides, particularly those overseeing the nation’s military and intelligence apparatus, have long been prime targets for cyberespionage, with periodic reports of hacking attempts. Salt Typhoon has been described by US intelligence officials as a group alleged to be working for Chinese intelligence, accused of gathering data on broad segments of Americans’ telephone communications and intercepted conversations, including those involving prominent US politicians and government officials. The group’s activities have previously drawn concern from the US intelligence community due to their alleged scope and persistence.

In December 2024 a top US security agency confirmed, citing an FCC factsheet, that foreign actors state‑sponsored by the People’s Republic of China had compromised systems and exposed vulnerabilities across at least eight US communications companies. In August 2025 the Cybersecurity and Infrastructure Security Agency issued an advisory warning that a recent breach of US telecommunications infrastructure by Chinese actors highlighted the growing scope and sophistication of China’s cyber capabilities. The Office of the Director of National Intelligence’s 2025 Annual Threat Assessment labeled China as the most active and persistent cyber threat to US government, private‑sector, and critical infrastructure networks. Despite efforts to strengthen US network defenses, a recent Senate vote to roll back certain cybersecurity regulations has prompted concern among lawmakers. Senator Mark R. Warner, the Vice Chairman of the Senate Select Committee on Intelligence and co‑founder of the Senate Cybersecurity Caucus, warned in November that the Salt Typhoon intrusion demonstrated that existing voluntary measures alone are insufficient to stop sophisticated state‑sponsored actors from gaining long‑term, covert access to critical networks, adding that Congress, the administration, and the FCC should pursue greater transparency and stronger protections rather than less. Beijing has repeatedly denied any involvement in the spying campaign.

Sources

Sources available to members: 1 source.

CSIDB