China's Cyber Prowess Rivals US, Dutch Intel Warns

China cyber capabilities are likely on par with the US, Dutch MIVD said in a report dated April 22nd, 2026, warning many attacks go unseen.

Lauren Collins ·

China's Cyber Prowess Rivals US, Dutch Intel Warns

The Netherlands’ Defence Intelligence and Security Service (MIVD) said China has likely reached parity with the United States in offensive cyber capabilities, warning that the shift is leaving many operations targeting Dutch interests undetected. The assessment was published in the agency’s public annual report released Tuesday and dated April 22nd, 2026.

In the report, the MIVD stated that “China now probably stands on an equal footing with the United States in the area of offensive cyber capabilities.” It said Chinese activity has become so advanced that “detection, response and mitigation are often inadequate,” adding that “probably only a limited proportion of Chinese cyber operations against Dutch interests is detected and subsequently mitigated.”

A separate U. S. assessment described China’s capabilities differently. The U. S. Office of the Director of National Intelligence said in its 2025 threat assessment that China has “demonstrated the ability to compromise U. S. infrastructure through formidable cyber capabilities,” without characterizing the two countries as equal.

The Dutch report framed the challenge as one where the scale and professionalism of Chinese operations can outpace the ability of intelligence services and cybersecurity defenders to identify and contain activity.

The MIVD also disclosed details about People’s Liberation Army (PLA) hacking units that it said have not previously appeared in Western public intelligence reporting. It linked improved operational performance to China’s 2024 cyber restructuring, when Beijing dissolved its Strategic Support Force and created a standalone Cyberspace Force. The MIVD said that change helped hackers in 2025 continuously adjust tools and infrastructure and respond more flexibly to shifting opportunities.

The Dutch assessment followed reporting last month by Google’s Threat Intelligence Group that China-linked groups doubled their zero-day exploitation in 2025 and remained “the most prolific” state-sponsored users of previously unknown vulnerabilities. Looking ahead, the MIVD said it expects “a further increase in the number of campaigns aimed at exploiting vulnerabilities, including in edge devices such as routers, firewalls and VPN solutions” in 2026.

As an example, the MIVD said a Chinese cyberespionage campaign tracked as Salt Typhoon and RedMike accessed routers at smaller Dutch hosting and internet service providers in 2025. The Netherlands’ Ministry of Defence had previously confirmed that “smaller internet service and hosting providers” were targeted, while saying the hackers were not believed to have moved beyond the router layer into internal networks.

The MIVD described telecommunications firms as “priority targets,” and noted Dutch services joined a 13-country advisory in August 2025 attributing the campaign to three Chinese technology companies working on behalf of Beijing.

The report also sits alongside earlier Dutch disclosures. In February 2024, the service said Chinese hackers entered a compartmentalized Dutch Ministry of Defence network by exploiting a FortiGate vulnerability and deploying malware named COATHANGER. A later investigation found the same campaign had infected at least 20,000 FortiGate systems worldwide, and the MIVD warned infections remained difficult to identify and remove.

On the policy side, the MIVD said China’s intelligence operations reflect a “whole of society approach,” citing a legal framework it said requires Chinese citizens, companies and organizations to cooperate with state intelligence. It noted that such cooperation became a criminal offence in the Netherlands under amended espionage law in 2025.

The MIVD further warned that China can “better integrate offensive cyber capabilities with military operations,” echoing concerns raised about Volt Typhoon. U. S. officials and Five Eyes partners have assessed Volt Typhoon is pre-positioning implants in Western critical infrastructure for potential activation in a future conflict, and Washington has said the most likely trigger is Taiwan.

The MIVD separately noted that China has “never excluded the use of military means” to annex the island, while the timing and scope of any cyber activity remain uncertain.

More stories