The U.S. Is Highly Vulnerable to Cyber Threats From China. Here’s What It Should Do
Protecting vulnerable infrastructure will require a multipronged approach to make the United States a tougher target.

By experts and staff
- Published
Adam SegalCFR ExpertIra A. Lipman Chair in Emerging Technologies and National Security and Director of the Digital and Cyberspace Policy Program
In August, the U.S. Department of Justice and FBI seized platforms used by Chinese hackers to target NASA, the Federal Reserve, and other government and private sector networks. This takedown followed actions in 2024, to disable a botnet that controlled thousands of infected Internet of Things devices, and in 2025 to remove malware from more than 4,000 U.S. computers. “State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” said Attorney General Todd Blanche. “We are here to ensure security for the American people and will use every tool we have to keep that promise.”
While this move was promising, the truth is that U.S. infrastructure has never been at greater risk. U.S. networks have been left exposed because of poorly secured hardware and software and chronic underinvestment in infrastructure modernization. The water treatment facilities, gas pipelines, power installations, telecommunications networks, and transportation nodes that underpin the United States’ society and economy are under digital siege. In July, for example, suspected Iran-linked hackers targeted the monitoring and control networks of water and wastewater utilities in at least twelve states.
Over the past decade, China has built a cyber apparatus whose sophistication, scale, and strategic alignment rival that of the United States. The United States has for its part failed to develop a clear national strategy to address the threat, resulting in a widening asymmetry: China’s access threatens systems the United States depends on to fight, govern, and function, while Washington lacks the defenses or the credible deterrent to change that calculus.
China has built a cyber apparatus whose sophistication, scale, and strategic alignment rival that of the United States.
U.S. President Donald Trump may well raise the cyber issue with Chinese President Xi Jinping when they meet next week. However, Trump has in the past equated U.S. and Chinese actions, which undermines any deterrent message the administration is trying to send Beijing. For example, on the flight home in May following the summit in Beijing, Trump told reporters about his conversation with Xi: “I told them, ‘We do a lot of stuff to you that you don’t know about, and you are doing stuff to us that we probably do know about. But we do plenty. It’s a double-edged sword.’”
The emergence of sophisticated large language models (LLMs) has injected new urgency into U.S.-China competition. Models such as Anthropic’s Claude Mythos and OpenAI’s GPT 5.5 contain advanced coding and cybersecurity capabilities and reduce the time, labor, resources, and expertise such activities previously required. China is developing LLMs that will match the capabilities of the top U.S. models. As the gap narrows and artificial intelligence (AI) makes offensive cyberattacks quicker, the advantage will go to the country that can more rapidly apply these capabilities to defense.
In response to these developments, the China Strategy Initiative and the Digital and Cyberspace Policy Program at CFR convened a yearlong study group to review developments in Chinese cyber capabilities and the reforms needed to make U.S. critical infrastructure more defensible and resilient. Drawing on the conversations of the study group—which included experts with extensive government, military, and private sector experience—CFR has released a new report that explains how the United States got here, and how the country can reduce China’s leverage in cyberspace.
To be clear, the United States does retain advantages in cyber, including the strength of its technology companies, alliance networks, and strong economic tools. The report draws on these advantages to offer recommendations organized along four lines of effort:
- Build shared visibility into Chinese campaigns. The U.S. government has poor visibility into Chinese cyber activity, which undermines U.S. strategic planning and defensive investments. The United States can reverse this trend through deeper integration with private-sector partners who have a clearer view, investments in targeted sensing and automated threat sharing, and measures to shield critical infrastructure networks from foreign threats.
- Impose costs on Chinese operations. The United States should focus its offensive cyber operations on degrading Chinese campaigns and the enabling infrastructure that sustains them, buying time for structural reforms. At the same time, the United States needs to develop credible economic, diplomatic, and cyber responses to manage competition in cyberspace and shift China’s decision calculus.
- Enhance critical infrastructure resilience. The United States needs to make its networks easier and cheaper to defend. That will require shifting the incentives that currently produce insecure technology products and services, restructuring key internet infrastructures not designed for security, and ensuring that AI becomes a tool of enduring defensive advantage. Those measures will in turn make it feasible to establish baseline cybersecurity requirements for critical infrastructure.
- Rebuild U.S. government capacity. None of these recommendations is possible without an empowered federal government that can set and implement a clear strategic vision, engage in operational collaboration with every sector, and hire and retain technical experts to fill both civilian and military roles.
The report includes eighteen specific recommendations. Some would impose new burdens on industry, requiring costly investments and difficult trade-offs. Others would expand government authorities in ways that demand careful oversight. And some carry real risks of retaliation from Beijing.
None would be sufficient on its own, but they are necessary because every year the United States delays structural reform, the asymmetry widens and the range of available responses narrows.
This work represents the views solely of the author(s). The Council on Foreign Relations is an independent, nonpartisan membership organization, think tank, and publisher, and takes no institutional positions on matters of policy.