A new report in Foreign Affairs lays out a troubling picture: Chinese state-linked hackers have gained, and in many cases retained, access to United States communications, energy, and transportation infrastructure. This is not a one-off breach story. It is a description of persistent, long-term intrusion into the systems that keep phones connected, power flowing, and transit running.

For most readers, cyberwarfare between nations can feel abstract, something that plays out between governments and corporations far removed from daily life. But when the targets are utility companies and communications networks, the consequences land squarely on ordinary people: outages, service disruptions, and the exposure of personal data that flows through these systems every day.

What the Report Says About Access to US Networks

According to the report, the core problem is not just that intrusions happen. It is that the hackers involved have been able to maintain a foothold inside critical systems over time. That distinction matters. A single breach that gets detected and shut down quickly is a very different threat than an adversary quietly sitting inside energy or transportation infrastructure for months or years, watching, mapping, and waiting.

The report argues that part of the reason these intrusions persist is a mismatch between how the US oversees utility cybersecurity and how modern hacking actually works. Federal oversight today largely judges utility companies on whether they comply with existing legal and regulatory standards. The problem, as the report points out, is that those standards often lag behind the pace of real-world hacking techniques. A company can technically check every regulatory box and still be running systems that are vulnerable to sophisticated, persistent intrusions.

A Different Way to Measure Utility Security

Instead of measuring compliance alone, the report proposes a more practical benchmark: how quickly a utility operator can detect and contain a cyberattack once it starts. This shifts the incentive away from paperwork and toward operational readiness. A utility that can identify an intrusion and shut it down within hours is in a fundamentally stronger position than one that technically meets every legal requirement but takes weeks to notice something is wrong.

The report also notes that funding remains a real obstacle for smaller utility operators, many of which do not have the budget to overhaul aging systems or hire dedicated security staff. It suggests that nonprofit organizations could help close that gap by issuing grants to cover the cost of security upgrades, an acknowledgment that infrastructure security is not just a technical problem but also a resourcing one.

Taken together, these proposals point to a broader shift in thinking: from "did you follow the rules" to "can you actually respond when something goes wrong." That is a meaningful change, but it also underscores how much work remains before US infrastructure oversight catches up to the threat landscape.

Chinese Cyber Activity Is Part of a Wider Pattern

This report does not exist in isolation. It fits into a broader pattern of Chinese-linked cyber activity that has been documented across multiple sectors in recent months. Separate reporting has tracked how Chinese hacking groups have doubled their attack volume using DeepSeek AI to speed up reconnaissance and malware development, and how China-aligned groups have raced to exploit zero-day vulnerabilities before defenders can patch them. Attackers more broadly have also adapted their delivery methods, with some now assembling malware directly inside the browser while abusing trusted brand names to avoid detection.

These are distinct incidents and campaigns, not the same operation described in the Foreign Affairs report. But together they illustrate a consistent theme: threat actors, including those linked to China, are becoming faster and more adaptive, while institutional oversight and defense structures often move more slowly.

What This Means For You

Most individuals cannot directly influence how utility companies are regulated or funded. But infrastructure-level intrusions still have real implications for personal privacy and security. When communications providers or energy companies are compromised, the data that flows through their networks, including call records, billing information, and account credentials, can be exposed alongside the operational systems attackers are really after.

During periods of confirmed infrastructure incidents or service disruptions, it is worth being extra cautious about which networks you connect to and what data you transmit over them. Using a VPN encrypts your traffic between your device and the internet, which reduces the risk of your data being intercepted if you are forced onto an unfamiliar or less secure network, such as a public hotspot during an outage. A VPN will not stop a utility company from being breached, but it does add a layer of protection for your own traffic regardless of what is happening upstream.

Takeaways

The persistence of Chinese access to US infrastructure, as described in this report, is a reminder that cybersecurity at the national level and personal privacy at the individual level are connected. A few practical steps make sense regardless of how this policy debate unfolds: keep software and routers updated, use strong unique passwords for utility and telecom accounts, enable two-factor authentication wherever it is offered, and consider a reputable VPN for an added layer of encryption when using networks you do not fully trust. Staying informed about how infrastructure oversight evolves, and how ransomware and state-linked hacking campaigns continue to develop, remains one of the simplest ways to stay ahead of risks you cannot control directly.