Skip to main content

China alleges that the U.S. carried out cyberattacks on its national time center

Dr. Layloma Rashid
5 minute read
China accuses US of cyber breaches at national time centre

China's Ministry of State Security has accused the U.S. National Security Agency of running a multi-year cyber campaign against the National Time Service Center, the facility that generates and distributes the country's standard time. In a post published Sunday on its official WeChat account, the ministry said it had obtained "irrefutable evidence" of the intrusion and had cut off the attack.

The center, based in Xi'an in Shaanxi province and operated under the Chinese Academy of Sciences, maintains and disseminates Beijing Time. Its signals underpin telecommunications, financial settlement, the power grid, transport, surveying and mapping, and defense systems. The ministry framed the alleged operation as an attempt not merely to steal data but to reach the machinery that keeps those sectors synchronized.

What the ministry alleges

According to the MSS account, the operation began on March 25, 2022, when attackers exploited a vulnerability in the text-messaging service of a foreign-brand mobile phone used by center staff, taking data from employees' devices.

Those devices, the ministry said, yielded login credentials that were used from April 18, 2023 onward to probe and then enter the center's internal networks. Between August 2023 and June 2024, the MSS claims, the attackers stood up a cyber warfare platform and deployed 42 distinct tools — malware, modules and malicious files — against multiple internal systems, including the center's High-Accuracy Ground-based Timing System.

The ministry described tradecraft consistent with a well-resourced operator: traffic routed through virtual private servers in the United States, Europe and Asia to disguise its origin, forged digital certificates to slip past antivirus software, and encryption used to erase forensic traces. It said its own investigators tracked the reconnaissance from an early stage, severed the attack chains and hardened the affected systems.

The MSS did not publish malware samples, file hashes, indicators of compromise or the name of the phone vendor. That leaves the technical core of the claim unverifiable by outside researchers, and it is the main reason the allegation will land differently in Beijing than it does abroad.

Why a timing lab is a serious target

Attacking a national time reference does not require destroying anything. It requires making clocks disagree.

Modern infrastructure assumes that separate systems share the same second. Financial exchanges sequence orders by timestamp. Power grids rely on synchronized phasor measurements to trip protection relays correctly. Mobile networks hand calls between base stations on tightly aligned clocks. Satellite navigation is, functionally, a timing problem. Drift introduced deliberately at the source propagates outward into all of it, and the resulting failures look like unrelated malfunctions rather than an attack.

That is what makes a timing center an attractive target for a state actor and why the MSS chose to make this particular case public.

A familiar exchange, in both directions

The accusation lands in a well-worn pattern. Washington has spent the past two years attributing intrusions into U.S. telecommunications carriers and critical infrastructure operators to Chinese state-linked groups. Beijing has increasingly responded in kind rather than simply denying: in April, the MSS named three people it identified as NSA operatives over alleged attacks on the Asian Winter Games in Harbin. Chinese officials also continue to cite the NSA's operation against Huawei, disclosed in documents leaked by Edward Snowden, as evidence that the United States built the playbook it now polices.

Neither side is offering the other much room. The U.S. case rests on indictments, sanctions and vendor telemetry; the Chinese case rests on ministry statements carried by state media. Both are political documents as much as technical ones.

The timing of the accusation

The disclosure arrives during an unusually bad stretch in the wider relationship. Earlier this month Beijing sharply expanded export controls on rare earths and related magnet and semiconductor materials, effective December 1, requiring foreign firms to obtain Chinese approval for products containing at least 0.1 percent Chinese-origin rare earth content. President Donald Trump answered with a threat of an additional 100 percent tariff on Chinese goods from November 1, plus export controls on critical software — a post that helped wipe roughly $2 trillion off U.S. equity values in a single session.

Publicizing an NSA intrusion into civilian infrastructure serves Beijing's argument that the United States applies one standard to itself and another to everyone else, and it plays to a domestic audience already being told that foreign interference justifies tighter control of Chinese networks.

Washington's response

The NSA did not engage with the specifics. "NSA does not confirm nor deny allegations in the media regarding its operations," an agency official said, adding that the agency is focused on countering foreign activity targeting American interests.

The U.S. Embassy in Beijing was blunter about the wider dispute, describing China as the most active and persistent cyber threat to U.S. government, private-sector and critical infrastructure networks.

Neither statement addresses the National Time Service Center. That silence is standard practice for intelligence operations, and it also leaves the narrative in Beijing's hands at home.

What it changes

Whether or not the specifics hold up, the case marks where state cyber operations have moved: away from ministries and defense contractors and toward the unglamorous reference systems — time, position, certificates, routing — that everything else quietly depends on. Those systems have few operators, thin redundancy and enormous downstream reach.

The likely consequence is more separation. Each accusation gives both governments another reason to build sovereign alternatives to shared infrastructure and standards, and less reason to cooperate on the norms that might constrain this kind of operation. The disagreement over who attacked whom is, at this point, less consequential than the shared conclusion both sides are drawing from it.

Disclaimer

This article is for informational purposes only and does not constitute financial, investment, tax, or legal advice. Market data, tax rules, and prices can change after the article date. TECHi and its authors may hold positions in securities or digital assets mentioned. Always conduct your own research and consult a licensed financial, tax, or legal professional before making decisions.

Share

Pick your channel

About the Author

Dr. Layloma Rashid
@laylomaTechnology writer | AI platforms, chip exports and enterprise AI earnings

Layloma Rashid writes about AI platforms and the companies selling them, from OpenAI's new teen alert on ChatGPT and GPT-5.6's arrival on Amazon Bedrock to C3.ai's enterprise AI earnings. She also follows chip policy for TECHi, including how many Nvidia H200s are shipping to China.

Comments