China cybersecurity policy

China's Incident-Reporting Rules Are Sound, but NightEagle Shows Defence Depends on Sharing Threat Intelligence Across Borders

Kaspersky's finding that NightEagle has moved from Chinese targets to Russian firms shows attackers ignore borders, and national reporting regimes need to allow for that.

China's Incident-Reporting Regime at a Glance People of Internet Research · China 1 hour CII operator report deadline Serious incidents go to the protec… 4 hours Other operators' deadline Reports go to the provincial cyber… RMB 5M Loss threshold for reporting Direct economic loss marks a 'rela… RMB 10M Maximum fine, amended law Applies to the most serious violat… peopleofinternet.com
China's Incident-Reporting Regime at a… People of Internet Research · China 1 hour CII operator report deadline 4 hours Other operators' deadline RMB 5M Loss threshold for reporting RMB 10M Maximum fine, amended law peopleofinternet.com

Key Takeaways

On September 18, 2026, The Record reported that Kaspersky has investigated several incidents at Russian businesses involving NightEagle, also tracked as APT-Q-95. The Chinese firm QiAnXin first publicly identified the group in July 2025 as a cyberespionage actor targeting Chinese defence, semiconductor, AI and quantum organisations. Kaspersky says the group has been active since at least 2023 and is now "updating its methods and adopting new techniques for persistence and lateral movement."

The technical story is mundane, and that is the policy lesson. In most cases the intruders logged in through VPNs with stolen credentials. They then targeted Microsoft Exchange servers and installed a backdoor called GhostContainer. They abused Active Directory weaknesses to move sideways, and hosted tooling on GitHub under names such as AdobeSync and TrueConf. Kaspersky could not establish how the backdoor first landed on the Exchange servers, and it did not disclose the victims or the number of incidents. Attribution also remains open: The Record notes that Chinese researchers have linked the group to North America, but that this is unconfirmed.

The strongest case for China's approach

Beijing's regulators would say that fast, mandatory reporting is exactly what defence against a group like this requires. The Cyberspace Administration of China (CAC) issued its National Cybersecurity Incident Reporting Management Measures on September 11, 2025, and they took effect on November 1, 2025. Critical information infrastructure operators must report serious incidents to their protection department and the police within one hour. Other network operators have four hours to report to the provincial cyberspace authority. The threshold is an incident rated "relatively major" or above. Examples include a personal-data breach affecting 1 million or more people, or direct economic losses of RMB 5 million or more, according to the Latham & Watkins summary.

This is a fair argument. A group that sits inside an Exchange server for months benefits from every hour of delay. Before 2025 the reporting duties were scattered across several laws. A single classification scheme with fixed clocks gives operators clarity, and it gives defenders a chance to spot patterns early. The Measures also require operators to contractually oblige their security and maintenance vendors to report incidents they detect. That gap is real, because vendors often see attacks before the customer does.

The National People's Congress Standing Committee then amended the Cybersecurity Law on October 28, 2025, with effect from January 1, 2026. The amendment added AI-related provisions and strengthened legal liability. Latham reports that maximum fines for the most serious violations rose to RMB 10 million. It also reports that the law now reaches overseas activity that endangers China's cybersecurity and causes serious consequences, a wider scope than the earlier critical-infrastructure limit. The amendment also allows penalties to be reduced or waived for operators who cooperate and disclose voluntarily.

Where the design falls short

The pro-security case is strong on speed, but NightEagle exposes three weaknesses.

1. Reporting flows up, not out. The Measures direct information to regulators and the police. They do not create a route for the technical details of an intrusion to reach other defenders quickly. GhostContainer, the stolen-VPN-credential pattern and the fake GitHub repositories were useful to defenders only once private vendors published them. A group that hit Chinese and then Russian companies over roughly a year is a case for structured indicator-sharing that does not depend on government channels. Fines do not produce that sharing.

2. Hard penalties push toward minimal disclosure. When a late or false report can bring liability, operators have a reason to under-classify an incident, or to delay declaring it. The leniency provisions in the amended law are the right instinct. They should be applied predictably and published, so that an operator that discovers a long-dwelling Exchange compromise expects credit for disclosing it.

3. The failure points are basic hygiene. Stolen VPN credentials and Active Directory weaknesses are not exotic. Multi-factor authentication, patched and monitored Exchange servers, and credential monitoring reduce this risk far more cheaply than the four-hour reporting clock does. A regime that measures compliance by whether the report was filed on time, rather than whether the defences were sound, rewards paperwork over resilience.

What proportionate policy looks like

NightEagle also shows why reporting mandates will not stop espionage. A state-linked actor that can be described by Chinese researchers as targeting China and by Russian researchers as targeting Russia is operating in a space where national regimes see only part of the picture. That is true regardless of who is behind it, and attribution here remains unresolved.

A proportionate approach would do four things:

The overall lesson is that speed of reporting matters, but the quality of the shared information matters more. China's 2025 reforms tightened the first. The next step should be the second.

Sources & Citations

  1. The Record: NightEagle expands operations to Russia
  2. CAC: National Cybersecurity Incident Reporting Management Measures
  3. NPC Standing Committee: Decision amending the Cybersecurity Law
  4. Latham & Watkins: CAC incident reporting measures
  5. Latham & Watkins: Cybersecurity Law amendments