On September 18, 2026, The Record reported that Kaspersky has investigated several incidents at Russian businesses involving NightEagle, also tracked as APT-Q-95. The Chinese firm QiAnXin first publicly identified the group in July 2025 as a cyberespionage actor targeting Chinese defence, semiconductor, AI and quantum organisations. Kaspersky says the group has been active since at least 2023 and is now "updating its methods and adopting new techniques for persistence and lateral movement."
The technical story is mundane, and that is the policy lesson. In most cases the intruders logged in through VPNs with stolen credentials. They then targeted Microsoft Exchange servers and installed a backdoor called GhostContainer. They abused Active Directory weaknesses to move sideways, and hosted tooling on GitHub under names such as AdobeSync and TrueConf. Kaspersky could not establish how the backdoor first landed on the Exchange servers, and it did not disclose the victims or the number of incidents. Attribution also remains open: The Record notes that Chinese researchers have linked the group to North America, but that this is unconfirmed.
The strongest case for China's approach
Beijing's regulators would say that fast, mandatory reporting is exactly what defence against a group like this requires. The Cyberspace Administration of China (CAC) issued its National Cybersecurity Incident Reporting Management Measures on September 11, 2025, and they took effect on November 1, 2025. Critical information infrastructure operators must report serious incidents to their protection department and the police within one hour. Other network operators have four hours to report to the provincial cyberspace authority. The threshold is an incident rated "relatively major" or above. Examples include a personal-data breach affecting 1 million or more people, or direct economic losses of RMB 5 million or more, according to the Latham & Watkins summary.
This is a fair argument. A group that sits inside an Exchange server for months benefits from every hour of delay. Before 2025 the reporting duties were scattered across several laws. A single classification scheme with fixed clocks gives operators clarity, and it gives defenders a chance to spot patterns early. The Measures also require operators to contractually oblige their security and maintenance vendors to report incidents they detect. That gap is real, because vendors often see attacks before the customer does.
The National People's Congress Standing Committee then amended the Cybersecurity Law on October 28, 2025, with effect from January 1, 2026. The amendment added AI-related provisions and strengthened legal liability. Latham reports that maximum fines for the most serious violations rose to RMB 10 million. It also reports that the law now reaches overseas activity that endangers China's cybersecurity and causes serious consequences, a wider scope than the earlier critical-infrastructure limit. The amendment also allows penalties to be reduced or waived for operators who cooperate and disclose voluntarily.
Where the design falls short
The pro-security case is strong on speed, but NightEagle exposes three weaknesses.
1. Reporting flows up, not out. The Measures direct information to regulators and the police. They do not create a route for the technical details of an intrusion to reach other defenders quickly. GhostContainer, the stolen-VPN-credential pattern and the fake GitHub repositories were useful to defenders only once private vendors published them. A group that hit Chinese and then Russian companies over roughly a year is a case for structured indicator-sharing that does not depend on government channels. Fines do not produce that sharing.
2. Hard penalties push toward minimal disclosure. When a late or false report can bring liability, operators have a reason to under-classify an incident, or to delay declaring it. The leniency provisions in the amended law are the right instinct. They should be applied predictably and published, so that an operator that discovers a long-dwelling Exchange compromise expects credit for disclosing it.
3. The failure points are basic hygiene. Stolen VPN credentials and Active Directory weaknesses are not exotic. Multi-factor authentication, patched and monitored Exchange servers, and credential monitoring reduce this risk far more cheaply than the four-hour reporting clock does. A regime that measures compliance by whether the report was filed on time, rather than whether the defences were sound, rewards paperwork over resilience.
What proportionate policy looks like
NightEagle also shows why reporting mandates will not stop espionage. A state-linked actor that can be described by Chinese researchers as targeting China and by Russian researchers as targeting Russia is operating in a space where national regimes see only part of the picture. That is true regardless of who is behind it, and attribution here remains unresolved.
A proportionate approach would do four things:
- Keep short reporting deadlines for genuinely serious incidents, with safe-harbour treatment for good-faith, timely disclosure.
- Publish anonymised technical indicators from reported incidents, so that other operators benefit and not only the regulator.
- Judge operators on baseline controls such as MFA, patching and logging, not only on report timing.
- Keep private research firms free to publish across borders. QiAnXin's 2025 disclosure and Kaspersky's 2026 follow-up both came from private firms, and the second built directly on the first. The wider the extraterritorial reach of national cyber laws, the more important it is that such publication carries no legal risk for researchers.
The overall lesson is that speed of reporting matters, but the quality of the shared information matters more. China's 2025 reforms tightened the first. The next step should be the second.