
Cyberdefense Cuts Could Sap U.S. Response to China Hacks, Insiders Say
Tom Brenner/For The Washington Post
Homeland Security Secretary Kristi L. Noem testifies on Capitol Hill earlier this month.
SAN FRANCISCO – As senior Trump administration officials say they want to amp up cyberattacks against China and other geopolitical rivals, some government veterans warn that such an approach would set the United States up for retaliation that it is increasingly unprepared to counter.
Alexei Bulazel, senior director for cyber at the National Security Council, said earlier this month that he wanted to fight back against China's aggressive pre-positioning of hacking capabilities within U.S. critical infrastructure and 'destigmatize' offensive operations, making their use an open part of U.S. strategy for the first time.
Bulazel, an Oracle security architect before joining the Trump administration, said such 'exciting' action would be the quickest way to 'change the script' and hopefully curb the rising rate of foreign cyberattacks on U.S. targets. He was speaking at the RSA Conference in San Francisco, the largest annual tech security meetup, where some others inside and outside government echoed his position.
'We have done everything, but it is extreme responses that will convince governments' to change their ways, said Rob Joyce, a former head of cybersecurity at the National Security Agency.
Yet far more security experts interviewed at the conference were fretting about recent personnel cuts to the Cybersecurity and Infrastructure Security Agency (CISA), and additional ones ahead under the GOP budget reconciliation bill, in which the administration asked for a 17 percent decrease in the budget of the principal civilian cyber agency. The consensus was that the U.S. is not well-defended now, and multiple security firms reported that the number of Chinese hacking attempts detected in the first quarter of this year more than doubled from a year earlier.
In a memo to CISA staff Thursday night, the new No. 2 at the agency wrote that the heads of four of CISA's six main divisions – cybersecurity, infrastructure security, emergency communications and integrated operations, which oversees regional offices – were all leaving this month. The leaders of most of the regional offices also are leaving, the memo said, along with the top CISA officers for finance, strategy, human resources and contracting.
U.S. security personnel revealed more than 18 months ago that Chinese military hackers had burrowed into the computer systems linked to infrastructure such as water and electrical utilities, ports and pipelines. That initiative, which the U.S. called Volt Typhoon, was soon supplemented by another, Salt Typhoon, that targets telecommunications networks. Sen. Mark R. Warner (D-Virginia) called it the 'worst telecom hack in our nation's history – by far.'
The covert offensive is far from over. Volt Typhoon is showing up in a wider variety of utilities, according to specialists at the cybersecurity firm Dragos, and an FBI official said Salt Typhoon might be able to reinfect carriers after they have been cleaned up. But CISA's parent, the Department of Homeland Security, has now disbanded advisory panels, including the Cyber Safety Review Board, which was investigating Salt Typhoon.
'We need CISA, we need these operations, we need these people and partnerships,' Dave DeWalt, a security industry investor and longtime CISA adviser, told The Washington Post, alluding to the unsettled state of international alliances. 'We've got to go fast, because we are vulnerable – especially if we're doing what we are doing around the world, geopolitically.'
Aside from Volt Typhoon and Salt Typhoon, DeWalt said a still-unfolding onslaught of Chinese attacks on water and power utilities and hundreds of other targets using a flaw in SAP business software shows that malicious activity is surging amid trade tensions between Washington and Beijing.
Under Homeland Security Secretary Kristi L. Noem, 130 probationary CISA employees have been dismissed, along with a small team dedicated to election security that had come under criticism from Republicans for its reports of misinformation about voting procedures. Many of the agency's numerous contractors have seen their contracts canceled.
'CISA was in disastrous shape when President Trump and Secretary Noem took office,' said a senior official with the Department of Homeland Security who spoke on the condition of anonymity under departmental policy. 'Under the Biden administration, despite a ballooning budget, CISA's mission was focused on becoming a hub of self-promotion, censorship, misinformation and electioneering.'
Noem told the San Francisco conference that while the agency has been doing important work, people 'only heard about it when it was doing something bad,' referring to its past contacts with social media companies about disinformation. She also said more responsibility for infrastructure protection should fall to state and local officials. 'I feel like most of the innovation can happen at the state level,' Noem said.
At a small Baltimore security conference more recently, former national cyber director Harry Coker said the opposite.
'My small hometown in rural Kansas is under assault every day from nation-state actors and malicious cybercriminals,' Coker said. 'They're going after the local hospital, the local school system, the local financial systems. And no one, especially our government, should expect my rural hometown to be able to defend itself against a nation-state actor.'
Security experts and officials from both major political parties had hoped to avoid cuts to CISA as severe as those being levied in other divisions and federal departments. They pointed to CISA's front-line role helping protect civilian government offices and privately owned critical infrastructure from attacks by highly effective ransomware gangs and geopolitical rivals.
'This is no time to pull defenders from the resilience and continuity of operations of lifeline human needs like water, power and access to emergency care,' said Joshua Corman, a former CISA official who now leads a pilot project with the nonprofit Institute for Security and Technology to improve security communications among people working in critical infrastructure. 'The coming storms need more help and better help. The risks are nonpartisan and affect all communities.'
Congress has held several hearings on cyberthreats and introduced bills aimed at deterring Chinese spying successes. At one, Rep. Andrew R. Garbarino (R-New York), chairman of the subcommittee on cybersecurity and infrastructure protection, said even early cuts were going too far and that CISA should take on more responsibility for safeguarding government departments.
CISA supporters in Congress and employees were encouraged by Trump's nomination of Sean Plankey to head CISA, though Sen. Ron Wyden (D-Oregon) has put the nomination on hold until he gets more information on telecom security. Plankey served in several high-level cybersecurity posts during the first Trump administration.
Concerns about the agency's efficacy have grown with the personnel and budget cuts, despite a recent court injunction against restructuring without congressional input.
'CISA is indirectly decimating our mid- and top ranks and leaving us without capable and experienced leaders,' said a current employee, who spoke on the condition of anonymity for fear of retaliation.
Current CISA executives declined to say how many people had left the agency or how it will adapt to the cuts.
CISA is 'doubling down and fulfilling its statutory mission to secure the nation's critical infrastructure and strengthen our collective cyberdefense,' Executive Director Bridget Bean said in an emailed statement. 'We have focused our operations on ensuring that we are prepared for a range of cyberthreats from our adversaries.'
Especially hard-hit by the cuts are the regional CISA offices that have helped local and state governments targeted by ransomware attacks, officials said. Scores of employees have also left the teams that provide CISA expertise to public and private entities – including hospitals, utilities and local public offices that have proved to be choice targets for foreign-origin hacking.
Vermont Secretary of State Sarah Copeland Hanzas expressed concern particularly about local offices. 'We don't have the economies of scale that a New York or a California or a Texas has to staff up in-house to provide some of the cybersecurity support and prevention that CISA has been providing,' she said.
Especially in light of the prospect of a more openly offensive U.S. cyber stance toward China, the trend toward a less robust CISA has alarmed many experts in the field.
'We were doing about a C-minus before, at risk of going down,' retired Rear Adm. Mark Montgomery, who led the congressionally chartered Cyberspace Solarium Commission confronting such issues, told attendees of the cybersecurity convention in San Francisco earlier this month. 'We are not ready for a systemic cyberattack in our country.'
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles

4 hours ago
Chinese Premier Urges Japan to Stand against Trump Tariffs
News from Japan World Jun 3, 2025 23:11 (JST) Beijing, June 3 (Jiji Press)--Chinese Premier Li Qiang on Tuesday urged Japan to deepen cooperation with China to stand against high U.S. tariffs. In a meeting in Beijing with a delegation from the Japanese Association for the Promotion of International Trade, Li said that the tariffs imposed by U.S. President Donald Trump's administration are a defiant challenge to nations around the world. According to sources with access to discussions at the meeting, Li said that the recent agreement between the United States and China to reduce their tariffs was based on the Chinese side's views. He also voiced hopes for expansion of Japanese companies' investments in China. Former House of Representatives Speaker Yohei Kono, who heads the delegation, said he is concerned that Japan-China relations may be rocked by outside influences. [Copyright The Jiji Press, Ltd.] Jiji Press


Asahi Shimbun
10 hours ago
- Asahi Shimbun
Two Japanese men killed in northeast China after business dispute
TOKYO/BEIJING--China's Foreign Ministry said on Tuesday that two Japanese men killed last month in the northeastern city of Dalian were business partners of the suspect and authorities were investigating. Dalian police confirmed the case in a statement on Tuesday and said a 42-year-old male suspect of Chinese nationality has been arrested. He had lived in Japan for a long time, the statement said. The two victims were business partners of the suspect who had entered China temporarily, police said, adding that the incident was triggered due to business conflicts. The Japanese government is "providing necessary support to the victims' families and will continue to respond appropriately from the perspective of protecting Japanese nationals," said Chief Cabinet Secretary Yoshimasa Hayashi. Chinese police notified the Japanese consulate in Shenyang on May 25 about the killings, two days after the incident, Hayashi, Japan's top government spokesperson, told a regular briefing.

Japan Times
10 hours ago
- Japan Times
Why Japan isn't panicking about Trump's foreign policy
My friend leaned back, perplexed. 'The Japanese don't seem very concerned about Trump,' he said, equal parts question and comment. 'At least, compared to the Europeans.' I checked the impulse to boot up the lecture on Japanese insecurity and Tokyo's hedging. and pondered his statement. The more I thought about it, the more I realized that he might be right. After all, the official line from the Japanese government is that the relationship is good. In March, Chief Cabinet Secretary Yoshimasa Hayashi expressed 'full confidence' that the U.S. will fulfill its obligations under the mutual security treaty and defend Japan, 'using all available capabilities, including nuclear ones.' That statement came after Trump again questioned the pact, claiming that the U.S. was obliged to defend Japan while Tokyo had no such responsibility. Late last month, after a quickly arranged phone call with Trump — at the request of the U.S. — a senior official from the Prime Minister's Office speculated in the Mainichi Shimbun that Prime Minister Shigeru Ishiba is 'becoming increasingly confident that he and Trump have chemistry,' a key factor in a relationship dominated by a decision-maker like the U.S. president. Hideshi Tokuchi, a former senior Japanese defense official, provided the backdrop for that optimism in a paper written after Ishiba's February visit to Washington. He explained that the alliance with the U.S. is 'indispensable' for Japan, 'the only reasonable and realistic option.' He quoted Koji Murata, a longtime student of the alliance at Doshisha University, who encouraged the Japanese to 'avoid making self-fulfilling prophesies' and 'to hold an optimistic attitude in the long term.' Murata in turn cited former British Prime Minister Winston Churchill, who famously concluded that 'Americans often make mistakes, but they always come back by correcting themselves. That is the resilience of the U.S. It is wrong to ignore the American power for course correction.' U.S. Secretary of Defense Pete Hegseth provided some assurance in remarks to the Shangri-La Dialogue last weekend in Singapore. Hegseth's SLD speech was the first systematic explanation of the Trump administration's policy about the region and it echoed Japanese thinking. Hegseth said the Indo-Pacific was the United States' 'priority theater' and 'we are here to stay.' Indeed, 'We will continue to be an Indo-Pacific nation — with Indo-Pacific interests — for generations to come.' He called out China for seeking to become 'a hegemonic power,' which through 'its massive military build-up and growing willingness to use military force to achieve its goals, including gray-zone tactics and hybrid warfare... has demonstrated that it wants to fundamentally alter the region's status quo.' He warned of a 'real' threat to invade Taiwan. Hegseth promised that the U.S. 'will not be pushed out of this critical region and we will not let our allies and partners be subordinated and intimidated.' He endorsed 'America's great allies and defense partners' that deter adversaries and 'execute peace through strength.' While he warned of 'uncomfortable and tough conversations' — a reference to demands to further increase defense spending — Hegseth promised that 'We will stand with you and work alongside you.' Ultimately, 'No one should doubt America's commitment to our Indo-Pacific allies and partners.' To prove that wasn't empty rhetoric, Hegseth then met counterparts from Japan, Australia and the Philippines in the second official gathering of 'the Squad,' a group launched at the SLD two years ago. He called the group the most 'strategically positioned to manifest deterrence, to bring about peace.' The statement released after that discussion noted the group's 'serious concern about dangerous conduct by China' and outlined concrete steps they were taking to counter it and to promote regional peace and stability. (Great reporting by Gabriel Dominguez and Jesse Johnson provides details from Hegseth's speech and the Squad meeting.) Still uncertain, I surveyed smarter folks than I and they agreed: Japan isn't as worried as the Europeans when it comes to Trump and U.S. security commitments — and with good reason. Most line up behind a Japanese security scholar, anonymous because of his work with the government, who echoed Tokuchi that the baseline for Tokyo is that it can't face China without the U.S. and therefore 'it has no other option but to do everything to promote ties with the U.S. whoever is the president.' They also credit U.S. actions to date. Administration officials insist that the Indo-Pacific is a priority theater and unlike their visits to Europe, there are no fireworks when they visit this region. When Hegseth visited Japan in March, his meetings with Ishiba and Defense Minister Gen Nakatani went well, with officials finding common ground and no reports of 'frank discussions,' diplomatic lingo for tension, friction or disagreements. Hegseth's SLD speech is the first extended statement about U.S. policy and it checked all the boxes. My scholar friend explained that 'Japanese have trepidations that something big may come but until then they stick to the same set of policies that they have been pursuing since before the Trump administration.' Yoichiro Sato, a professor at Ritsumeikan University, offered another reason for the calm: 'The Japanese side seems to be getting a lot of assurances from the U.S. through their highly personal channels of defense zoku (contacts).' Sato then served up a third, more prosaic, explanation. Appearing to be worried, he said, Tokyo would give away important leverage in tariff negotiations. The most compelling argument, one made by all my interlocutors, is that Japan has done a lot to consolidate the alliance and establish itself as an ally and partner worth defending. Corey Wallace, associate professor at Kanagawa University, explained it well. 'There is a feeling of having greater room for maneuver should Japan be faced with tough choices about the alliance and its national security direction compared to 2016.' Key to this process has been the three national security documents released in 2022 — the National Security Strategy, the National Defense Strategy and the Defense Buildup Program — that allow the country to play a bigger role in regional security and defense. Wallace noted that 'Not only has Japan made important strides since the beginning of Trump 1.0 in terms of spending more and beefing up the Self-Defense Forces, improving capabilities and even enhanced command elements, but Japanese leaders are more sanguine about being able to push through further changes should they be needed.' Wallace highlighted another critical development: the weave of relationships that Japan has created. Strategic partnerships have become more prominent. At SLD, Defense Minister Nakatani explained the 'One Cooperative Effort Among Nations' (OCEAN) concept for defense partnerships in the Indo-Pacific region. OCEAN will allow countries with shared values to 'have a panoramic perspective of the entire Indo-Pacific and bring new value and benefits to the region.' Defense cooperation is part of the package. (OCEAN is reportedly the newest iteration of the 'one theater' concept I discussed a few weeks ago.) As Wallace explained, 'Japanese leaders feel Japan is establishing itself within a wider security framework/network that might afford it some options and 'room for maneuver.'' Convinced? Color me skeptical. First, my sources distinguished economic and security issues. Their emphasis was on the latter, where there is agreement between the two strategic and bureaucratic communities. Japan is insistent, too, on separating the two. U.S. thinking may not be so neat and clean; indeed, Trump insists that allies take advantage of U.S. security expenditures to create their economic advantage. Second, there is the hold that Japan has on Trump. One of the few constants in his policy pronouncements — since the 1980s — is the assertion that Japan has exploited U.S. largesse and is the source of U.S. economic troubles. Finally, for all the convergence in strategic thinking, Trump has also been reluctant to shed blood in pursuit of foreign policy. He has railed against a foreign policy elite that launched forever wars and meddles in distant affairs. He likes measures that don't risk U.S. lives, such as drone attacks. That renders deterrence a bit shaky. Nor is it clear that Trump's contest with China extends to the military realm, although his national security advisers see the competition in that way. He frames the U.S.-China relationship in economic terms, mostly in the terms of trade. Combine this outlook with his reticence about bloodshed and a source of Japanese confidence dissipates. To my mind, then, Japan should be worried. But my friend was right — thus far, it isn't. Brad Glosserman is a senior adviser at Pacific Forum. His new book on the geopolitics of high-tech is expected to come out from Hurst Publishers this fall.