Chinese hackers and user lapses turn smartphones into a 'mobile security crisis'
WASHINGTON (AP) —
Cybersecurity investigators noticed a highly unusual software crash — it was affecting a small number of smartphones belonging to people who worked in government, politics, tech and journalism.
The crashes, which began late last year and carried into 2025, were the tipoff to a sophisticated cyberattack that may have allowed hackers to infiltrate a phone without a single click from the user.
The attackers left no clues about their identities, but investigators at the cybersecurity firm iVerify noticed that the victims all had something in common: They worked in fields of interest to China's government and had been targeted by Chinese hackers in the past.
Foreign hackers have increasingly identified smartphones, other mobile devices and the apps they use as a weak link in U.S. cyberdefenses. Groups linked to China's military and intelligence service have targeted the smartphones of prominent Americans and burrowed deep into telecommunication networks, according to national security and tech experts.
It shows how vulnerable mobile devices and apps are and the risk that security failures could expose sensitive information or leave American interests open to cyberattack, those experts say.
'The world is in a mobile security crisis right now,' said Rocky Cole, a former cybersecurity expert at the National Security Agency and Google and now chief operations officer at iVerify. 'No one is watching the phones.'
US zeroes in on China as a threat, and Beijing levels its own accusations
U.S. authorities warned in December of a sprawling Chinese hacking campaign designed to gain access to the texts and phone conversations of an unknown number of Americans.
'They were able to listen in on phone calls in real time and able to read text messages,' said Rep. Raja Krishnamoorthi of Illinois. He is a member of the House Intelligence Committee and the senior Democrat on the Committee on the Chinese Communist Party, created to study the geopolitical threat from China.
Chinese hackers also sought access to phones used by Donald Trump and running mate JD Vance during the 2024 campaign.
The Chinese government has denied allegations of cyberespionage, and accused the U.S. of mounting its own cyberoperations. It says America cites national security as an excuse to issue sanctions against Chinese organizations and keep Chinese technology companies from the global market.
'The U.S. has long been using all kinds of despicable methods to steal other countries' secrets,' Lin Jian, a spokesman for China's foreign ministry, said at a recent press conference in response to questions about a CIA push to recruit Chinese informants.
U.S. intelligence officials have said China poses a significant, persistent threat to U.S. economic and political interests, and it has harnessed the tools of digital conflict: online propaganda and disinformation, artificial intelligence and cyber surveillance and espionage designed to deliver a significant advantage in any military conflict.
Mobile networks are a top concern. The U.S. and many of its closest allies have banned Chinese telecom companies from their networks. Other countries, including Germany, are phasing out Chinese involvement because of security concerns. But Chinese tech firms remain a big part of the systems in many nations, giving state-controlled companies a global footprint they could exploit for cyberattacks, experts say.
Chinese telecom firms still maintain some routing and cloud storage systems in the U.S. — a growing concern to lawmakers.
'The American people deserve to know if Beijing is quietly using state-owned firms to infiltrate our critical infrastructure,' U.S. Rep. John Moolenaar, R-Mich. and chairman of the China committee, which in April issued subpoenas to Chinese telecom companies seeking information about their U.S. operations.
Mobile devices have become an intel treasure trove
Mobile devices can buy stocks, launch drones and run power plants. Their proliferation has often outpaced their security.
The phones of top government officials are especially valuable, containing sensitive government information, passwords and an insider's glimpse into policy discussions and decision-making.
The White House said last week that someone impersonating Susie Wiles, Trump's chief of staff, reached out to governors, senators and business leaders with texts and phone calls.
It's unclear how the person obtained Wiles' connections, but they apparently gained access to the contacts in her personal cellphone, The Wall Street Journal reported. The messages and calls were not coming from Wiles' number, the newspaper reported.
While most smartphones and tablets come with robust security, apps and connected devices often lack these protections or the regular software updates needed to stay ahead of new threats. That makes every fitness tracker, baby monitor or smart appliance another potential foothold for hackers looking to penetrate networks, retrieve information or infect systems with malware.
Federal officials launched a program this year creating a 'cyber trust mark' for connected devices that meet federal security standards. But consumers and officials shouldn't lower their guard, said Snehal Antani, former chief technology officer for the Pentagon's Joint Special Operations Command.
'They're finding backdoors in Barbie dolls,' said Antani, now CEO of Horizon3.ai, a cybersecurity firm, referring to concerns from researchers who successfully hacked the microphone of a digitally connected version of the toy.
Risks emerge when smartphone users don't take precautions
It doesn't matter how secure a mobile device is if the user doesn't follow basic security precautions, especially if their device contains classified or sensitive information, experts say.
Mike Waltz, who departed as Trump's national security adviser, inadvertently added The Atlantic's editor-in-chief to a Signal chat used to discuss military plans with other top officials.
Secretary of Defense Pete Hegseth had an internet connection that bypassed the Pentagon's security protocols set up in his office so he could use the Signal messaging app on a personal computer, the AP has reported.
Hegseth has rejected assertions that he shared classified information on Signal, a popular encrypted messaging app not approved for the use of communicating classified information.
China and other nations will try to take advantage of such lapses, and national security officials must take steps to prevent them from recurring, said Michael Williams, a national security expert at Syracuse University.
'They all have access to a variety of secure communications platforms,' Williams said. 'We just can't share things willy-nilly.'
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


CNN
24 minutes ago
- CNN
Sellers: US under Trump is ‘drifting towards authoritarianism' – full interview
CNN Political Commentators Bakari Sellers, Xochitl Hinojosa, Kristen Soltis Anderson, and Republican Rep. Nicole Malliotakis join CNN's Dana Bash to respond to President Trump's decision to federalize thousands of National Guard troops and deploy them to Los Angeles.


CNN
25 minutes ago
- CNN
GOP Sen. Johnson: Trump's bill ‘just doesn't go far enough' to cut spending
Republican Sen. Ron Johnson tells CNN's Dana Bash that "nothing's really changed" in his criticism of President Trump's spending and tax cut bill.


Fox News
29 minutes ago
- Fox News
CHUCK DEVORE: Trump moves fast to save LA from a 1992 repeat
Los Angeles is rioting again. Mobs, amped up by professional agitators and implicit support from Democratic elected officials, have attacked federal law enforcement officers with deadly intent. This violence, which includes hurling rocks, torching cars, launching fireworks, and assaulting federal law enforcement officers, aims to prevent U.S. Immigration and Customs Enforcement's (ICE) from carrying out lawful deportation efforts. Missing the irony, the rioters enthusiastically waved the flags of nations to which they are fighting against being returned. In response, federal and some local law enforcement deployed tear gas and flash bangs to disperse the crowd in the LA suburb of Paramount. But with law enforcement lives clearly threatened and the local law enforcement response less than robust, President Donald Trump ordered up 2,000 members of the National Guard to restore order. Additional active duty troops are said to be on standby. Predictably, California Gov. Gavin Newsom and LA Mayor Karen Bass clutch their pearls, whining about "cruel" immigration enforcement while the city spirals into anarchy. Newsom labeled Trump's federalization of the National Guard "purposefully inflammatory." He said it would escalate tensions—one supposes the future presidential candidate sees the ruckus as "mostly peaceful." The pro-immigration without limits group, the League of United Latin American Citizens, predictably condemned Trump's order, claiming it "marks a deeply troubling escalation in the administration's approach to immigration and civilian reaction to the use of military-style tactics." Trump isn't moved by the criticism. He doesn't want to see federal law enforcement officers killed or injured by anarchists and would-be revolutionaries for simply doing their jobs. I saw this movie before. In 1992, as a California Army National Guard captain, I patrolled LA's scorched Crenshaw District during the Rodney King riots. Looters ran wild, businesses burned, and chaos reigned until Gov. Pete Wilson called up the National Guard and President George H.W. Bush invoked the Insurrection Act, sending 3,500 federal troops—active duty Army and Marines—to back 10,000 federalized Guardsmen. Order swiftly returned. It worked. There's a big difference—so far—between today's unrest and that of 1992. The Rodney King riot was initially sparked by resentment over what was seen as excessive police force. Due to LA's chronically under-staffed police department and a tactical error—pulling back law enforcement from an intersection that had been taken over by a violent mob—the riot quickly spiraled out of control. By the end, some 63 people were dead, 2,383 injured, 12,111 arrested, and more than $2.3 billion in inflation-adjusted property damage was inflicted. In comparison, the 1992 LA riot equaled all the death, injuries, arrests, and damage of the 2020 George Floyd-Antifa-BLM riots of 2020 combined. In 1992, once law and order broke down, opportunistic looting and arson quickly followed. Today's riots are fueled by open-borders radicals and their enablers, not anger over police using excessive force. ICE is enforcing federal law, rounding up illegal immigrant criminals and those with final deportation orders. And the danger, so far, is more focused on federal law enforcement officers, not private property per se. Thus, there's a subtle difference in the call-up of troops, both in the size of the deployment—13,500 in 1992 vs. 2,000 today—and in their purpose. Normally, National Guard personnel, when operating on a state mission for a governor, can enforce civilian law. The post-Civil War Posse Comitatus Act which generally prohibits the use of the military to enforce civilian laws doesn't apply. But when the Guard is federalized—that is, called up to federal service—the Posse Comitatus Act's restrictions apply to the Guard, just as they do to active-duty service members. But there's a big exception: The Insurrection Act. Through 1992, presidents have invoked the Insurrection Act 31 times. Essentially, when local law and order break down, the president is authorized to use the military to enforce civilian law. But Trump has not yet invoked the Insurrection Act. What he did instead was to call up the California National Guard and potentially some Marines to protect federal law enforcement officers. Thus, these military personnel will not be allowed to arrest agitators and rioters or conduct immigration enforcement operations, but they will be allowed to perform force protection missions and provide logistical support. Of course, if that's not enough. Trump can always invoke the Insurrection Act, federalize more National Guard soldiers—even from other states—and send in additional active-duty forces, just as Eisenhower and Kennedy did to smash segregationist resistance in the 1950s and 60s. Newsom and Bass are at fault here. Their failure is glaring. Californians have been voting with their feet for years, fleeing Newsom's wrong-headed policies. Now, his mismanagement of LA's violence will torch what is left of his presidential ambitions. These rioters aren't protesters—they're insurgents. Like Antifa in 2020, they're attacking federal authority, targeting ICE agents enforcing laws Congress passed. Newsom and Bass coddle them. Since they won't act, Trump must. The left will scream "tyranny," and some retired generals will fret about "politicizing" the military. But anarchy is a brutal tyranny of its own kind.