China’s Cyber Spies Targeted President Trump’s Circle

August 2, 2026

Share Article:

Using America's Own Home Networks

When most of us hear about foreign hackers, we picture someone far away typing away in another country. But according to U.S. investigators, one of China’s biggest spying operations used something much closer to home: regular internet routers sitting in American houses and small businesses.

In March 2024, the U.S. Department of Justice charged seven people tied to a Chinese government hacking group called APT31. Prosecutors say these hackers worked for China’s Ministry of State Security and spent more than ten years spying on Americans. Their targets included U.S. government officials, Members of Congress, journalists, defense companies, and people connected to President Trump’s presidential campaign.


You can read the Justice Department’s announcement here:

https://www.justice.gov/archives/opa/pr/seven-hackers-associated-chinese-government-charged-computer-intrusions-targeting-perceived


President Trump’s Campaign Was in Their Crosshairs

According to the Justice Department and the official MITRE ATT&CK database, APT31 went after individuals linked to President Trump’s 2020 campaign as part of a larger effort to gather intelligence.

The Justice Department has not said the hackers changed any votes or messed with election results. Their goal was simpler and more dangerous in a different way: they wanted information. They wanted insight into American political leaders and the people around them.


The targeting didn’t stop with the campaign. Federal investigators say the same group also went after:

  • White House officials
  • U.S. Senators
  • Members of Congress
  • Campaign staff
  • Defense contractors
  • Journalists
  • Foreign policy experts
  • Chinese dissidents living in the United States and overseas


Taken together, this was one of the biggest Chinese cyber-spying operations the United States has ever publicly charged.


You can see the official group profile here:

https://attack.mitre.org/groups/G0128/


It Often Started With a Simple Email

Investigators say APT31 sent more than 10,000 emails that looked like normal news stories or messages from journalists.


Here’s the part that should bother everyone: many people didn’t even need to click a link. Depending on how their email was set up, just opening the message could send the hackers useful information, things like an IP address, a rough location, the type of computer or phone being used, and other technical details.

According to the indictment, the hackers sometimes went after spouses and family members next. Why? Because home internet networks are usually less protected than government systems. Once they got into a home router, they had a new way in.


Hiding Behind Everyday American Homes

This is the part that feels especially wrong.

Cybersecurity researchers have described something called Operational Relay Box networks, or ORBs. These are large collections of compromised home routers, internet devices, and other equipment that hackers use to hide where their attacks really come from.

Instead of the traffic looking like it came from China, it can look like it came from a regular house or small business right here in the United States.

Researchers at Mandiant, which is owned by Google, have written about one of these networks called FLORAHOX. It relies in part on compromised routers from companies like Cisco, ASUS, and DrayTek. Public reporting has linked APT31 to these kinds of techniques during their spying operations.


You can read Mandiant’s report here:

https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-orb-networks


Why This Should Matter to All of Us

This case shows that China’s cyber operations are not just about attacking military bases or secret government computers. According to U.S. investigators, they are willing to use the weakest links they can find, including outdated home routers, to learn about America’s elected leaders, government officials, and political campaigns.


The White House, FBI, NSA, CISA, and the Justice Department have all warned that Chinese state-sponsored hackers remain one of the most active and persistent cyber threats facing the United States. They continue to go after government agencies, businesses, and critical infrastructure.


The Bottom Line

The Justice Department’s case against APT31 is a clear reminder that foreign intelligence operations no longer stay inside secret facilities overseas. They are using the everyday technology millions of Americans rely on without a second thought.

Whether the target is a Member of Congress, a business leader, or people connected to President Trump’s campaign, the lesson stays the same. Keeping home networks secure, updating internet equipment, and staying alert to suspicious emails are no longer just personal good habits. They are part of protecting the country’s security.


Official sources for further reading:


Follow Us:

Latest Articles, Submissions & Community Highlights

Participating groups, neighborhood leaders, and citizen coalitions can share news, documents, or resources here.

July 30, 2026
Discover why Elgin Township local property taxes fund multi-million dollar non-profits. We question government spending transparency and accountability
By Eric Stare July 29, 2026
New research suggests fetal consciousness may begin before birth in the third trimester, raising important ethical questions about prenatal life and care
July 28, 2026
Election‑integrity fight over the SAVE Act and citizenship‑only voting, as critics say Democrats block reforms.