Countering China's "Typhoon" Threats Targeting US Critical Infrastructure

Marc Raimondi (Chief of Staff · Silverado Policy Accelerator), Brett Leatherman (Deputy Assistant Director, Cyber Operations · Federal Bureau of Investigation), Wendi Whitmore (Senior Vice President, Unit 42 · Palo Alto Networks), Tim Maurer (Senior Director, Global Cybersecurity Policy · Microsoft), John Carlin (Partner · Paul Weiss)

RSA Conference 2025 · Day 1 · Policy · Policy & Government

Overview

A high-profile panel featuring FBI, Microsoft, Palo Alto Networks, and former senior Justice Department officials gathered at RSA Conference 2025 to deliver an unambiguous assessment of the China Typhoon threat: PRC-affiliated actors have shifted from intellectual property theft to pre-positioning inside U.S. critical infrastructure in preparation for potential kinetic conflict. The response requires a restructured public-private collaboration model, updated legal incentive frameworks, and a fundamental reconceptualization of what it means to be a victim of nation-state cyber intrusion. Attribution, disruption, and information sharing are the three levers available — and all three need to be deployed simultaneously. ---

Watch on YouTube

Visual summary for Countering China's "Typhoon" Threats Targeting US Critical Infrastructure by Marc Raimondi, Brett Leatherman, Wendi Whitmore, Tim Maurer, John Carlin
Visual summary for Countering China's "Typhoon" Threats Targeting US Critical Infrastructure by Marc Raimondi, Brett Leatherman, Wendi Whitmore, Tim Maurer, John Carlin

Key moments

  1. 3:05 PRC cyber ops shifted in 18-24 months from espionage to kinetic-conflict pre-positioning
  2. 4:03 Public attribution of Flax Typhoon forced complete Chinese actor withdrawal
  3. 5:51 Palo Alto research: single Typhoon campaign compromised 23 government agencies globally
  4. 8:11 Volt Typhoon declared paradigm shift: targets civilian infrastructure, not intelligence collection
  5. 11:23 Typhoon campaigns depart from spirit of 2015 US-China cyber non-aggression agreement
  6. 14:00 Early FBI engagement extends SEC breach disclosure window from 4 days to 90 days
  7. 13:21 FBI reframes victim engagement: nation-state intrusions are not the company's fault
  8. 5:35 China exploits CVEs faster than organizations can patch, making remediation timelines obsolete

Countering China's "Typhoon" Threats Targeting US Critical Infrastructure

Speakers: Marc Raimondi (Silverado Policy Accelerator), Brett Leatherman (FBI), Wendi Whitmore (Palo Alto Networks), Tim Maurer (Microsoft), John Carlin (Paul Weiss)

Event: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco

Watch: YouTube — Countering China's "Typhoon" Threats Targeting US Critical Infrastructure

Reading time: ~9 minutes

TL;DR

A high-profile panel featuring FBI, Microsoft, Palo Alto Networks, and former senior Justice Department officials gathered at RSA Conference 2025 to deliver an unambiguous assessment of the China Typhoon threat: PRC-affiliated actors have shifted from intellectual property theft to pre-positioning inside U.S. critical infrastructure in preparation for potential kinetic conflict. The response requires a restructured public-private collaboration model, updated legal incentive frameworks, and a fundamental reconceptualization of what it means to be a victim of nation-state cyber intrusion. Attribution, disruption, and information sharing are the three levers available — and all three need to be deployed simultaneously.

Introduction

The session was titled "Storm Watch," and the metaphor was apt. For the past two years, a succession of Chinese state-sponsored threat actor groups — Volt Typhoon, Flax Typhoon, Salt Typhoon, Silk Typhoon, and others — have mounted an escalating campaign of intrusions into Western critical infrastructure that senior U.S. government officials have described in the starkest possible terms: this is not espionage for financial or intelligence gain. It is pre-positioning for wartime disruption.

At RSA Conference 2025, moderator Marc Raimondi, Chief of Staff at the Silverado Policy Accelerator, convened a panel with the operational and legal depth to go beyond the headlines. Brett Leatherman, Deputy Assistant Director of the FBI's Cyber Division, brought law enforcement's perspective on tracking and disrupting these campaigns. Wendi Whitmore, recently elevated from SVP of Unit 42 to Chief Security Intelligence Officer at Palo Alto Networks, provided the global industry view. Tim Maurer, Senior Director for Global Cybersecurity Policy at Microsoft, explained how Volt Typhoon's discovery reshaped the company's threat assessment framework. And John Carlin, a partner at Paul Weiss who has served as both Acting Deputy Attorney General and Assistant Attorney General for National Security, placed the current threat in the historical context of twenty years of China-U.S. cyber confrontation.

From Intellectual Property Theft to Pre-Positioning for Conflict

The panel's opening exchange established the most critical contextual shift: China's cyber operations against the West have fundamentally changed in character over the past eighteen to twenty-four months.

▶ Watch: PRC shift to critical infrastructure pre-positioning (02:00)

Brett Leatherman described the historical arc from the FBI's vantage point. The bureau has tracked PRC-directed cyber threats for decades, beginning with campaigns targeting universities and corporations for competitive intellectual property. That threat model was damaging but comprehensible within a framework of economic espionage. What the FBI is now documenting is categorically different: actors leveraging sophisticated obfuscation networks and advanced tactics to burrow into transportation, maritime, manufacturing, and telecommunications infrastructure — not to steal information, but to establish persistent access that could be weaponized in a conflict scenario.

"In peacetime, the weaponization of that access — it's incredibly important that the U.S. government, that industry works together to illuminate that," Leatherman said. The FBI's approach, confirmed by the Flax Typhoon operation, is that public attribution forces actors to either adapt their techniques or withdraw entirely. When the bureau and its partners publicly attributed Flax Typhoon's botnet to the Chinese Communist Party and conducted lawful technical operations against the infrastructure, the actors withdrew. That disruption only became possible because industry partners provided the visibility the government alone could not generate.

The Typhoon Threat Is Global — Not Just a U.S. Problem

Wendi Whitmore contextualized the Typhoon campaigns within Palo Alto Networks' global network perspective, which spans organizations in dozens of countries. The targeting pattern she described is broader than most public reporting has captured.

▶ Watch: Global scope of China's Typhoon campaigns (04:00)

Whitmore noted that her team had released research documenting a "whole of government compromise" across twenty-three different government agencies in a single campaign — and that the PRC's operations extend well beyond U.S. targets. Governments that maintain close relationships with China are not exempt. Even nations that consider themselves friendly to Beijing are being subjected to the same categories of pre-positioning and corporate espionage.

The technical signature of these campaigns reflects a deliberate evolution in adversary sophistication. Chinese nation-state actors are now exploiting CVEs at scale, often reaching vulnerable systems before organizations have patched them — and compressing that exploitation cycle to a degree that makes conventional patch-and-remediate timelines inadequate. "We've seen the Chinese nation-state in particular become even more aggressive, more expansive, really being able to leverage technology to scale their operations," Whitmore said.

She emphasized that this is not primarily an issue of novel zero-day development, but of operational speed and scale: the ability to identify, exploit, and establish persistence across a large number of targets faster than defenders can respond.

▶ Watch: PRC exploitation at scale and speed (05:00)

Volt Typhoon as a Paradigm Shift — and What Microsoft's Discovery Revealed

Tim Maurer explained how Microsoft came to characterize Volt Typhoon as a "paradigm shift" among the threat actors the company tracks — not merely a more sophisticated version of existing espionage campaigns, but a qualitatively different category of threat.

▶ Watch: Why Volt Typhoon is a paradigm shift (06:30)

The defining characteristic is targeting. Where most nation-state threat actors, including other PRC-affiliated groups, are primarily focused on espionage — collecting information that serves intelligence or economic objectives — Volt Typhoon's targeting set is built around critical infrastructure entities across transportation, maritime, and manufacturing sectors. Microsoft's leadership has been explicit that this targeting rationale places Volt Typhoon in a different category from espionage-focused actors: the access being established is not useful for reading secrets, but for disrupting operations in ways that would matter during a conflict.

Maurer drew on his background in both academia and senior government roles to situate this within the longer arc of U.S.-China cyber policy. The 2015 Obama-Xi agreement — in which both governments pledged not to conduct cyber operations targeting private companies for private financial gain, nor to target critical infrastructure in ways that could harm civilian populations — was a direct product of the earlier wave of PRC IP theft. That agreement represented progress. The Typhoon campaigns represent a departure from its spirit if not its letter, targeting infrastructure in ways that carry a clear military-strategic rationale.

The takeaway for Maurer was structural: companies cannot solve this problem alone, and the current government-industry collaboration model needs to evolve toward something closer to a genuine partnership, with government providing actionable intelligence back to companies in exchange for the visibility that only industry can supply.

The Legal Framework: Carrots, Sticks, and the Case for Coming In Early

John Carlin offered the session's most pointed policy critique — and its most practical advice for organizations currently facing intrusions or uncertain about whether and when to engage the FBI.

▶ Watch: Legal framework for victim engagement with FBI (10:00)

Carlin traced his own experience from the moment when, upon joining the Justice Department's national security division, he encountered the full scale of China's operations for the first time. The initial government approach had kept attribution and victim notification behind compartmented doors — a model that made sense for protecting intelligence sources but actively prevented the private sector from defending itself. The shift toward public attribution, culminating in the 2014 indictment of five People's Liberation Army officers, was a deliberate decision to treat corporate victims as stakeholders in a collective defense rather than passive recipients of classified information they were not permitted to share.

Today, Carlin argued, the legal incentive structure still does not adequately reward cooperation. When a nation-state is responsible for an intrusion, the calculus should make engagement with law enforcement the obvious choice — not the costly and uncertain one. He pointed to SEC cyber disclosure rules as one example of a framework that can be made more cooperation-friendly: under current rules, a publicly traded company facing a material cybersecurity incident has four days to disclose. But if the incident involves a national security dimension and the Attorney General certifies a public safety interest, that window can be extended to thirty, sixty, or ninety days — provided the company has engaged proactively with the FBI.

▶ Watch: SEC disclosure rules and national security carve-outs (14:00)

"The only way to do that is to come in to talk to the FBI and get the approval from the attorney general," Carlin said. "If you wait until you've determined that it is a material event and you only have four days, it's no" — cutting off to underscore the urgency. Early engagement, he argued, routinely results in better tactical outcomes for victim organizations, as the FBI is now explicitly structured to treat companies as victims rather than re-victimizing them with regulatory burdens.

Leatherman confirmed the cultural shift at the bureau: the FBI's number one goal when a company comes in is to provide tactical intelligence derived from what the agency knows about how the same actor has operated against other targets — helping the victim get the threat actor out of their systems as quickly as possible. "In no other space as a victim are you expected to do this on your own," Carlin noted.

Notable Quotes

"Over the last eighteen to twenty-four months, that threat has shifted dramatically towards pre-positioning in critical infrastructure, leveraging obfuscation networks, and leveraging more sophisticated tactics, techniques, and procedures to target U.S. critical infrastructure in preparation for likely some sort of kinetic event." — Brett Leatherman, FBI

"The Chinese nation-state in particular has become even more aggressive, more expansive, really being able to leverage technology to scale their operations." — Wendi Whitmore, Palo Alto Networks

"Because of the specific targeting of critical infrastructure entities within the United States across different sectors — transportation, maritime, manufacturing — our leadership has been explicit about why it considers this to fall into a different category." — Tim Maurer, Microsoft

"In no other space as a victim are you expected to do this on your own, and nor are you viewed as it's your fault if a nation state attacks you." — John Carlin, Paul Weiss

"What we should do is continue to encourage companies and change the calculus so that the only right choice is to come in and share when there's a nation state." — John Carlin, Paul Weiss

Key Takeaways

  1. The PRC's cyber posture has shifted from espionage to pre-positioning — Typhoon campaigns across transportation, maritime, manufacturing, and telecommunications are establishing persistent access intended for wartime disruption, not information collection.
  1. Public attribution works as a disruption tool — the Flax Typhoon operation demonstrated that when the FBI and partners publicly attributed a campaign to the CCP and conducted lawful technical operations, the actors withdrew completely.
  1. The threat is global, not bilateral — Palo Alto Networks documented twenty-three government agencies compromised in a single campaign, and even nations with close ties to China are being targeted.
  1. Volt Typhoon represents a paradigm shift — its targeting of civilian critical infrastructure with no intelligence collection rationale places it in a category distinct from conventional espionage, requiring a commensurately distinct response.
  1. Early FBI engagement is the strategically correct choice for victim companies — the national security carve-out in SEC disclosure rules allows the four-day reporting window to be extended to thirty, sixty, or ninety days for companies that proactively engage with law enforcement, and the FBI is now structured to provide tactical intelligence to victims, not to re-victimize them.
  1. The legal incentive framework needs recalibration — current rules do not adequately reward cooperation when nation-state actors are responsible for intrusions; getting the carrots and sticks right is essential to building the collective defense posture the Typhoon threat demands.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

The most operationally significant panel of RSA 2025. Not because the threat is news — it isn't — but because FBI, Microsoft, Palo Alto, and John Carlin together provide a level of attribution specificity, operational context, and legal framework guidance that you simply do not get from open-source reporting. Carlin's SEC four-day vs. ninety-day disclosure window mechanics alone justifies the time investment for any GC or CISO at a publicly traded company in critical infrastructure sectors.

Heather Calloway (CISO) — STRONG ACCEPT

FBI, Palo Alto Networks, Microsoft, and former Acting Deputy AG John Carlin explain China's Typhoon campaigns as a categorical shift from espionage to pre-positioning for conflict, document 23 government agencies compromised in a single campaign, and make the operational case for early FBI engagement by victim organizations.

→ Top-rated talks at RSA Conference 2025

All talks from RSA Conference 2025