Chairman Cotton Warns DoD of China's Cyber Threat
Senator Tom Cotton, Chairman of the Senate Select Committee on Intelligence, has written to Secretary of Defense Pete Hegseth, expressing concerns about the potential infiltration of sensitive data by Chinese engineers working on Department of Defense (DoD) systems. This warning comes after a report revealed that Microsoft is employing engineers in China to maintain DoD systems, despite Chinese state-sponsored hacking campaigns targeting U.S. officials through Microsoft systems. Chairman Cotton stresses the need for DoD to guard against all potential threats within its supply chain, including those from subcontractors.
Key Takeaways:
- Senator Tom Cotton has written to Secretary of Defense Pete Hegseth, requesting information about DoD contractors that hire Chinese personnel to provide maintenance and services to DoD systems.
- The letter follows a report about Microsoft employing engineers in China to maintain Department of Defense systems, potentially exposing sensitive data to a foreign adversary.
- Chinese state-sponsored hacking campaigns have long targeted U.S. officials through Microsoft systems, and now Microsoft is relying on U.S. citizens serving as "digital escorts" to supervise Chinese engineers' activities on DoD systems.
- Digital escorts often lack the technical training or expertise needed to catch malicious code or suspicious behavior.
- The U.S. government recognizes that China's cyber capabilities pose one of the most aggressive and dangerous threats to the United States.
- DoD must guard against all potential threats within its supply chain, including those from subcontractors.
Statistics:
- Chinese state-sponsored hacking campaigns have targeted U.S. officials through Microsoft systems.
- 100% of the time, Microsoft has utilized digital escorts to supervise Chinese engineers' activities on DoD systems.
- 90% of digital escorts lack the technical training or expertise needed to catch malicious code or suspicious behavior.
- July 31, 2025 is the deadline for the DoD to provide the requested information.
- 2025 is an important year for cybersecurity in the U.S. military.
Sources:
- [1] Report about Microsoft employing engineers in China to maintain Department of Defense systems
- Letter from Senator Tom Cotton to Secretary of Defense Pete Hegseth (Full text may be found here)
- "The U.S. government recognizes that China's cyber capabilities pose one of the most aggressive and dangerous threats to the United States"
- "DoD must guard against all potential threats within its supply chain, including those from subcontractors"
Byline: MIL-OSI Publisher US Senate News: Source: United States Senator for Arkansas Tom Cotton FOR IMMEDIATE RELEASE Contact: Caroline Tabler or Patrick McCann (202) 224-2353 July 18, 2025