# UK, allies expose China-linked global espionage actors

Published: 2026-10-08 · Severity: routine · Sectors: government-national
Canonical: https://vorant.io/reports/7a43b827-9a25-588a-8512-47cf8a3d0748/uk-allies-expose-china-linked-global-espionage-actors

> UK NCSC and international partners issued a joint advisory on China-linked actors compromising networks worldwide to steal sensitive data.

The NCSC, alongside international partners, published a joint advisory calling out China-linked malicious cyber actors for exploiting and compromising organisational networks globally to access sensitive data. The published announcement is a brief notice pointing to the advisory rather than a detailed technical report, so specific indicators of compromise, exploited vulnerabilities, malware names, or tactics, techniques and procedures are not included in this excerpt.

Defenders should treat this as a signal to review the full joint advisory referenced by NCSC and partner agencies for detailed technical guidance, affected sectors, and mitigation recommendations, as the activity described spans multiple countries and targets organisations broadly rather than a single sector or product.

## Mentioned in this report

- Threat actors: China-linked actors

Source reporting: https://www.ncsc.gov.uk/news/china-linked-actors-called-out-by-uk-and-international-partners-for-targeting-sensitive-data

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7a43b827-9a25-588a-8512-47cf8a3d0748/uk-allies-expose-china-linked-global-espionage-actors.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
