Skip to main content
Dragonfly
Are the mythical Chinese hackers a real threat to your company?

Are the mythical Chinese hackers a real threat to your company?

No, not if your infrastructure is looked after. According to various reports online, most incidents exploit vulnerabilities that predate 2024 — which makes them neglect, not hostile action.

Patryk Dawidziuk

Patryk Dawidziuk

Partner. Specialisms: Linux, L3 networking, virtualisation · 01.12.2025

Every attack on a company that gets explained away as a raid by “Chinese hackers” is worth putting through one filter: who actually failed here? The answer is almost always the same — not Chinese intelligence, but someone who had not updated software in years, had not rolled out MFA, was not monitoring the network, had not replaced ageing software, had not replaced ageing hardware. The list of “had nots” goes on.

What is really behind those attack reports?

Reports on Chinese APT groups (Advanced Persistent Threat) — the likes of APT10, APT41 or Volt Typhoon, and yes, the names do sound menacing — concern critical infrastructure, government administration and large corporations in defence, energy and telecoms. If you own a 20–200 person company in trade, manufacturing or services, you are of no interest to them. Not because your defences are good, but because you hold nothing they can turn into cash or leverage.

The cyberattacks that actually hit small and medium companies are:

  • ransomware — encrypting data and demanding payment (criminal groups, mainly from Russia and Eastern Europe)
  • phishing — tricking someone out of login details or a bank transfer
  • credential stuffing — using leaked passwords to break into company accounts
  • botnet exploitation — automated scanning of the internet for unpatched services

None of these needs Chinese intelligence. A bot and an unpatched router will do.

What does a vulnerable company actually look like?

When your IT tells you “it was a Chinese attack, nothing could be done” — ask specific questions:

Infrastructure

  • When was the firmware on the routers and firewall last updated?
  • Does the VPN use strong passwords and require MFA?
  • Is the RDP port (3389) reachable directly from the internet?
  • When was the last penetration test?

Monitoring

  • Are system logs collected and analysed (SIEM)?
  • Do you get alerts for logins outside working hours?
  • How long passed between the breach and its detection?

Procedures

  • Is there an incident response plan (IRP)?
  • When was restoring from backup last tested?
  • Is there an offline backup, cut off from the network?

If the answers are “I don’t know” or “a while ago” — you have a problem that has nothing to do with China. These are not all the questions worth asking, of course, but they are enough to form a view.

The vulnerabilities most often exploited in small and mid-sized companies

Unpatched VPN — Fortinet, Pulse Secure and Citrix devices have documented CVEs from 2020–2023 that still work today on instances nobody updated. A public exploit and a scanner are enough.

Exposed RDP — the remote desktop protocol published straight onto the internet is an invitation to brute-force attacks.

Exchange without patches — ProxyLogon (2021), ProxyShell (2021), ProxyNotShell (2022). Each of these allowed a full takeover of the mail server. Companies that did not update Exchange were scanned and taken over en masse by bots within hours of the exploits going public.

Passwords without MFA — leaked databases hold billions of login and password pairs. Without multi-factor authentication every account is exposed if the user ever reused that password somewhere else. And they did.

Poland has been implementing the NIS2 directive since 2024, extending cybersecurity obligations to a far wider set of organisations than before. If your company works in manufacturing, transport, digital services or waste management, NIS2 duties may apply to you.

What that means in practice:

  • an obligation to report incidents within 24 hours (initial) and 72 hours (full report)
  • a requirement to maintain a security policy and run regular audits
  • board-level responsibility for the state of the organisation’s cybersecurity
  • fines reaching EUR 10 million or 2% of global turnover

“The Chinese attacked us” is not a defence that removes responsibility. The question will be whether you took adequate preventive measures.

What to do after an incident

If you have just been through an attack and your IT department is filing reports about a “sophisticated APT attack”, insist on:

  1. A detailed post-breach analysis — which logs, which traces, which entry vector
  2. A list of systems the attacker could reach — what they could see, copy or encrypt
  3. An assessment of what data leaked — with a 72-hour reporting duty to the data protection authority where personal data is involved
  4. A remediation plan with a timetable — not “we will fix it”, but what exactly, by when, and who owns it
  5. Verification of your backups — whether the copies are intact and the systems can be restored

If your IT partner cannot deliver this, your problem is with the partner, not with China.

When the threat is real

There are situations where advanced state-backed attacks can reach a smaller company, indirectly. The most common scenario: your company is a subcontractor or supplier to an organisation in defence, energy or government. The attacker comes in through the weaker link in the supply chain.

If those are your clients, the security bar has to be considerably higher: network segmentation, zero trust, regular audits, identity management.

For everyone else: get the basics right. Updates, MFA, monitoring, offline backup. That removes most of the threats that are actually out there.

Contact

Let's talk about which parts of your business we can improve

Call us

Visit us at our office
ul. Stargardzka 7 (off Metalowców),
54-156 Wrocław

office hours: 8:30 am – 5 pm on weekdays