The Belgian secret service was no longer a secret to Beijing

In February 2025, a report shocked Belgium and the entire European intelligence community. Chinese hackers had had access to the email system of the State Security Service (VSSE) for years. For three years, Beijing was reading along with Belgian State Security. Not figuratively, but literally. Between 2021 and May 2023, Chinese hackers intercepted around ten percent of all incoming and outgoing emails from the VSSE, our intelligence service, which was no longer much of a secret to the People’s Republic. A vulnerability in software from an American supplier had left the door wide open. This was considered one of the largest breaches of Belgian state security ever. The federal prosecutor’s office opened an investigation, but the damage had already been done: sensitive information about operations, contacts, and possibly sources may have ended up in the hands of Chinese state actors.
And the worst part? Almost no one was surprised. No demonstrations on Schuman Square in Brussels, no emergency debate on Rue de la Loi, no minister slamming a fist on the table. One news story, a few days of outrage on X, and then we slipped back into our usual debates about privacy and cookie banners. That is the real headline of this story: not that China is reading along, but that we are letting it happen.

And no, this was not an isolated incident. It fits into a pattern of Chinese cyber espionage that is increasingly affecting Europe, and certainly Belgium as well. While Beijing is building a digital authoritarian system at home, with mass surveillance, social credit, and strict data control, it is exporting the same logic abroad. Cyber is no longer a side issue, but a strategic weapon in the struggle between great powers. And Europe is letting it happen.
From diplomatic emails to critical infrastructure
The VSSE hack was painfully visible, but there are more examples. In February 2025, the Port of Ostend became the victim of a cyberattack. The Ensor system, which tracks ship movements and crew lists, was hit. The port filed a complaint with the federal police, and the Centre for Cybersecurity Belgium (CCB) coordinated the response. Although not explicitly attributed to China in all reports, CERT-EU often places such incidents within the broader picture of China-linked threats against European infrastructure.
At the European level, the response is escalating. In March 2026, the EU sanctioned two Chinese companies, Integrity Technology Group and Anxun Information Technology, as well as two individuals and an Iranian company. Integrity Technology Group supplied tools that led to the hacking of more than 65,000 devices in six member states between 2022 and 2023. Anxun offered hacking services targeting critical infrastructure. These sanctions freeze assets and prohibit doing business in the EU. This shows that Brussels is no longer merely observing, but taking action. Still, the approach remains mainly reactive.
Why Belgium? Our country is a logistical and diplomatic hub: the Port of Antwerp, NATO headquarters, EU institutions in Brussels, and numerous diplomatic missions. Chinese actors target precisely these kinds of high-value targets for intellectual property, political insight, and pre-positioning ahead of future crises, for example around Taiwan or trade conflicts. And yes, we keep allowing ourselves to be caught off guard.
The Chinese strategy: cyber as an extension of state power
In China, the distinction between civilian and military is vague, or even deliberately absent: so-called civil-military fusion. Companies such as Huawei, or smaller players, often cooperate with or operate under pressure from the Ministry of State Security, China’s MSS. Hacker groups such as APT31, Salt Typhoon, Mustang Panda, and many others carry out targeted campaigns. They exploit vulnerabilities in routers, email systems, and supply chains, not always for immediate theft, but to maintain persistent access. They often hide inside our systems for months or years.
This is the export of domestic repression. The same ecosystem that monitors Uyghurs with AI-driven cameras and facial recognition, or intimidates dissidents in exile, is now targeting European governments and companies. Reports from the Dutch intelligence service, the MIVD, from 2026 state that Chinese cyber capabilities are now on the same level as those of the United States. They explicitly target the defence industry and telecommunications. While we are still discussing ethics and privacy, Beijing acts as though it is in a permanent cyberwar. One could call it a cyber economy, but I prefer to call it what it is: a cyberwar.
For Belgium, this means concrete risks. Diplomats, civil servants, and business leaders working with China face the threat of spear phishing or compromised devices. Economically, stolen technology accelerates China’s lead in AI, semiconductors, and “green” technology, while we remain dependent on highly risky supply chains.
Europe’s slow awakening
Europe is no longer a naïve victim, but its response remains embarrassingly slow and fragmented. Member states such as the Netherlands, Czechia, and Belgium have removed Huawei and other high-risk suppliers from the core of 5G networks, or are at least trying to do so: a very important but small step. Because elsewhere in the networks, among operators and especially among end users - smartphones, routers, IoT devices, surveillance cameras - Chinese brands are still massively present. They remain a potential gateway for espionage or sabotage. The EU AI Act, fully applicable from August 2026, and the revised Cybersecurity Act attempt to keep high-risk suppliers out of critical systems, but real de-risking requires more than just cleaning up core networks.
Member states are taking measures, but the economic temptation remains too strong: cheap Chinese technology, investments in ports, or EV factories. The sanctions of March 2026 are a step forward. But as long as profit is placed above security, we will remain vulnerable. Belgium, with its open economy, is paying the price for this schizophrenia: wanting to trade with China while preserving sovereignty. An impossible combination.
Time for a European cyber doctrine
We can no longer ignore this. China sees cyber as a domain of continuous struggle, with no peacetime. While we debate privacy and ethics, Beijing is building a digital battlefield. The VSSE hack, the port attack, and the subsequent EU sanctions are not incidents, but symptoms of a systemic threat.
For Belgian policymakers: stop taking half-hearted measures. Accelerate the implementation of national AI and cybersecurity policies, protect critical infrastructure end to end, not only the core, invest heavily in domestic talent and technology, and dare to make difficult choices about economic dependence. For companies: adopt zero-trust architectures, carry out supply-chain due diligence, and avoid unnecessary Chinese cloud or IoT solutions in sensitive sectors. For citizens and voters: understand that your data, your privacy, and the security of the country are inseparably linked.
The 21st century has become a tech war, and Europe is still half asleep. Belgium and Europe must now choose: remain victims in a world dominated by authoritarian regimes, or finally become serious players in digital sovereignty. How many hacks, how much stolen data, and how much lost strategic advantage will it take before we wake up? Time is running out. Beijing is not waiting for us to publish our policy papers. They are reading along while we type them.
Thijs Jansen is a Dutch cybersecurity expert with experience in threat analysis and digital defense. He follows the intersection of technology and geopolitics, with a particular focus on cyber operations carried out by authoritarian regimes and other foreign actors against European governments, companies, and critical infrastructure. As a staunch defender of individual freedom and sovereignty, he combines technical insights with strategic analysis in his columns to make readers aware of the hidden digital battlefields that affect our security and sovereignty, as well as the many geopolitical dimensions of cyber threats.
Image credits: Getty Images via Unsplash



