China-linked hackers reportedly breached telecoms and government agencies using Google Sheets

THE BRIEF
Cybersecurity Dive reported on February 25, 2026, that China-linked hackers breached dozens of telecommunications companies and government agencies. The report highlighted a technique in which malware hid in plain sight on Google Sheets. The supplied account does not provide further details about the affected organizations, the malware’s operation, how Google Sheets was used, the duration of access, the data involved, or the attackers’ objectives. It also does not establish whether “China-linked” describes a confirmed attribution or an assessment made by investigators; the supplied headline uses that wording. The central security lesson presented by the excerpt is that malicious activity may be concealed within a familiar, legitimate cloud service rather than appearing as an obviously suspicious standalone tool. Organizations that rely on Google Sheets should therefore treat unexpected or unusual activity involving the service as worth reviewing, while avoiding assumptions beyond the report’s limited description. This brief records the reported technique and scope without adding unverified details.
WHY IT MATTERS
According to the supplied report, the activity combined a potentially broad target set—dozens of telecommunications companies and government agencies—with concealment in a familiar productivity service. That combination matters because security programs may focus on clearly malicious infrastructure or unusual tools and overlook activity occurring within legitimate platforms. The available facts do not show what was accessed, how long attackers remained present, or whether the technique succeeded in every listed environment. Even so, the report supports reviewing trusted cloud services as part of defensive monitoring, while keeping the attribution and operational details appropriately qualified.
WHO SHOULD CARE
Telecom operators, government agencies, security teams, cloud administrators, and organizations using Google Sheets should consider whether their monitoring and review processes can identify suspicious activity in trusted services.
WHAT TO DO NOW
- Review Google Sheets access, sharing, and activity logs for unexpected or unusual behavior.
- Confirm that monitoring covers activity involving cloud collaboration services, including Google Sheets.
- Investigate anomalous Sheets-related activity alongside endpoint and security telemetry rather than relying on a single signal.
- Brief defenders on the report’s limited attribution and avoid treating “China-linked” as a confirmed conclusion without additional evidence.