Paraguay and US tie intrusion to Flax Typhoon
Paraguay and the United States found Flax Typhoon on Paraguayan state networks after a joint review. Deputies asked for reports.
Paraguay and the United States detected Flax Typhoon on Paraguayan state networks after a joint cybersecurity review. The Chamber of Deputies asked the executive branch and Mitic for details on the scope of the infiltrations, affected systems and compromised data.
Update August 23, 2026: the joint review cited in the note was later clarified with the name of the detected group, Flax Typhoon, and with broader regional background on China-linked cyberespionage in Paraguay and other Latin American countries.
Paraguay and the United States carried out a joint cybersecurity review of Paraguayan state networks and found Flax Typhoon in government systems. The attribution put the activity of China-linked groups inside Paraguay's public infrastructure back into public debate.
What did the joint review detect in Paraguay?
The inspection identified Flax Typhoon in Paraguayan government networks, according to a communication released by Paraguay and U.S. Southern Command in December 2024. The review was part of a broader series of alerts about groups linked to the Chinese government inside state systems across the region.
Paraguayan authorities later said publicly that the inspection identified multiple threat actors linked to China and that the intrusions affected several state systems. That confirmation opened an additional diplomatic dispute with Beijing, beyond the technical issue, according to the information released by the authorities.
What regional background emerged later?
Later reporting expanded the map of activity attributed to China-linked groups in Latin America. In April 2025, Guatemala detected APT15 in systems at the Ministry of Foreign Affairs during a joint review with SOUTHCOM.
Reuters reported in February 2025 that UNC2814 had compromised at least 53 organizations in 42 countries, with a focus on government entities and telecommunications companies. Google later said it disrupted UNC2814, also identified as Gallium, and that the group had confirmed access to 53 entities in 42 countries, with suspected access in at least 22 more countries at the time of the intervention.
CrowdStrike said in its 2025 Latin America Threat Landscape report that in 2024 activity by groups linked to the Chinese Communist Party rose 150% from the previous year. The report also identified Vixen Panda, Aquatic Panda and Liminal Panda as active against government, telecommunications and defense targets.
ESET Research, in its regional analysis, said China-linked groups expanded their activity in Latin America and named Argentina, Ecuador, Guatemala, Honduras and Panama among the countries affected by FamousSparrow during the April to September 2025 period it reviewed. The same assessment described the region as a notable focus of China-aligned espionage, more sustained and broader than before.
What did the Chamber of Deputies request?
Paraguay's Chamber of Deputies formally asked the executive branch and the Ministry of Information and Communication Technologies, Mitic, to detail the true scope of the incidents, the systems and data breached, and the technical indicators supporting attribution to Chinese actors. It also asked for specifics on the scope of cooperation with U.S. intelligence and cybersecurity agencies.
The legislative request also sought a full copy of the official joint statement from Mitic and the U.S. government on the intrusion, along with all technical reports, audits and studies supporting the attribution. Among the elements mentioned were IP addresses, digital signatures and tools that, according to the parliamentary filing, would have been used by groups linked to the Chinese government.
What other measures and responses followed?
Lawmakers also demanded information on mitigation steps and state cybersecurity measures that Mitic says it adopted after detecting the intrusions. The request also includes the communication sent to the State Attorney General's Office for possible legal action.
China officially responded by rejecting the accusations from the United States and Paraguay about the involvement of agents linked to Beijing in the intrusion into Paraguayan government systems. The Chinese government called the claims unfounded and reaffirmed its position against cyberattacks.
Diálogo Americas also reported that Paraguay and SOUTHCOM had already identified Flax Typhoon in a joint review at the end of 2024, and that this earlier case was later cited in coverage by DPL News and Infobae about cyberattacks attributed to China-linked actors on Paraguayan state systems.
Sources
- Diputados pide informes sobre supuestos ciberataques de China al Gobierno de Santiago Peñaabc.com.py· ABC Color
- Estados Unidos y Paraguay detectaron infiltraciones cibernéticas de actores vinculados a China en sistemas estatales paraguayosinfobae.com· Infobae
- Paraguay atribuye ciberataques a China y abre una nueva disputa con Pekínnotipress.mx· NotiPress
- China nega acusação de ataque hacker contra o Paraguaiexame.com· Exame
- Paraguay | Declaración Conjunta sobre Operaciones Cibernéticas Maliciosas dirigidas al Gobiernodplnews.com· DPL News
- Ciberespionaje de China en Latinoamérica: Amenaza realdialogo-americas.com· Dialogo Americas
- China refuerza el ciberespionaje en Latinoamérica y Ucraniadefensa.com· Defensa.com
- Google disrupts Chinese-linked hackers that attacked 53 groups globallyreuters.com· ReutersUnverified URL
- China's Cyber Espionage in Latin America: A Real Threatdialogo-americas.com· Diálogo Americas
- Chinese Cyber Espionage Puts Latin America’s Critical Infrastructure at Riskdialogo-americas.com· Diálogo Americas
- Espionaje cibernético chino expone riesgos para la infraestructura crítica de Latinoaméricadialogo-americas.com· Dialogo Americas
- Estados Unidos y Paraguay detectaron infiltraciones cibernéticas de actores vinculados a China en sistemas estatales paraguayosinfobae.com· Infobae



