news.mlab.sh
Back to the feed
threat-intel

China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans

High
Summary

China’s military procurement system has suspended or permanently barred over a dozen leading cybersecurity firms since 2024, primarily due to concerns about collusive bidding and not product failures. These companies, including TopSec, Venustech, and Qi An Xin, have long-standing ties to the PLA and China’s security services, supporting military cyber operations. The crackdown is part of a broader effort to professionalize defense acquisition and doesn’t necessarily indicate a weakening of China’s cybersecurity capabilities.

China’s military procurement system has implemented significant restrictions on leading cybersecurity firms since 2024, with over a dozen companies facing suspension or permanent bans. According to a report by threat intelligence group Natto Thoughts, these actions stem from concerns about collusive bidding during military contract auctions, rather than issues with product quality or technical shortcomings. The report details a three-tier system used by the People’s Liberation Army (PLA): a private warning list for early-stage concerns, a suspension list for confirmed but limited violations, and a public blacklist reserved for serious offenses.

One example is Beijing TopSec Network Security, an indirect subsidiary of TopSec Technologies Group. In 2024, the company was suspended from specific services for three years after being accused of collusive bidding on an Army contract, but investigators later expanded the suspension to cover all military branches. In January 2026, following a two-year probe, authorities imposed a lifetime ban on all military procurement, the maximum penalty available.

Venustech Group followed a similar trajectory, with its subsidiary, Beijing Venustech Information Security Technology, suspended from a regional military command in August 2024 and from all military bidding in February 2025. In April 2026, the sanctions escalated to include the parent company itself, though the action remains a suspension rather than a permanent ban.

Other firms named in the research include Qi An Xin’s Legendsec subsidiary, digital certificate provider BJCA, Kylinsec, Westone (CETC Cyber Security), and Huaru Technologies. These companies occupy a dual role in China’s security ecosystem, according to Eugenio Benincasa, a China-focused cybersecurity researcher at ETH Zurich. On the defensive side, they pioneered China’s firewall market, while Qi An Xin has built a strong position in threat intelligence.

Benincasa clarified that none of the firms have been publicly linked to directly operating offensive hacking groups, but they have long-standing ties to the PLA and China’s security services, supporting military cyber operations through training and service provision, and, in Qi An Xin’s case, through investments in companies tied to known Chinese APT activity. The crackdown is part of a broader shift in PLA procurement oversight, including 2024 regulations on competitive bidding for military equipment and the growing enforcement role of China’s newly formed Cyberspace Force, which the report credits with six of the reviewed violation cases. Commercial pressures, such as softening security budgets and a market pivot toward AI- and data-driven demand, are also contributing factors.

Read the full article at SecurityWeek