China military unit 'behind prolific hacking'

The BBC's John Sudworth was detained while filming the reported hub of the hacking operation

Related Stories

A secretive branch of China's military is probably one of the world's "most prolific cyber espionage groups", a US cyber security firm has said.

Mandiant said Unit 61398 was believed to have "systematically stolen hundreds of terabytes of data" from at least 141 organisations around the world.

The White House said it has taken its concerns about cyber-theft to the highest levels of China's government.

China has denied hacking and questioned Mandiant's report.

"Hacking attacks are transnational and anonymous," said foreign ministry spokesman Hong Lei.

"Determining their origins are extremely difficult. We don't know how the evidence in this so-called report can be tenable.

Mr Hong added that Beijing "firmly opposes hacking", has taken steps to prevent it and is also a victim of cyber attacks.

In an indication of the military sensitivity around the Shanghai site pinpointed by the report as home to the hacking group, the BBC's John Sudworth and his camera crew were briefly detained by soldiers when they went to film the facility. They were only released once they had handed over their footage.

Satellite image showing the office building in Shanghai suspected of being the headquarters of the Chinese hackers
'Extensive campaign'

In its unusually detailed report, US-based computer security company Mandiant said it had investigated hundreds of data breaches since 2004, most of which it attributed to what it termed "Advanced Persistent Threat" actors.

Analysis

The scale of the Chinese hacking alleged by the computer security firm Mandiant is striking. Until now the bulk of this hacking has been a digital version of old-fashioned industrial espionage - stealing designs and company secrets.

But there is a more sinister side to this activity as well. Chinese hackers are alleged to have a growing interest in gaining access to key parts of the US infrastructure - gas lines, power grids and waterworks. President Barack Obama himself warned during his recent State of the Union address that the nature of the cyber threat was changing.

Gaining access to critical systems is the key. Once inside the digital perimeter - especially if the intrusion is not identified, there is the possibility of causing real physical damage to the infrastructure that the computers control.

The details it had uncovered, it said, "convince us that the groups conducting these activities are based primarily in China and that the Chinese government is aware of them".

The most prolific of these actors is APT1, which Mandiant says is "a single organisation of operators that has conducted a cyber espionage campaign against a broad range of victims since at least 2006".

"From our observations, it is one of the most prolific cyber espionage groups in terms of the sheer quantity of information stolen," it said, adding that it was "likely government-sponsored and one of the most persistent of China's cyber threat actors".

"We believe that APT1 is able to wage such a long-running and extensive cyber espionage campaign in large part because it receives direct government support," said Mandiant.

The firm said it had traced the hacking activities of APT1 to the site of 12-storey building in the Pudong area of Shanghai. It said that Unit 61398 of the People's Liberation Army "is also located in precisely the same area" and that the actors had similar "missions, capabilities and resources".

Among the findings about APT1 in the report were that it:

  • is staffed by hundreds, possibly thousands, of proficient English speakers with advanced computer security and networking skills
  • has hacked into 141 companies across 20 industries, 87% based in English-speaking countries, and is able to steal from dozens of networks simultaneously
  • has stolen hundreds of terabytes of information including blueprints, business plans, pricing documents, user credentials, emails and contact lists
  • stayed inside hacked networks for an average of 356 days, with the longest lasting 1,764 days
  • targeted industries identified by China as strategically important under its Five Year Plan for economic growth
'Groundless'

Unit 61398 has for some time been suspected by the US of being central to China's cyber espionage programme, the New York Times reports.

Table showing the industries most often targeted by the hackers

Mandiant admitted there could be one alternative explanation for its findings: that "a secret, resourced organisation full of mainland Chinese speakers with direct access to Shanghai-based telecommunications infrastructure is engaged in a multi-year, enterprise scale computer espionage campaign right outside of Unit 61398's gates, performing tasks similar to Unit 61398's known mission".

Several governments, foreign companies and organisations have said in the past they suspect China of carrying out extensive cyber espionage over periods of several years.

On Tuesday, White House spokesman Jay Carney told reporters that the Obama administration had "repeatedly raised our concerns at the highest levels about cyber theft with senior Chinese officials including in the military and we will continue to do so".

Mr Carney declined to comment specifically on the contents of the report.

Last month, the New York Times said its systems had been infiltrated over a period of four months, after it wrote a report on the alleged wealth of China's outgoing Premier Wen Jiabao.

Mandiant, which the paper hired to investigate, traced the hack to China. However, the paper said its breach had been attributed to a different group. The Wall Street Journal also reported a China-based hack.

At the time, China's foreign ministry dismissed the New York Times accusations as "groundless", saying that to "conclude without hard evidence that China participated in such hacking attacks is totally irresponsible".

More on This Story

Related Stories

The BBC is not responsible for the content of external Internet sites

More China stories

RSS

Features & Analysis

Elsewhere on the BBC

  • Van DammeA-list adverts

    BBC Autos takes a look at some of the most curious and courageous link-ups in car-advert history

Programmes

  • Bitcoin logoClick Watch

    The developer behind the new Bitcoin tech on the fears it will hide criminal activity

BBC © 2014 The BBC is not responsible for the content of external sites. Read more.

This page is best viewed in an up-to-date web browser with style sheets (CSS) enabled. While you will be able to view the content of this page in your current browser, you will not be able to get the full visual experience. Please consider upgrading your browser software or enabling style sheets (CSS) if you are able to do so.