5 Chinese PLA officials accused of cyber espionage on US companies

The United States has filed criminal charges against five Chinese military PLA officials for cyber espionage and hacking against several US companies.

The United States early this week charged five Chinese military PLA officers and accused them of hacking into computers of American companies. US authorities accused the China’s People’s Liberation Army officers of hacking into US companies in the energy sector to steal trade secrets and intellectual property.
DoJ has issued a press release which revealed the names of the five hackers, the victim companies and the time period of the cyber attacks, following an abstract from the indictment:

Defendants :  Wang Dong, Sun Kailiang, Wen Xinyu, Huang Zhenyu, and Gu Chunhui, who were officers in Unit 61398 of the Third Department of the Chinese People’s Liberation Army (PLA).  The indictment alleges that Wang, Sun, and Wen, among others known and unknown to the grand jury, hacked or attempted to hack into U.S. entities named in the indictment, while Huang and Gu supported their conspiracy by, among other things, managing infrastructure (e.g., domain accounts) used for hacking.

Victims : Westinghouse Electric Co. (Westinghouse), U.S. subsidiaries of SolarWorld AG (SolarWorld), United States Steel Corp. (U.S. Steel), Allegheny Technologies Inc. (ATI), the United Steel, Paper and Forestry, Rubber, Manufacturing, Energy, Allied Industrial and Service Workers International Union (USW) and Alcoa Inc.

Time period : 2006-2014.

The FBI accused the PLA‘s official for hacking  and applied total 31 counts charges, for:

  • Conspiring to commit computer fraud and abuse
  • Accessing (or attempting to access) a protected computer without authorization to obtain information for the purpose of commercial advantage and private financial gain
  • Transmitting a program, information, code, or command with the intent to cause damage to protected computers
  • Aggravated identity theft
  • Economic espionage
  • Trade secret theft
“When a foreign nation uses military or intelligence resources and tools against an American executive or corporation to obtain trade secrets or sensitive business information for the benefit of its state-owned companies, we must say, ‘Enough is enough,'” U.S. Attorney General Eric Holder declared at a news conference.
The accompanying indictment states:

“From at least in or about 2006 up to and including at least in our about April 2014, members of the People’s Liberation Army (“PLA”), the military of the People’s Republic of China (“China”), conspired together and with each other to hack into the computers of commercial entities in the Western District of Pennsylvania and elsewhere in the United States.” 

The Chinese Government denied the charges, saying that this incident would damage the relationship between the two countries. Cyber espionage is a top national security concern for both governments,  top U.S. Intelligence officials released early 2014 a new Worldwide Threat Assessment Report during a Senate hearing, the document considers the effects of cyber campaigns conducted by foreign state-sponsored hackers as a serious threat for Homeland security.
The US authorities suspect hackers work for the PLA’s Unit 61398 based in Shanghai, according investigation the hackers have stolen trade secrets and also sensitive data related to nuclear power plant design and a solar panel company’s cost and pricing data.

Federal prosecutors suspect the list of targeted companies is very long and includes Alcoa Inc, Allegheny Technologies Inc, United States Steel Corp, Toshiba Corp unit Westinghouse Electric Co, the U.S. subsidiaries of SolarWorld AG, and a steel workers’ union.According US Officials losses to the companies were “significant.”

“The victims had all filed unfair trade claims against their Chinese rivals, helping Washington draw a link between the alleged hacking activity and its impact on international business.” reports Reuters.

The five PLA Chinese officials are considered by US authorities, international fugitives, the indictment is a clear message to other governments, the US doesn’t want to accept further cyber espionage on its companies, curious if we consider recent revelation based on Snowden documents on US cyber espionage activities against foreign countries.
Be aware as reported in the text of the indictment, “An indictment is merely an accusation and a defendant is presumed innocent unless proven guilty in a court of law.“.

Pierluigi Paganini

(Security Affairs –  Chinese PLA officials, hacking)  

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Google fixes fifth actively exploited Chrome zero-day this year

Since the start of the year, Google released an update to fix the fifth actively…

15 hours ago

Russia-linked APT28 targets government Polish institutions

CERT Polska warns of a large-scale malware campaign against Polish government institutions conducted by Russia-linked…

15 hours ago

Citrix warns customers to update PuTTY version installed on their XenCenter system manually

Citrix urges customers to manually address a PuTTY SSH client flaw that could allow attackers…

21 hours ago

Dell discloses data breach impacting millions of customers

Dell disclosed a security breach that exposed millions of customers' names and physical mailing addresses.…

1 day ago

Mirai botnet also spreads through the exploitation of Ivanti Connect Secure bugs

Threat actors exploit recently disclosed Ivanti Connect Secure (ICS) vulnerabilities to deploy the Mirai botnet.…

2 days ago

Zscaler is investigating data breach claims

Cybersecurity firm Zscaler is investigating claims of a data breach after hackers offered access to…

2 days ago

This website uses cookies.