It is probably the first time that Chinese authorities have arrested hackers in China following a request of the US Government.
The hackers were arrested on charges of cyber espionage on U.S. firms, the criminals have stolen sensitive data from the victims to resell them to Chinese companies.
At the moment, there is no publicly available information related to the identity of the hackers and what punishments they face.
“The arrests come amid signs of a potential change in the power balance between the U.S. and Chinese governments on commercial cyber espionage, one of the most fraught issues between the two countries. ” states the Washington Post.
The hackers were included in a list of the hackers, drawn up by the US intelligence and law enforcement agencies, the United States want to arrest.
“We need to know that you’re serious,” was the way one individual familiar with the matter described the message. “So we gave them a list, and we said, ‘Look, here’s these guys. Round them up.’”
China and US agreed to stop any mutual hacking activity, including mutual corporate espionage and US authorities hope that the arrests are a first step of the announced cooperation.
Which is the opinion of the experts?
“I bet they nabbed ‘contractors,’ not PLA/MSS*,” said FireEye/Mandiant strategist Richard Bejtlich. “If CN gov arrested [PLA Unit] 61398 members, CN gov will likely claim they were rogue actors. Fits w/anti-corruption campaign, but bad for PLA morale.”
Let’s see what will happen in the next months.
(Security Affairs – China, hacking)
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best…
Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…
A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…
A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…
Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code…
This website uses cookies.