Leaked files detail Chinese state-linked hacking groups carrying out large-scale, systematic cyber intrusions against governments, companies, and infrastructure
A trove of leaked documents from a Chinese state-linked hacking group shows that Beijing's intelligence and military groups …
Washington Post
Context & Ripple Effects
The leak adds operational detail to a long-running record of reporting on Chinese state-linked cyber activity, from research connecting campaigns to military personnel to reported compromises of US critical infrastructure. It matters because the alleged targets span public institutions, businesses and infrastructure rather than a single sector.
Organizations named or implicated by the leaked material face an immediate need to assess exposure, rotate potentially compromised access and compare the files with existing incident data.
The disclosures increase scrutiny of the state-linked groups and of Beijing's intelligence and military cyber operations, while giving defenders potentially useful detail on targeting and methods.
Second-order effects
Government agencies, infrastructure operators and corporate security teams are likely to share and operationalize the leaked indicators, raising the cost of maintaining access across affected networks.
IT and managed-service providers face added pressure to demonstrate that privileged customer access is segmented and monitored, given the documented value of provider compromises as a route into client systems.
Third-order effects
If repeated disclosures continue to show broad, state-linked targeting, cyber resilience for infrastructure and major suppliers will be treated less as a company-level security issue and more as a national-security dependency.
The pattern points toward a more persistent contest over intelligence access in shared digital infrastructure, where attribution and defensive coordination matter as much as perimeter security.
The trend: This is one data point in the continued expansion of state-linked cyberespionage from discrete targets toward the digital infrastructure and service relationships that connect many targets at once.
Interesting Thread on a massive dump from a Chinese 🇨🇳 Ministry of Public Security (MPS) private industry contractor called iSoon (aka Anxun) Leak contains: - Spyware - Espionage Ops - “Twitter Monitoring Platform” - And a lot more 🔥 This is a crazy NTC Vulkan-level leak ⚠️
🇨🇳 I-SOON leak: files 44 and 46 contain tables enumerating data samples from targets — telcos, universities, government departments such as foreign ministries, hospitals, etc — in various countries including Afghanistan, India, Indonesia, Thailand, Myanmar, Vietnam, Malaysia,... …
Service offerings of 🇨🇳 I-SOON (安洵信息) include penetration into specific targets and intelligence collection targeting countries such as India and Nepal, among others (file 59). [image]
2/The files pull back the curtains on Chinese hacking operations, showing how Chinese police rely on companies such as this contractor, I-Soon, to surveil dissidents overseas and squash anti-government sentiment even on non-Chinese platforms like X, formerly known as Twitter. [im…
3/A few days ago, a post by this threat intelligence researcher pointing to last week's dump went viral, as it dug into the documents and pointed out all the hacking tools and hacked data it described inside. https://x.com/...
“spreadsheet showed that the firm had a sample of 459GB of road-mapping data from Taiwan...could prove useful to the Chinese military in the event of an invasion of Taiwan...other targets were 10 Thai gov agencies, including...foreign ministry, intelligence agency and senate”
Last week a Chinese hacker company serving CCP's needs was exposed on GitHub: I-s00n(安洵). The leaked documents show that I-s00n developed sophisticated hacking tools and hacked into many countries' systems to steal whatever CCP wanted. More info here https://github.com/... [image…
“But the iSoon files contain complaints from disgruntled employees over poor pay and workload. Many hackers work for less than $1,000 a month, surprisingly low pay even in China...” Vast Chinese international hacking effort - The Washington Post https://www.washingtonpost.com/ ..…
Fascinating, unprecedented, look here inside files of a firm (iSoon/安洵) that does Chinese state hacking, targeting almost two dozen foreign governments w/ @cdcshepherd https://www.washingtonpost.com/ ...
The more I pour through the isoon leaks, the more it dawns upon me how good value espionage this is for China. The rates they earn are so low, one wonders what happens when the contract is up. Hello criminality as a gun for hire?
A trove of leaked documents from a Chinese state-linked hacking group shows that Beijing's intelligence and military groups are carrying out large-scale, systematic cyber intrusions against foreign governments, companies and infrastructure — exploiting what the hackers claim are.…
Great story. Github repository of Chinese firm iSoon (aka Auxun) reveals hacking ops its conducted for Chinese gov and others - “lists targets...summaries of sample data amounts extracted and details on whether the hackers obtained full or partial control” https://www.washingtonp…
1/A few days ago, files from a contractor for Chinese police quietly dumped online went viral. But though analysts thought the files authentic, they weren't 100% confident. Now, after a visit to the company's offices, I can confirm the leak is real: https://apnews.com/...
“ISoon's product manuals also advertise a $25K service for a ‘remote access’ control system to obtain Apple iOS smartphone data from a target, including ‘basic mobile phone information, GPS positioning, mobile phone contacts’ and ‘environment recording.’” https://www.washingtonpo…
Massive cache of leaked files linked to top Chinese police agency shows Beijing spying on foreigners, unmasking concealed identities on Twitter, and spying on Uyghurs abroad, incl. claimed access to hacked overseas airline, cellular and government data. https://apnews.com/...