Sources: state-sponsored Chinese hackers breached networks of HPE and IBM, then used access to hack into their clients' computers in campaign called Cloudhopper
- Hackers working on behalf of China's Ministry of State Security breached the networks of Hewlett Packard Enterprise Co and IBM …
Context & Ripple Effects
This December 2018 report was the first to name Hewlett Packard Enterprise and IBM as breached in Cloudhopper, attributing the campaign to hackers working for China's Ministry of State Security. What made it notable was the method: rather than attacking end targets directly, the intruders compromised the IT providers themselves and rode trusted network access downstream into client systems.
Subsequent reporting confirmed and expanded the picture: APT10's campaign ultimately touched eight IT service providers including HPE and IBM, and by year-end 2019 the WSJ reported Cloud Hopper was far larger than first known, reaching more than a dozen cloud providers and possibly remaining active as late as November 2019. The story sits alongside Symantec's earlier finding of a China-based espionage campaign against satellite and defense firms, part of a sustained run of state-backed intrusions.
First-order effects
- HPE and IBM face immediate remediation and disclosure burdens: their own networks were the staging ground, so every client connected through them is a potential victim requiring notification and forensics.
- Clients of these managed service providers lose the assumption that hiring a major IT firm isolates them from nation-state targeting — the provider relationship itself became the attack vector.
Second-order effects
- Other managed service and cloud providers are forced to treat their own infrastructure as high-value espionage targets, hardening privileged-access controls because one breach propagates across an entire client base.
- Security vendors and enterprise buyers shift scrutiny toward supply-chain compromise patterns, following the trail Symantec documented against defense and satellite firms earlier in 2018.
Third-order effects
- If the pattern holds, state espionage structurally favors compromising shared IT intermediaries over individual targets, since one provider foothold yields many victims at once — a dynamic later echoed when Microsoft reported Chinese state-sponsored hackers inside US critical infrastructure organizations (Microsoft's critical-infrastructure warning).
- The scale revealed by later reporting suggests attribution and scope lag badly behind intrusion activity, pressuring governments toward mandatory breach disclosure and security baselines for service providers.
The trend: Nation-state espionage is shifting from direct breaches of end targets to compromising shared IT and cloud intermediaries, where a single intrusion scales across dozens of downstream victims.