/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Sources: state-sponsored Chinese hackers breached networks of HPE and IBM, then used access to hack into their clients' computers in campaign called Cloudhopper

- Hackers working on behalf of China's Ministry of State Security breached the networks of Hewlett Packard Enterprise Co and IBM

Reuters

Context & Ripple Effects

This December 2018 report was the first to name Hewlett Packard Enterprise and IBM as breached in Cloudhopper, attributing the campaign to hackers working for China's Ministry of State Security. What made it notable was the method: rather than attacking end targets directly, the intruders compromised the IT providers themselves and rode trusted network access downstream into client systems.

Subsequent reporting confirmed and expanded the picture: APT10's campaign ultimately touched eight IT service providers including HPE and IBM, and by year-end 2019 the WSJ reported Cloud Hopper was far larger than first known, reaching more than a dozen cloud providers and possibly remaining active as late as November 2019. The story sits alongside Symantec's earlier finding of a China-based espionage campaign against satellite and defense firms, part of a sustained run of state-backed intrusions.

First-order effects

  • HPE and IBM face immediate remediation and disclosure burdens: their own networks were the staging ground, so every client connected through them is a potential victim requiring notification and forensics.
  • Clients of these managed service providers lose the assumption that hiring a major IT firm isolates them from nation-state targeting — the provider relationship itself became the attack vector.

Second-order effects

  • Other managed service and cloud providers are forced to treat their own infrastructure as high-value espionage targets, hardening privileged-access controls because one breach propagates across an entire client base.
  • Security vendors and enterprise buyers shift scrutiny toward supply-chain compromise patterns, following the trail Symantec documented against defense and satellite firms earlier in 2018.

Third-order effects

  • If the pattern holds, state espionage structurally favors compromising shared IT intermediaries over individual targets, since one provider foothold yields many victims at once — a dynamic later echoed when Microsoft reported Chinese state-sponsored hackers inside US critical infrastructure organizations (Microsoft's critical-infrastructure warning).
  • The scale revealed by later reporting suggests attribution and scope lag badly behind intrusion activity, pressuring governments toward mandatory breach disclosure and security baselines for service providers.

The trend: Nation-state espionage is shifting from direct breaches of end targets to compromising shared IT and cloud intermediaries, where a single intrusion scales across dozens of downstream victims.