DOJ charges two alleged members of China's state sponsored hacking unit APT10 with stealing data from at least 45 US tech companies and government agencies
we've come a long way since that botched 2014 press release on the Sony Hack https://twitter.com/... Elsa B. Kania / @ebkania : According to the indictment, APT10 has targeted 45 U.S. companies and government agencies, along with firms in more than a dozen nations, targeting sectors that have included finance, telecommunications, biotechnology, automotive, health care, and mining. https://www.bloomberg.com/... Marise Payne / @marisepayne : Australia joins with other international partners in expressing serious concern about a global campaign of cyber-enabled commercial intellectual property theft by APT10, acting on behalf of the Chinese Ministry of State Security https://foreignminister.gov.au/ ... Tyler Q. Houlton / @spoxdhs : In order to provide support for anyone who believes they may have been affected, @DHSgov established http://www.us-cert.gov/china , a one-stop-shop of resources and tools to inform and assist network defenders charged with protecting networks and data from these malicious activities. Ncsc Uk / @ncsc : We've assessed with the highest level of probability that the group widely known as APT10 is responsible for a sustained cyber campaign focused on large-scale service providers https://www.ncsc.gov.uk/... Michael Pillsbury / @mikepillsbury : China's goal, simply put, is to replace the U.S. as the world's leading superpower, and they're using illegal methods to get there," said FBI Director Christopher A. Wray http://www.washingtonpost.com/ ... Thomas Rid / @ridt : And VERY impressive to see that DoJ's APT10 indictment/attribution was orchestrated to happen simultaneously with a major UK high-confidence intelligence assessment — the first time Britain is publicly calling out China for digital espionage https://www.gov.uk/... pic.twitter.com/syjFHs2svJ John Bolton / @ambjohnbolton : Today, @TheJusticeDept indicted hackers who conduct unprecedented intellectual property theft on behalf of the Chinese Ministry of State Security. We stand w/ allies & partners in calling out this shameful violation of the 2015 US-China Cyber Commitments. http://www.justice.gov/... @foreignoffice : Together with our allies, we are holding elements of the Chinese government responsible for an extensive cyber campaign targeting intellectual property and sensitive commercial data in Europe, Asia and the US. http://www.gov.uk/... http://twitter.com/... David Dowling / @david_s_dowling : Australian Signals Directorate released more information about Operation Cloud Hopper (APT10) by the Chinese Ministry of State Security targeting MSPs and MSP customers in Australia and globally. https://lnkd.in/fscuwfw @joshuawongcf : U. S. charges Chinese hackers in alleged theft of vast trove of confidential data in 12 countries http://www.washingtonpost.com/ ... @x0rz : Two members of the #APT10 group indicted by the FBI, they were acting on behalf of the Tianjin State Security Bureau (), part of the Ministry of State Security (MSS) in China http://www.justice.gov/... #cyber #espionage #china Thomas Rid / @ridt : Apparently the answer is yes, Germany will join its allies and call out China, according to @nakashimae, thanks @shashj http://www.washingtonpost.com/ ... http://twitter.com/... Gregg Housh / @gregghoush : “China will find it difficult to pretend that it is not responsible for this action,” Deputy Attorney General Rod Rosenstein said at a press conference Thursday morning. Justice Department charges Chinese nationals in ‘extensive’ global hacking campaign http://www.cnbc.com/... Eamon Javers / @eamonjavers : WH is not waiving us off this scoop from the WPost now. Expect more details from the DOJ this morning: “U.S. and more than a dozen allies to condemn China for economic espionage” - The Washington Post http://www.washingtonpost.com/ ... Eric Geller / @ericgeller : The Washington Post previews today's China announcements along the lines of what I have heard: Coordinated international condemnation of Beijing, with MSS hacker charges and a formal statement about the 2015 agreement. http://www.washingtonpost.com/ ... http://twitter.com/...
Context & Ripple Effects
This indictment lands just seven weeks after the DOJ charged ten Chinese nationals for hacking US and European companies between 2010 and 2015 (that earlier IP-theft case) — but the APT10 case escalates the playbook: for the first time in this sequence, multiple allied governments, including Australia via the Australian Signals Directorate's Operation Cloud Hopper disclosures, publicly attribute the campaign to China's Ministry of State Security rather than leaving Washington to name names alone.
What makes the targeting notable is the vector: per the Cloud Hopper material, APT10 reached its victims by compromising managed service providers, meaning one intrusion could cascade into dozens of downstream corporate customers across finance, telecom, biotech, automotive, health care, and mining.
First-order effects
- Two alleged APT10 members now face US criminal charges on behalf of at least 45 breached US tech companies and government agencies, with the FBI and DOJ converting intelligence findings into named defendants tied to the MSS's Tianjin bureau.
- DHS stands up a US-CERT China resource so network defenders at the affected firms can hunt for the specific tools and infrastructure used in the campaign.
Second-order effects
- Managed service providers become the contested ground: their customers must now audit whether their MSP was the entry point, pressuring providers to prove segmentation and security or lose trust-based business.
- Allied governments' joint attribution raises the diplomatic cost for Beijing, pushing cyber theft onto the agenda of trade and security talks with Britain, Germany, and Australia alongside Washington.
Third-order effects
- Public indictment becomes the standing US response to state-sponsored hacking rather than a one-off — a pattern that repeats in the 2020 charges over a decade-long spree including vaccine secrets ([[a:955960]]) and again in 2025 when twelve Chinese nationals, including PRC staff, were charged over espionage against Treasury and other agencies ([[a:883205]]).
- If the pattern holds, attribution itself hardens into policy infrastructure: shared Five Eyes-style disclosure, defender-facing resources like the US-CERT page, and sanctions or visa consequences that follow each named unit.
The trend: The US and its allies are shifting from quiet diplomatic protest to routine, coordinated public indictment of state-sponsored hacking units as the primary tool of cyber deterrence.