/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

DOJ unseals charges against four Chinese nationals, believed to be part of China-backed APT 40 hacking group; charging docs focus on activity from 2011 to 2018

The US Department of Justice has indicted four Chinese nationals today for hacking companies, government agencies …

The Record Catalin Cimpanu

Context & Ripple Effects

The charges add APT40 to a DOJ record that already included alleged members of China's state-sponsored APT10 unit accused of stealing data from US technology companies and government agencies. In 2020, the department also charged five Chinese citizens over alleged intrusions targeting 100 companies and institutions across the US and elsewhere.

The case reaches back to activity from 2011 through 2018, showing the department is continuing to turn older alleged intrusion campaigns into public criminal cases rather than treating each indictment as a one-off event.

First-order effects

  • Four Chinese nationals face unsealed US charges tied to alleged APT40 hacking activity, formally extending DOJ's public allegations to that group.
  • DOJ gains another public attribution case against alleged China-backed hacking actors, alongside its earlier APT10 and broader 2020 charging actions.

Second-order effects

  • Organizations that match the alleged target profile in the earlier DOJ cases—companies and government agencies—have further reason to treat China-linked intrusion allegations as an enduring exposure rather than an isolated breach category.
  • The new case reinforces the evidentiary and attribution record behind US enforcement messaging, even where the alleged activity predates the charging announcement by years.

Third-order effects

  • A sequence of cases against alleged APT10, Equifax-related intelligence officers, and now APT40 points to criminal indictments becoming a recurring instrument for publicly attributing alleged state-linked cyber activity.
  • If this pattern persists, the divide between criminal enforcement and cyber deterrence narrows: long-running intrusion investigations become part of the US government's sustained response to alleged foreign espionage operations.

The trend: The DOJ is building a cumulative public-attribution strategy through successive criminal cases alleging China-linked cyber espionage across multiple groups and periods.

Discussion

  • @nakashimae Ellen Nakashima on x
    NEW: U.S., allies accuse China of hacking Microsoft & condoning other attacks. It's the largest condemnation of China's cyber aggressions to date. But it falls short of punishment, which some analysts say is necessary for deterrence. @John_hudson & me https://www.washingtonpost.c…
  • @billbirtles Bill Birtles on x
    Within hours of the Biden admin & allies alleging widespread hacking & commercial theft backed by China's MSS, a Chinese state media outlet (no prizes for guessing which one) published unusually detailed claims of 3 US hacking attacks on China last year: https://www.abc.net.au/..…
  • @shanvav Shannon Vavra on x
    A senior admin official says in addition to the Microsoft Exchange Server hacking, U.S. & allies plan to lay out how China's MSS works thru criminal hackers: “MSS is using, knowledgeably, criminal contract hackers to conduct unsanctioned cyber operations globally,” https://twitte…
  • @dojnatsec @dojnatsec on x
    Four Chinese Nationals Working with the Ministry of State Security Charged with Global Computer Intrusion Campaign Targeting Intellectual Property and Confidential Business Information, Including Infectious Disease Research https://www.justice.gov/... https://twitter.com/...
  • @keithjkrach Keith Krach on x
    How blatant can you get? We need to wake up. @SecBlinken: China's Ministry of State Security “has fostered an ecosystem of criminal contract hackers who carry out both state-sponsored activities and cybercrime for their own financial gain.” https://www.nytimes.com/...
  • @datadrivenmd Jorge A. Caballero on x
    Sen. Blumenthal is right— it's not clear what the end-game is for this particular move. There's *a lot* going on in cyber, and we can't deal in subtleties if we hope to effect change https://twitter.com/...
  • @kenroth Kenneth Roth on x
    “The United States accused China for the first time of paying criminal groups to conduct large-scale hackings, including ransomware attacks to extort companies for millions of dollars, according to a statement from the White House.” https://www.nytimes.com/... https://twitter.com…
  • @quicktake Bloomberg Quicktake on x
    Biden on China's involvement in the Microsoft Exchange hack: “The Chinese government, not unlike the Russian government, is not doing this themselves but are protecting those that are doing it” https://www.bloomberg.com/... https://twitter.com/...
  • @senblumenthal Richard Blumenthal on x
    Waving a fist inside a heavily padded glove will not deter ruthless & relentless continuing cyber-attacks by China, Russia & others. Attributing blame is a good step, but only if followed by action that makes attackers pay a real price, proportionate to their destructive impact. …
  • @cisagov @cisagov on x
    #APT40 has targeted government, universities, & a wide-range of industries in the U.S. & globally. With @FBI, we published #TTPs & indicators of compromise (#IOCs) to help organizations identify & remediate APT40 intrusions & established footholds: https://us-cert.cisa.gov/... (3…
  • @realpnavarro Peter Navarro on x
    The latest production from the trans-national organization known as the Chinese Communist Party. It is time for the world to sever the cord with China. CCP will continue to do what it has been doing. U.S., allies accuse China of hacking Microsoft https://www.washingtonpost.com/ .…
  • @nicoleperlroth Nicole Perlroth on x
    A decade ago, China was considered the top cyber threat. Russia was more sophisticated but China more urgent because of the sheer volume of attacks on American interests. Now China has professionalized its hacking operations to a disturbing degree. https://www.nytimes.com/...
  • @nicoleperlroth Nicole Perlroth on x
    Calling it out as a global alliance is critical and the attribution to MSS is probably the quickest level of specificity I've seen, but it hasn't been a deterrent. If history's any guide, China will only continue to professionalize it's cyber ops and push them further underground
  • @nytimesbusiness @nytimesbusiness on x
    China has reorganized its hacking operations to become fluent in stealthy, decentralized digital assaults of American companies and interests around the world. https://www.nytimes.com/...
  • @dnvolz Dustin Volz on x
    Some former officials are perplexed by the difference between the Biden administration's hardline retaliation for Russia's SolarWinds attack and its response to China's Microsoft Exchange Server hack, which lacked punitive measures. https://www.wsj.com/... https://twitter.com/...
  • @dalperovitch Dmitri Alperovitch on x
    Major action from the White House and an impressive coalition of allies calling out China for its reckless and dangerous behavior with the unconstrained and untargeted Exchange hacks 1/ https://twitter.com/...
  • @dod_policy Colin Kahl on x
    The @DeptofDefense continues to be concerned about the PRC's pattern of irresponsible behavior in the cyber domain. We worked closely with the interagency, Allies & partners to determine attribution for the Microsoft Exchange Server compromise. https://www.whitehouse.gov/...
  • @tom_fowdy Tom Fowdy on x
    Don't fall for the mainstream media hysteria that this is a show of unity between the EU and US. The EU statement is very soft and purposefully avoids calling out the Chinese government only by levelling the accusation to “from the territory of China”. https://www.consilium.europ…
  • @tom_fowdy Tom Fowdy on x
    Biden's China policy is becoming more and more unhinged by the day. https://twitter.com/...