Chinese spies breached hundreds of public, private networks, security firm says

Advertisement

Advertise with us

Suspected state-backed Chinese hackers used a security hole in a popular email security appliance to break into the networks of hundreds of public and private sector organizations globally, nearly a third of them government agencies including foreign ministries, the cybersecurity firm Mandiant said Thursday.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 15/06/2023 (1183 days ago), so information in it may no longer be current.

Suspected state-backed Chinese hackers used a security hole in a popular email security appliance to break into the networks of hundreds of public and private sector organizations globally, nearly a third of them government agencies including foreign ministries, the cybersecurity firm Mandiant said Thursday.

“This is the broadest cyber espionage campaign known to be conducted by a China-nexus threat actor since the mass exploitation of Microsoft Exchange in early 2021,” Charles Carmakal, Mandiant’s chief technical officer, said in a emailed statement. That hack compromised tens of thousands of computers globally.

In a blog post Thursday, Google-owned Mandiant expressed “high confidence” that the group exploiting a software vulnerability in Barracuda Networks’ Email Security Gateway was engaged in “espionage activity in support of the People’s Republic of China.” It said the activivity began as early as October.

FILE - The American and Chinese flags wave at Genting Snow Park ahead of the 2022 Winter Olympics, in Zhangjiakou, China, on Feb. 2, 2022. Hackers linked to China were likely behind the exploitation of a software security hole in cybersecurity firm Barracuda Networks’ email security feature that affected public and private organizations globally, according to an investigation by security firm Mandiant. (AP Photo/Kiichiro Sato, File)
FILE - The American and Chinese flags wave at Genting Snow Park ahead of the 2022 Winter Olympics, in Zhangjiakou, China, on Feb. 2, 2022. Hackers linked to China were likely behind the exploitation of a software security hole in cybersecurity firm Barracuda Networks’ email security feature that affected public and private organizations globally, according to an investigation by security firm Mandiant. (AP Photo/Kiichiro Sato, File)

The hackers sent emails containing malicious file attachments to gain access to targeted organizations’ devices and data, Mandiant said. Of those organizations, 55% were from the Americas, 22% from Asia Pacific and 24% from Europe, the Middle East and Africa and they included foreign ministries in Southeast Asia, foreign trade offices and academic organizations in Taiwan and Hong Kong. the company said.

Mandiant said the majority impact in the Americas may partially reflect the geography of Barracuda’s customer base.

Barracuda announced on June 6 that some of its its email security appliances had been hacked as early as October, giving the intruders a back door into compromised networks. The hack was so severe the California company recommended fully replacing the appliances.

After discovering it in mid-May, Barracuda released containment and remediation patches but the hacking group, which Mandiant identifies as UNC4841, altered their malware to try to maintain access, Mandiant said. The group then “countered with high frequency operations targeting a number of victims located in at least 16 different countries.”

Word of the breach as U.S. Secretary of State Antony Blinken departs for China this weekend as part of the Biden administration’s push to repair deteriorating ties between Washington and Beijing.

His visit had initially been planned for early this year but was postponed indefinitely after the discovery and shootdown of what the U.S. said was a Chinese spy balloon over the United States.

Mandiant said the targeting at both the organizational and individual account levels, focused on issues that are high policy priorities for China, particularly in the Asia Pacific region. It said the hackers searched for email accounts of people working for governments of political or strategic interest to China at the time they were participating in diplomatic meetings with other countries.

In a emailed statement Thursday, Barracuda said about 5% of its active Email Security Gateway appliances worldwide showed evidence of potential compromise. It said it was providing replacement appliances to affected customers at no cost.

The U.S. government has accused Beijing of being its principal cyberespionage threat, with state-backed Chinese hackers stealing data from both the private and public sector.

In terms of raw intelligence affecting the U.S., China’s largest electronic infiltrations have targeted OPM, Anthem, Equifax and Marriott.

Earlier this year, Microsoft said state-backed Chinese hackers have been targeting U.S. critical infrastructure and could be laying the technical groundwork for the potential disruption of critical communications between the U.S. and Asia during future crises.

China says the U.S. also engages in cyberespionage against it, hacking into computers of its universities and companies.

——

AP Business Writer Zen Soo contributed from Hong Kong.

Report Error Submit a Tip

More Stories

Flash, bang … oops: police raid leads to lawsuit

Erik Pindera 4 minute read Preview

Flash, bang … oops: police raid leads to lawsuit

Erik Pindera 4 minute read 6:00 AM CDT

A couple suing the city allege Winnipeg Police Service officers trying to execute a search warrant at their condominium complex rappelled down the side of the building, broke in their glass patio door and fired off a stun grenade before realizing they were in the wrong unit.

Saeid Ghavami and Shahla Shojaei, a married couple who are academics and scientific researchers at the University of Manitoba, filed the lawsuit in Court of King’s Bench last month over the Jan. 31, 2025 incident.

The claim names the City of Winnipeg and several officers involved in the operation, whose identities are, at this point, unknown to the couple, and are referred to as “John Does.”

Officers were attempting to execute the warrant on the third floor of the eight-storey Pembina Highway building, the court filing says. The couple lives on the fourth floor.

Read
6:00 AM CDT

All quiet on the Hellebuyck front

Mike McIntyre 8 minute read Preview

All quiet on the Hellebuyck front

Mike McIntyre 8 minute read Yesterday at 4:58 PM CDT

Pull up a chair, folks, as we address the elephant in the room. Or, to be more precise, the decorated goaltender who is not in the room. Or on the ice. Or even in the city.

Not surprisingly, the Connor Hellebuyck situation took centre stage Tuesday as members of the Winnipeg Jets held their first media session following an informal, pre-training camp skate.

“We’re definitely going to get asked about it. That’s no chirp to anybody. I think that’s just the reality of the situation,” admitted veteran defenceman Dylan DeMelo, who took part in an hour-long practice at Hockey For All Centre that involved nearly every member of the organization.

With one very notable exception, of course.

Read
Yesterday at 4:58 PM CDT

South Winnipeg neighbourhood will be first to go geothermal

Chris Kitching 4 minute read Preview

South Winnipeg neighbourhood will be first to go geothermal

Chris Kitching 4 minute read Updated: 7:28 PM CDT

A new neighbourhood in south Winnipeg will be Manitoba’s first to use a shared, large-scale geothermal system to heat and cool hundreds of homes over coming decades.

The province is giving up to $4 million to the developers of Southwood Circle, just north of the University of Manitoba’s Fort Garry campus, for a district geothermal system as part of the NDP’s goal to reach net-zero greenhouse gas emissions by 2050.

“It means a whole neighbourhood can tap into geothermal, which means low-carbon heating and cooling for at least 1,000 homes,” Premier Wab Kinew said at a news conference Wednesday.

Geothermal systems, equipped with pumps and pipes, use underground temperatures to heat and cool one or more buildings. Proponents point to long-term energy and cost savings compared with conventional heating and cooling systems.

Read
Updated: 7:28 PM CDT

Council to consider moving ahead with final phase of sewage plant upgrade before securing expected federal cash

Joyanne Pursaga 5 minute read Preview

Council to consider moving ahead with final phase of sewage plant upgrade before securing expected federal cash

Joyanne Pursaga 5 minute read 6:00 PM CDT

City council will consider approving $115 million toward the final phase of the North End sewage treatment plant upgrade, while civic staff warn sewer rates would soar $200 higher per year if more federal funding isn’t provided.

However, several politicians say a response from Ottawa to the city’s request for more money is expected soon.

A water and waste report asks council to waive a condition that the city finalize funding agreements with the provincial and federal governments for the mega-project before awarding the money for a contractor to complete the $115-million development phase agreement for the final project.

The third and final nutrient removal facilities phase is expected to cost $1.57 billion, bringing the total cost of the entire upgrade to $3.1 billion.

Read
6:00 PM CDT

Councillors say Main Street Project scuttles other agency’s efforts to house homeless

Scott Billeck 5 minute read Preview

Councillors say Main Street Project scuttles other agency’s efforts to house homeless

Scott Billeck 5 minute read Yesterday at 6:57 PM CDT

A Winnipeg outreach agency that’s been largely shut out of government funding says it has found housing for more people in the last five months than Manitoba’s homeless strategy that began last year.

Read
Yesterday at 6:57 PM CDT

Manitoba-Canada Defence Alliance unveiled

Gabrielle Piché 5 minute read Preview

Manitoba-Canada Defence Alliance unveiled

Gabrielle Piché 5 minute read 8:11 PM CDT

Despite Ottawa’s promises of increased defence spending, Jack Enns has seen slowdowns.

Tit-for-tat tariffs between Canada and the United States have lessened demand for some of A. Adams Supply (1969) Ltd.’s products, the firm’s general manager said.

The Winnipeg company ships specialized tools to aerospace manufacturers, metalworkers and transport firms.

More clients could be useful — and so would local companies winning defence contracts, Enns said. If that happened, vendors such as A. Adams Supply may get more orders, boosting business.

Read
8:11 PM CDT