Chinese hackers and user lapses turn smartphones into a ‘mobile security crisis’

Advertisement

Advertise with us

WASHINGTON (AP) —

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 08/06/2025 (450 days ago), so information in it may no longer be current.

WASHINGTON (AP) —

Cybersecurity investigators noticed a highly unusual software crash — it was affecting a small number of smartphones belonging to people who worked in government, politics, tech and journalism.

The crashes, which began late last year and carried into 2025, were the tipoff to a sophisticated cyberattack that may have allowed hackers to infiltrate a phone without a single click from the user.

FILE - A child holds an iPhone at an Apple store on Sept. 25, 2015 in Chicago. (AP Photo/Kiichiro Sato, File)
FILE - A child holds an iPhone at an Apple store on Sept. 25, 2015 in Chicago. (AP Photo/Kiichiro Sato, File)

The attackers left no clues about their identities, but investigators at the cybersecurity firm iVerify noticed that the victims all had something in common: They worked in fields of interest to China’s government and had been targeted by Chinese hackers in the past.

Foreign hackers have increasingly identified smartphones, other mobile devices and the apps they use as a weak link in U.S. cyberdefenses. Groups linked to China’s military and intelligence service have targeted the smartphones of prominent Americans and burrowed deep into telecommunication networks, according to national security and tech experts.

It shows how vulnerable mobile devices and apps are and the risk that security failures could expose sensitive information or leave American interests open to cyberattack, those experts say.

“The world is in a mobile security crisis right now,” said Rocky Cole, a former cybersecurity expert at the National Security Agency and Google and now chief operations officer at iVerify. “No one is watching the phones.”

US zeroes in on China as a threat, and Beijing levels its own accusations

U.S. authorities warned in December of a sprawling Chinese hacking campaign designed to gain access to the texts and phone conversations of an unknown number of Americans.

“They were able to listen in on phone calls in real time and able to read text messages,” said Rep. Raja Krishnamoorthi of Illinois. He is a member of the House Intelligence Committee and the senior Democrat on the Committee on the Chinese Communist Party, created to study the geopolitical threat from China.

Chinese hackers also sought access to phones used by Donald Trump and running mate JD Vance during the 2024 campaign.

The Chinese government has denied allegations of cyberespionage, and accused the U.S. of mounting its own cyberoperations. It says America cites national security as an excuse to issue sanctions against Chinese organizations and keep Chinese technology companies from the global market.

“The U.S. has long been using all kinds of despicable methods to steal other countries’ secrets,” Lin Jian, a spokesman for China’s foreign ministry, said at a recent press conference in response to questions about a CIA push to recruit Chinese informants.

U.S. intelligence officials have said China poses a significant, persistent threat to U.S. economic and political interests, and it has harnessed the tools of digital conflict: online propaganda and disinformation, artificial intelligence and cyber surveillance and espionage designed to deliver a significant advantage in any military conflict.

Mobile networks are a top concern. The U.S. and many of its closest allies have banned Chinese telecom companies from their networks. Other countries, including Germany, are phasing out Chinese involvement because of security concerns. But Chinese tech firms remain a big part of the systems in many nations, giving state-controlled companies a global footprint they could exploit for cyberattacks, experts say.

Chinese telecom firms still maintain some routing and cloud storage systems in the U.S. — a growing concern to lawmakers.

“The American people deserve to know if Beijing is quietly using state-owned firms to infiltrate our critical infrastructure,” U.S. Rep. John Moolenaar, R-Mich. and chairman of the China committee, which in April issued subpoenas to Chinese telecom companies seeking information about their U.S. operations.

Mobile devices have become an intel treasure trove

Mobile devices can buy stocks, launch drones and run power plants. Their proliferation has often outpaced their security.

The phones of top government officials are especially valuable, containing sensitive government information, passwords and an insider’s glimpse into policy discussions and decision-making.

The White House said last week that someone impersonating Susie Wiles, Trump’s chief of staff, reached out to governors, senators and business leaders with texts and phone calls.

It’s unclear how the person obtained Wiles’ connections, but they apparently gained access to the contacts in her personal cellphone, The Wall Street Journal reported. The messages and calls were not coming from Wiles’ number, the newspaper reported.

While most smartphones and tablets come with robust security, apps and connected devices often lack these protections or the regular software updates needed to stay ahead of new threats. That makes every fitness tracker, baby monitor or smart appliance another potential foothold for hackers looking to penetrate networks, retrieve information or infect systems with malware.

Federal officials launched a program this year creating a “cyber trust mark” for connected devices that meet federal security standards. But consumers and officials shouldn’t lower their guard, said Snehal Antani, former chief technology officer for the Pentagon’s Joint Special Operations Command.

“They’re finding backdoors in Barbie dolls,” said Antani, now CEO of Horizon3.ai, a cybersecurity firm, referring to concerns from researchers who successfully hacked the microphone of a digitally connected version of the toy.

Risks emerge when smartphone users don’t take precautions

It doesn’t matter how secure a mobile device is if the user doesn’t follow basic security precautions, especially if their device contains classified or sensitive information, experts say.

Mike Waltz, who departed as Trump’s national security adviser, inadvertently added The Atlantic’s editor-in-chief to a Signal chat used to discuss military plans with other top officials.

Secretary of Defense Pete Hegseth had an internet connection that bypassed the Pentagon’s security protocols set up in his office so he could use the Signal messaging app on a personal computer, the AP has reported.

Hegseth has rejected assertions that he shared classified information on Signal, a popular encrypted messaging app not approved for the use of communicating classified information.

China and other nations will try to take advantage of such lapses, and national security officials must take steps to prevent them from recurring, said Michael Williams, a national security expert at Syracuse University.

“They all have access to a variety of secure communications platforms,” Williams said. “We just can’t share things willy-nilly.”

Report Error Submit a Tip

More Stories

Winnipeg police ID deceased man, notify family

Free Press staff 3 minute read Preview

Winnipeg police ID deceased man, notify family

Free Press staff 3 minute read Yesterday at 11:26 AM CDT

Winnipeg police have been able to notify next-of-kin about the death of a man found unresponsive on a city street in July.

The man was identified after police asked for the public’s help and issued a composite sketch and description of the unknown man on Friday.

On Sunday, police said his family has been notified and thanked the public. Additional details about the man were not released in order to respect the family’s privacy, police said.

The man died in hospital after being found unresponsive July 28 at the corner of Main Street and James Avenue in Winnipeg, and investigators’ previous efforts to identify him were unsuccessful.

Read
Yesterday at 11:26 AM CDT

Heavy rain, wind sweep across Manitoba as tornado takes out barn near Elkhorn

Malak Abas 5 minute read Preview

Heavy rain, wind sweep across Manitoba as tornado takes out barn near Elkhorn

Malak Abas 5 minute read Updated: 7:32 PM CDT

Kelvin Siemens hoped he was dreaming when a tornado touched down near his home Sunday evening.

When he woke up the next morning, the southwestern Manitoba farmer confirmed it was no dream, as his barn and hay shed were toppled and a pile of rubble was left behind.

“This kind of devastation can really test your constitution,” Siemens, 65, told the Free Press from his farm just south of Kola, a small community in the Rural Municipality of Wallace-Woodworth.

The tornado was reported near Elkhorn, about 105 kilometres west of Brandon, at about 6:30 p.m. Sunday. A second tornado touched down near Maryfield, Sask., located southwest of Elkhorn.

Read
Updated: 7:32 PM CDT

Village Green Bakery keeps focus on classic quality, kindness, fun in Victoria Beach

Aaron Epp 6 minute read Preview

Village Green Bakery keeps focus on classic quality, kindness, fun in Victoria Beach

Aaron Epp 6 minute read 6:00 AM CDT

VICTORIA BEACH — They’re not carved into stone tablets — they’re reminders and not commandments, after all — but behind one of the display cases at Village Green Bakery is a laminated sheet of letter-size paper with a list of statements outlining how owner Jen Leslie wants staffers to approach their work.

Fittingly, there’s a baker’s dozen of them.

One is aimed specifically at a stoic teen who’s worked at the bakery since it opened in summer 2022 — “Smile, Brody,” it says — while the other 12 are meant for all 17 employees at the seasonal business, which is open annually from May long weekend until Thanksgiving.

“Smile and enjoy the ride,” is the first reminder, followed by, “The summer is short, so make it a good one,” “always take the high road” and “you are awesome.”

Read
6:00 AM CDT

Security guard in stable condition after grocery store assault

Scott Billeck 2 minute read Preview

Security guard in stable condition after grocery store assault

Scott Billeck 2 minute read Updated: Yesterday at 2:31 PM CDT

A security guard was taken to hospital after an assault at a Sargent Avenue FreshCo Friday, just days after another guard was stabbed during a robbery at a St. James Dollarama.

Read
Updated: Yesterday at 2:31 PM CDT

Foreign workers at Manitoba hotel are owed $138K in unpaid wages and fees, labour board rules

Abiola Odutola 4 minute read Preview

Foreign workers at Manitoba hotel are owed $138K in unpaid wages and fees, labour board rules

Abiola Odutola 4 minute read Yesterday at 11:47 AM CDT

BRANDON — The Manitoba Labour Board has ordered the Western Star All Suites Hotel to pay nearly $138,000 in unpaid wages and administrative fees after it dismissed the appeals involving three foreign workers employed by the company.

In a decision dated Aug. 25, the board ordered 6692452 Manitoba Ltd. (doing business as Western Star All Suites Hotel), 1638185 Alberta Ltd. and company director P.X. to pay a total of $137,915.79 to the Employment Standards Branch for wages owed to foreign workers S.J., J.B. and G.R.

The decision was edited to protect the personal information of the employees, who worked at a hotel, reportedly in Melita, at different times and also lived there during their employment.

The board stated the employees were owed wages after hearing evidence about long working hours, irregular payments, inadequate employment records and working conditions.

Read
Yesterday at 11:47 AM CDT

Winnipegger battles through partially torn MCL to claim U20 wrestling world title

Taylor Allen 5 minute read Preview

Winnipegger battles through partially torn MCL to claim U20 wrestling world title

Taylor Allen 5 minute read 6:16 PM CDT

Kaura Coles admits she’s not the strongest, fastest or most athletic amateur wrestler.

But that hasn’t stopped the 19-year-old from Winnipeg from becoming the best in the world.

Coles, representing London-Western Wrestling Club out of London, Ont., won gold in the 53-kg division at the U20 World Championships in Bratislava, Slovakia, on Aug. 19.

She’s only the fifth Canadian to win a U20 world title.

Read
6:16 PM CDT