Ministry of State Security revealed three data security breachesA foreign spy agency hacked multiple Chinese airlines.
Ministry of State Security revealed three data security breachesA foreign spy agency hacked multiple Chinese airlines.
Zhixin Wan
and
Zichen Wang
9 hr ago1
China’s Counter-Espionage Law 《中华人民共和国反间谍法》 was adopted on November 1, 2014. On the eve of its seventh anniversary, the Ministry of State Security 国家安全部 revealed three cases that it described as having "jeopardized the security of important data, aiming to further raise the society's awareness on non-traditional security, thus the public can jointly maintain national security."
Several days have passed but that has yet to make it into English-language news.
Whereas the U.S. and other western security sources are not infrequent contributors to Western media reports on China, usually detailing what’s described as Chinese influence, threats, espionage, or hacking, the same simply can’t be said of this side. Also, press content with those intelligence sources is almost always quite prominent in the news. With that in mind, your Pekingnologist believes the information on specific cases from the Chinese Ministry of State Security should be interesting as well.
Also, the three cases are about data, one of the hottest topics in the discourse revolving around intelligence these days. Plus, they are described with quite some details, though key information such as the specific foreign government is not available. That, alas, would have instantly launched breaking news.
Without further ado, below are translated from a Xinhua report in Chinese entitled 国家安全部公布三起危害重要数据安全案例 Ministry of State Security disclosed three cases where data security was jeopardized, released on Oct. 31, 2021.
案件一:某航空公司数据被境外间谍情报机关网络攻击窃取案
2020年1月,某航空公司向国家安全机关报告,该公司信息系统出现异常,怀疑遭到网络攻击。国家安全机关立即进行技术检查,确认相关信息系统遭到网络武器攻击,多台重要服务器和网络设备被植入特种木马程序,部分乘客出行记录等数据被窃取。
国家安全机关经过进一步排查发现,另有多家航空公司信息系统遭到同一类型的网络攻击和数据窃取。经深入调查,确认相关攻击活动是由某境外间谍情报机关精心谋划、秘密实施,攻击中利用了多个技术漏洞,并利用多个网络设备进行跳转,以隐匿踪迹。
针对这一情况,国家安全机关及时协助有关航空公司全面清除被植入的特种木马程序,调整技术安全防范策略、强化防范措施,制止了危害的进一步扩大。
Case 1: An airline’s data was stolen by a foreign spy agency via cyberattacks
In January 2020, an airline reported to State Security organs that the company’s information system had seen an anomaly and they suspected a cyberattack. The State Security organs immediately conducted a technical inspection and confirmed that relevant information systems had been attacked by cyber weapons. Multiple important servers and network equipment were implanted with special Trojan horse programs. Some passengers’ travel records and other data were stolen.
After further investigation, the State Security organs found that many other airlines’ information systems were subjected to the same type of cyber attack and data theft. After thorough investigation, it was confirmed that the relevant attack activities were carefully planned and secretly carried out by a foreign spy agency, which took advantage of multiple technical loopholes and used multiple network devices to hide its trace.
In response to this situation, the State Security organs promptly assisted relevant airlines in removing the implanted special Trojan horse programs, adjusted technologies and strategies to safeguard security, strengthened prevention measures, and ultimately prevented further expansion of the damage....
Please continue reading the article/work done by the author on the link below: