🎁 💸 Warren Buffett's Top Picks Are Up +49.1%. Copy Them to Your Watchlist – For FreeCopy Portfolio

Exclusive: China hacked eight major computer services firms in years-long attack

Published 06/26/2019, 07:21 AM
© Reuters. FILE PHOTO - Man holds laptop computer as cyber code is projected on him in this illustration picture
DXC
-
IBM
-
ERICAs
-

By Jack Stubbs, Joseph Menn and Christopher Bing

LONDON (Reuters) - Hackers working for China's Ministry of State Security broke into networks of eight of the world's biggest technology service providers in an effort to steal commercial secrets from their clients, according to sources familiar with the attacks.

Reuters today reported extensive new details about the global hacking campaign, known as Cloud Hopper and attributed to China by the United States and its Western allies.

Read the full report here:

https://www.reuters.com/investigates/special-report/china-cyber-cloudhopper

A U.S. indictment in December outlined an elaborate operation to steal Western intellectual property in order to advance China's economic interests but stopped short of naming victim companies. A Reuters report at the time identified two: Hewlett Packard Enterprise and IBM (NYSE:IBM).

Now, Reuters has found that at least six other technology service providers were compromised: Fujitsu, Tata Consultancy Services, NTT Data, Dimension Data, Computer Sciences Corporation (NYSE:DXC) and DXC Technology, HPE's spun-off services arm.

Reuters has also identified more than a dozen victims who were clients of the service providers. That list includes Swedish telecoms giant Ericsson (BS:ERICAs), U.S. Navy shipbuilder Huntington Ingalls Industries and travel reservation system Sabre.

HPE said it worked "diligently for our customers to mitigate this attack and protect their information." DXC said it had "robust security measures in place" to protect itself and clients, neither of which have "experienced a material impact" due to Cloud Hopper.

NTT Data, Dimension Data, Tata Consultancy Services, Fujitsu and IBM declined to comment. IBM has previously said it has no evidence sensitive corporate data was compromised by the attacks.

Sabre said it had disclosed a cybersecurity incident in 2015 and an investigation concluded no traveler data was accessed. A Huntington Ingalls spokeswoman said the company is "confident that there was no breach of any HII data" via HPE or DXC.

Ericsson said it does not comment on specific cybersecurity incidents. "While there have been attacks on our enterprise network, we have found no evidence in any of our extensive investigations that Ericsson's infrastructure has ever been used as part of a successful attack on one of our customers," a spokesman said.

The Chinese government has consistently denied all accusations of involvement in hacking. The Chinese Foreign Ministry said Beijing opposed cyber-enabled industrial espionage. "The Chinese government has never in any form participated in or supported any person to carry out the theft of commercial secrets," it said in a statement to Reuters.

The Cloud Hopper attacks carry worrying lessons for government officials and technology companies struggling to manage security threats.

Chinese hackers, including a group known as APT10, were able to continue the attacks in the face of a counter-offensive by top security specialists and despite a 2015 U.S.-China pact to refrain from economic espionage.

Reuters was unable to detail the full extent of the damage done by the hacking and many victims are unable to tell exactly what was stolen. Yet senior Western intelligence officials say the toll was high.

© Reuters. FILE PHOTO - Man holds laptop computer as cyber code is projected on him in this illustration picture

"This was a sustained series of attacks with a devastating impact," said Robert Hannigan, former director of Britain’s GCHQ signals intelligence agency and now European chairman at cybersecurity firm BlueVoyant.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.