Skip to main content

Chinese cyber attacks on West are widespread, experts say

STORY HIGHLIGHTS
  • Report: One in every three observed computer attacks in Q3 2012 came from China
  • The New York Times and the Wall Street Journal claim to be victims of Chinese attacks
  • Chinese officials say there are no state-sponsored hacking attacks on Western companies
  • Experts say the number of attacks coming out of China has risen in recent years

Hong Kong (CNN) -- Allegations that Chinese hackers infiltrated the computers of two leading U.S. newspapers add to a growing number of cyber attacks on Western companies, governments and foreign-based dissidents that are believed to originate in China, experts say.

According to one recent report, one in every three observed computer attacks in the third quarter of 2012 emanated from China.

Chinese officials have denied that Beijing has supported any cyber attacks, stressing that hacking is illegal in the country.

The New York Times reported Wednesday it had been the target of four months of cyber assaults, which started during an investigation by the newspaper into the wealth reportedly accumulated by relatives of the Chinese premier, Wen Jiabao. The Wall Street Journal said Thursday that its computer systems also had been infiltrated by Chinese hackers.

Cyber security experts say the alleged attack on The New York Times appeared to be similar to previously reported attacks that were linked to China.

"To do a spear-phishing attack of this kind is a well-established move in attacks against Google and various U.S. defense contractors from China," said Thomas Parenty, a former employee of the U.S. National Security Agency who now advises foreign firms in China on computer security.

NYT attack a wake-up call, security experts say

China denies NY Times hack attack
China denies NY Times hack attack
New York Times: We were hacked

"You could say the tools are sort of stock-in-trade" for Chinese hackers, he said.

"Spear-phishing" is a technique of disguising an email so that it appears to be from a trusted source, luring the victim to open an attachment or link that unleashes malicious software on the computer.

Investigators for The Times say they suspect the technique was used by the hackers to break into the newspaper's system where they were able collect passwords of every Times employee and gain access to the personal computers of 53 employees.

Security experts who helped the newspaper to counter the attacks accumulated evidence that the hackers used methods "associated with the Chinese military in the past" to breach the network, The Times said.

Chinese denials

Asked about The Times's allegations on Thursday, a spokesman for the Chinese Foreign Ministry said that "all such alleged attacks are groundless, irresponsible accusations lacking solid proof or reliable research results." China has been the victim of cyberattacks and "has laws and regulations prohibiting such actions," the spokesman, Hong Lei, said at a regular news briefing.

A separate statement from the Chinese Ministry of National Defense said the country's military "has never supported any hacker activities."

But data reported by Western companies suggest that even though Chinese authorities say they prohibit hacking, they are struggling to keep it under control.

One-third of all observed computer attacks from July through September last year came from China, according to a report last month from Akamai Technologies, an Internet services company.

The United States was a distant second, originating 13% of observed attacks, followed by Russia with 4.7%.

"China has been consistently responsible for the largest percentage of observed attacks since (the fourth quarter of) 2011," the report said.

The most recent report shows a dramatic upswing in incidents from the Asian country. In the second quarter, 16% of observed cyber attacks came from China, the company said.

The executive summary of the report didn't specify from which groups or individuals in China the attacks might have come.

Google had a very public spat with the Chinese government in 2010 after it claimed China had led a hacking attack against Google, other technology companies, defense corporations and Chinese dissidents.

"In the past they've been pretty much focused on either intellectual properties, such as the hacking of defense companies, or dissidents they want to get at, like the Google Gmail attacks," Parenty said. "In this case, it appears they were trying to be able to get to people who talked to The New York Times -- they could make their lives miserable and send the message: Don't do this.

"They love to instill fear so people self censor or limit what they would say or do with the media," he added.

Compromised computers

Mandiant, the security firm that led the investigation at The New York Times, says there is good reason for concern in the United States.

"There are thousands of computers compromising the United States at universities, at Mom and Pop shops -- small organizations without a big cyber security program -- and those computers serve as the beachhead to hack blue-chip American companies," Kevin Mandia, the chief executive of Mandiant, told CNN.

"The majority of victims, well over 90% of the victims we have responded to, really don't disclose that these attacks occur" for fear of losing customer trust, Mandia said.

"The folks that perpetrated this intrusion have done it to hundreds of other organizations and usually they are very successful," Mandia said. "What's really unique here is the fact that the victim organization, The New York Times, has decided to share this information with the public, so people can be more aware of the problem -- because it's a very pervasive problem."

Marc Frons, chief information officer of The Times, told CNN that the newspaper believed it had prevented this attack from revealing confidential sources.

In the case of the investigation into Wen's family's finances, much of the information came from public records.

But Frons said The Times isn't letting its guard down after expelling the hackers.

"I think we're over this phase of the attack and obviously the types of things they tried to do previously they'll have a more difficult time doing, but this isn't over," he said. "As long as there are computers and networks we're going to be faced with cyber espionage threats."

CNN's Hala Gorani, Jethro Mullen and CNN's Beijing bureau contributed to this report

ADVERTISEMENT
Part of complete coverage on
updated 3:57 AM EST, Thu December 18, 2014
Chinese students show a handmade red ribbon one day ahead of the the World AIDS Day, at a school in Hanshan, east China's Anhui province on November 30, 2009.
Over 200 Chinese villagers in Sichuan province have signed a petition to banish a HIV-positive eight-year-old boy, state media reported.
updated 6:44 AM EST, Mon December 15, 2014
A Chinese couple allegedly threw hot water on a flight attendant and threatened to blow up the plane, forcing the Nanjing-bound plane to turn back to Bangkok.
updated 12:03 AM EST, Mon December 15, 2014
China's 1.3 billion citizens may soon find it much harder to belt out their national anthem at will.
updated 7:21 PM EST, Tue December 9, 2014
Like Beijing today, Los Angeles in the last century went through its own smog crisis. The city's mayor says LA's experience delivers valuable lessons.
updated 12:42 AM EST, Sat December 6, 2014
At the height of his power, Zhou Yongkang controlled China's police, spy agencies and courts. Now, he's under arrest.
updated 3:26 AM EST, Fri December 5, 2014
China says it will end organ transplants from executed prisoners but tradition means that donors are unlikely to make up the shortfall.
updated 1:48 AM EST, Fri December 5, 2014
China's skylines could look a lot more uniform in the years to come, if a statement by a top Beijing official is to believed.
updated 3:55 AM EST, Wed December 3, 2014
Despite an anti-corruption drive, China's position on an international corruption index has deteriorated in the past 12 months.
updated 7:01 AM EST, Wed November 26, 2014
A daring cross-border raid by one of Russian President Vladimir Putin's associates has -- so far -- yet to sour Sino-Russian relations.
updated 7:51 PM EST, Sun November 23, 2014
A 24-hour Taipei bookstore is a hangout for hipsters as well as bookworms.
updated 8:53 PM EST, Mon November 24, 2014
China is building an island in the South China Sea that could accommodate an airstrip, according to IHS Jane's Defence Weekly.
updated 5:57 AM EST, Wed November 19, 2014
North Korean refugees face a daunting journey to reach asylum in South Korea, with gangs of smugglers the only option.
updated 6:19 PM EST, Fri November 21, 2014
China and "probably one or two other" countries have the capacity to shut down the nation's power grid and other critical infrastructure.
ADVERTISEMENT