Chinese Hackers Target UK Think Tanks

China-based hacking groups are repeatedly targeting British think tanks specialising in international security and defence issues.

This is the warning from US security specialist Crowdstrike, which said that the attacks by the Chinese groups have been targeting the groups since April 2017, but not all the hacking attacks were successful.

For years now experts have warned that Chinese hackers have targeted Western organisations, mostly located (but not exclusively) in the defence industry.

Chinese Hacks

Crowdstrike told the BBC that it had seen repeated targeting of think tanks specialising in international security and defence issues.

The BBC said that not all of the UK think tanks targeted were breached.

Crowdstrike said that it had been called in by some think tanks to respond to hack attacks, but a number of think tanks contacted by the BBC declined to comment on the matter.

The security firm reportedly attributes the attacks to a group it calls “Panda”. Crowdstrike reportedly said Panda is based in China and is linked to the Chinese state.

Crowdstrike also said Chinese cyber activity increased in 2017 across the world.

Crowdstrike said that from the summer of 2017, law firms, universities and technology companies were targeted around the world, whilst in the UK think tanks were targeted.

Aggressively Targeted

Dmitri Alperovitch, Crowdstrike’s co-founder and CTO, told the BBC that a number of think tanks that work on Chinese policy were targeted “very aggressively”.

He said those behind the attacks were trying to steal reports – but also any information about connections to government.

“They do believe the think tanks are very influential both in the US and UK,” he reportedly said. “They believe that they may have access to information which is not public.

“In some cases [that] can be true, because you do have a lot of informal channels that these think tank people will have with government officials.”

Alperovitch said Crowdstrike would be brought in after an attack to help investigate, “clean up” and protect the organisations going forward.

Crowdstrike said that even after the Chinese hackers were kicked out, they would try to get back in.

Crowdstrike has been previously been brought in to investigate politically motivated hacking incidents during the US presidential election, including the release of emails stolen from the Democratic National Committee (DNC).

The United States government has officially blamed Russia for that attack.

It said that the ‘Fancy Bear’ hacking group, allegedly linked to the Russian military, had hacked the DNC.

This same group allegedly last month attacked the US Senate and organisations linked to the Olympic Games.

Do you know all about security? Try our quiz!

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

Apple, Google Mobile Ecosystems Should Be Investigated, CMA Told

CMA receives 'provisional recommendation' from independent inquiry that Apple,Google mobile ecosystem needs investigation

3 days ago

Australia Rejects Elon Musk Claim About Social Media Ban For Under-16s

Government minister flatly rejects Elon Musk's “unsurprising” allegation that Australian government seeks control of Internet…

3 days ago

Northvolt Files For Bankruptcy Protection In US

Northvolt files for Chapter 11 bankruptcy protection in the United States, and CEO and co-founder…

3 days ago

UK’s CMA Readies Cloud Sector “Behavioural” Remedies – Report

Targetting AWS, Microsoft? British competition regulator soon to announce “behavioural” remedies for cloud sector

4 days ago

Former Policy Boss At X, Nick Pickles, Joins Sam Altman Venture

Move to Elon Musk rival. Former senior executive at X joins Sam Altman's venture formerly…

4 days ago

Bitcoin Rises Above $96,000 Amid Trump Optimism

Bitcoin price rises towards $100,000, amid investor optimism of friendlier US regulatory landscape under Donald…

4 days ago