Google disclosed that it had been hit by a sophisticated, targeted cyber attack originating in China, later widely known as Operation Aurora. The company said at least 20 other large companies had been similarly targeted and announced it would stop censoring results on Google.cn.
What happened
- Google said the attack, detected in mid-December 2009, resulted in the theft of some of its intellectual property.
- A primary goal appeared to be accessing the Gmail accounts of Chinese human rights activists; Google said two accounts were accessed, limited to metadata such as subject lines.
- Other targets spanned the internet, finance, technology, media, and chemical sectors.
- Google said it was no longer willing to censor search results in China, even if that meant closing Google.cn and its offices there.
Why it mattered
It was one of the first times a major company publicly described being targeted by a state-linked espionage campaign, bringing advanced persistent threats into mainstream news and boardroom discussion.
Lessons for organisations
Assume well-resourced attackers may target intellectual property and privileged users; prompt patching of browsers, monitoring for unusual access, and a tested incident response plan are essential. Frameworks such as ISO/IEC 27001 help make these controls systematic.
Source: Google Public Policy Blog
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.