Don’t do SECURITY. Do business SECURELY.

Google reveals China-based cyber attack and rethinks censorship

Google disclosed a targeted attack originating in China that stole intellectual property and targeted activists' Gmail accounts.

Google disclosed that it had been hit by a sophisticated, targeted cyber attack originating in China, later widely known as Operation Aurora. The company said at least 20 other large companies had been similarly targeted and announced it would stop censoring results on Google.cn.

What happened

  • Google said the attack, detected in mid-December 2009, resulted in the theft of some of its intellectual property.
  • A primary goal appeared to be accessing the Gmail accounts of Chinese human rights activists; Google said two accounts were accessed, limited to metadata such as subject lines.
  • Other targets spanned the internet, finance, technology, media, and chemical sectors.
  • Google said it was no longer willing to censor search results in China, even if that meant closing Google.cn and its offices there.

Why it mattered

It was one of the first times a major company publicly described being targeted by a state-linked espionage campaign, bringing advanced persistent threats into mainstream news and boardroom discussion.

Lessons for organisations

Assume well-resourced attackers may target intellectual property and privileged users; prompt patching of browsers, monitoring for unusual access, and a tested incident response plan are essential. Frameworks such as ISO/IEC 27001 help make these controls systematic.

Source: Google Public Policy Blog

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights