Don’t do SECURITY. Do business SECURELY.

Mandiant report links APT1 hacking group to Chinese military unit

Security firm Mandiant publicly tied a long-running cyber espionage campaign against 141 organisations to a unit of China's People's Liberation Army.

US security firm Mandiant published a detailed report on a hacking group it called APT1, which it said had carried out cyber espionage against 141 organisations since 2006. The company linked the group to Unit 61398 of China’s People’s Liberation Army, an unusually direct public attribution by a private company.

What happened

  • Mandiant said APT1 had stolen large volumes of data from organisations across many industries, most of them in English-speaking countries.
  • The report traced the activity to a unit of the PLA General Staff Department’s 3rd Department, based in Shanghai.
  • Alongside the report, Mandiant released more than 3,000 technical indicators, including domain names, malware hashes, and encryption certificates.
  • The Chinese government rejected the allegations.

Why it mattered

The report broke the industry’s habit of avoiding nation-state attribution and set a template for the public threat intelligence reporting that followed. It also raised the profile of state-sponsored intellectual property theft as a boardroom and diplomatic issue.

Lessons for organisations

Organisations holding valuable intellectual property should assume they may be targeted by well-resourced attackers and invest in detection and response, not just prevention. Sharing and using published indicators of compromise helps defenders spot known threats early.

Source: Mandiant (Google Cloud)

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights