US Government Employee Data Breach Reportedly Tied to Chinese Intelligence

Advertisement
By Reuters | Updated: 22 June 2015 20:51 IST

The Chinese hacking group suspected of stealing sensitive information about millions of current and former US government employees has a different mission and organizational structure than the military hackers who have been accused of other US data breaches, according to people familiar with the matter.

While the Chinese People's Liberation Army typically goes after defence and trade secrets, this hacking group has repeatedly accessed data that could be useful to Chinese counter-intelligence and internal stability, said two people close to the US investigation.

Advertisement

Washington has not publicly accused Beijing of orchestrating the data breach at the US Office of Personnel Management (OPM), and China has dismissed as "irresponsible and unscientific" any suggestion that it was behind the attack.

Sources told Reuters that the hackers employed a rare tool to take remote control of computers, dubbed Sakula, that was also used in the data breach at US health insurer Anthem Inc disclosed this year.

Advertisement

The Anthem attack, in turn, has been tied to a group that security researchers said is affiliated with China's Ministry of State Security, which is focused on government stability, counter-intelligence and dissidents. The ministry could not immediately be reached for comment.

In addition, US investigators believe the hackers registered the deceptively named OPM-Learning.org website to try to capture employee names and passwords, in the same way that Anthem, formerly known as Wellpoint, was subverted with spurious websites such as We11point.com, which used the number "1" instead of the letter "l".

Advertisement

(Also See: EU States Endorse Overhaul of Data Protection Rules)

Both the Anthem and OPM breaches used malicious software electronically signed as safe with a certificate stolen from DTOPTOOLZ Co, a Korean software company, the people close to the inquiry said. DTOPTOOLZ said it had no involvement in the data breaches.

Advertisement

The FBI did not respond to requests for comment. People familiar with its investigation said Sakula had only been seen in use by a small number of Chinese hacking teams.

"Chinese law prohibits hacking attacks and other such behaviours which damage Internet security," China's Foreign Ministry said in a statement. "The Chinese government takes resolute strong measures against any kind of hacking attack. We oppose baseless insinuations against China."

Many unknowns
Most of the biggest US cyber-attacks blamed on China have been attributed, with varying degrees of certitude, to elements of the Chinese army. In the most dramatic case last year, the US Justice Department indicted five PLA officers for alleged economic espionage.

Far less is known about the OPM hackers, and security researchers have differing views about the size of the group and what other attacks it is responsible for.

People close to the OPM investigation said the same group was behind Anthem and other insurance breaches. But they are not yet sure which part of the Chinese government is responsible.

"We are seeing a group that is only targeting personal information," said Laura Galante, manager of threat intelligence at FireEye Inc , which has worked on a number of the high-profile network intrusions.

CrowdStrike and other security companies, however, say the Anthem hackers also engaged in stealing defence and industry trade secrets. CrowdStrike calls the group "Deep Panda," EMC Corp's RSA security division dubs it "Shell Crew," and other firms have picked different names.

The OPM breach gave hackers access to US government job applicants' security clearance forms detailing past drug use, love affairs, and foreign contacts that officials fear could be used for blackmail or recruiting.

In contrast to hacking outfits associated with the Chinese army, "Deep Panda" appears to be affiliated with the Ministry of State Security, said CrowdStrike co-founder Dmitri Alperovitch.

Information about US spies in China would logically be a top priority for the ministry, Alperovitch said, adding that "Deep Panda's" tools and techniques have also been used to monitor democracy protesters in Hong Kong.

An executive at one of the first companies to connect the Anthem and OPM compromises, ThreatConnect, said the disagreements about the boundaries of "Deep Panda" could reflect a different structure than that in top-down military units.

"We think it's likely a cohort of Chinese actors, a bunch of mini-groups that are handled by one main benefactor," said Rich Barger, co-founder of ThreatConnect, adding that the group could get software tools and other resources from a common supplier.

"We think this series of activity over time is a little more distributed, and that is why there is not a broad consensus as to the beginning and end of this group."

© Thomson Reuters 2015

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Chinese, Cyber Attack, Data, Hakcing, Internet, US
Advertisement

Related Stories

Popular Mobile Brands
  1. PhonePe Launches UPI 123Pay for Feature Phones Across India
  2. Philips 5G Smartphone Set to Launch in India on This Date
  3. Redmi 17 5G Will Launch in India On This Date: See Colourways, Specs
  4. Xiaomi Pad 9 Pro Max Appears on Geekbench With Xring O3 Chip
  5. Motorola Razr 70 Swarovski Edition Teased Ahead of IFA 2026
  6. Vivo T5 5G Key Specifications Confirmed Ahead of September 2 India Launch
  7. Here's Why the Google Pixel 11 Series Will Not Get GrapheneOS
  8. Samsung Galaxy S26 FE Will Go on Sale in India Soon, Microsites Confirm
  9. Boltt Ace 5G, Evo Software Support Confirmed Ahead of September 1 Sale
  1. Xiaomi Pad 9 Pro Max Appears on Geekbench With Xring O3 Chip
  2. Philips 5G Smartphone India Launch Date Confirmed: Here’s What We Know
  3. Boltt Reveals Software Update Policy for Ace 5G and Evo Ahead of September 1 Sale
  4. Samsung Galaxy Tab S12 Ultra Allegedly Listed on Geekbench With MediaTek Dimensity 9500 Chipset
  5. NPCI to Soon Allow Users to Port UPI AutoPay Mandates Across Digital Payments Platforms: Report
  6. PhonePe UPI 123Pay Enables UPI Payments Without Internet on Feature Phones in India
  7. Vivo T5 5G Key Specifications Teased; 7,050mAh Battery, Dual Rear Cameras Confirmed
  8. Anthropic’s Claude Closes 85 Percent of AI Safety Gap in Automated Research Test
  9. OpenClaw 2.0 Released as Biggest Update Since Launch; Brings Shared Cloud Sessions, Smarter Automations
  10. Samsung Galaxy S26 FE Set to Go on Sale in India Soon as Multiple Microsites Go Live
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.