DOJ Hacking Indictments Against China Continue: What Do They Mean for Companies?
Robert Silvers, a partner in the litigation department at Paul Hastings in Washington, D.C., said Thursday the Justice Department's action serves as a stark reminder for companies to not only check their own cybersecurity but also the security of their third-party vendors. Many of the companies were compromised by attacks on their managed service providers, who manage, process and store data.
December 20, 2018 at 05:12 PM
6 minute read
The U.S. Department of Justice unsealed the indictment of two Chinese citizens Thursday on charges they engaged in computer hacks on technology companies and government agencies globally for more than a decade in the latest in a series of such DOJ indictments.
A grand jury in the U.S. District Court for the Southern District of New York indicted Zhu Hua and Zhang Shilong, charging them with conspiracy to commit computer intrusions, wire fraud and aggravated identity theft. Both defendants also were indicted under several aliases, according to the document signed by U.S. Attorney Geoffrey Berman.
Deputy Attorney General Rod Rosenstein said in a statement Thursday that the indictment “alleges that the defendants were part of a group that hacked computers in at least a dozen countries and gave China's intelligence service access to sensitive business information. ”
He said, “the activity alleged in this indictment violates the commitment that China made to members of the international community” in a 2015 bilateral agreement with the United States.
Even as the U.S. was unsealing its indictment, the United Kingdom brought similar charges against the same APT10 group for carrying out similar cyber espionage activities in the UK, Asia and the U.S. according to the Washington Post.
Robert Silvers, a partner in the litigation department at Paul Hastings in Washington, D.C., said Thursday the Justice Department's action serves as a stark reminder for companies to not only check their own cybersecurity but also the security of their third-party vendors. Many of the companies were compromised by attacks on their managed service providers, who manage, process and store data.
“Even if you were thinking about your own organization's cybersecurity program, you might not be thinking big enough,” Silver said. “Hacks on third-party vendors can be just as devastating as hacks on the companies themselves.”
Silvers, who served as the assistant secretary for cyber policy in the Department of Homeland Security during the Obama administration, also said that China's violating the 2015 bilateral agreement should be of concern for companies. The agreement was supposed to mean that neither government would support the cyber espionage of corporations.
“That agreement was meant to protect companies,” Silvers explained. “This literally puts tens of billions of dollars of intellectual property at risk.
China generally has denied the accusations.
The 23-page indictment claims Zhu and Zhang belonged to a hacking organization based in China known to the cybersecurity community as Advanced Persistent Threat 10, or APT10 group, and by other names. They allegedly worked for a company called Huaying Haitai Science and Technology Development Company and in association with the Chinese Ministry of State Security's Tianjin State Security Bureau, an intelligence organization.
The indictment claims that starting in 2006 or earlier, the defendants stole sensitive defense technology and trade secrets, among other information, from the managed service providers—other companies used to store and process commercial data—of more than 45 companies in the United States as well as from U.S. government agencies including NASA and the Jet Propulsion Laboratories. None of the companies were named in the indictment.
A wide range of industries and business were compromised, including aviation, factory automation, financial services and banking, telecommunications, biotechnology, health care, pharmaceutical manufacturing, energy exploration and production and many more. The Justice Department said Zhu and Zhang “registered IT infrastructure that the APT10 Group used for its intrusions and engaged in illegal hacking operations.”
The attacks included spear-phishing attacks on a helicopter manufacturer that originated from an IP address in Tianjin, China under the control of the APT10 group. The emails, when opened, installed keystroke-logging malware on the computers that was used to steal usernames and passwords that in turn were used to help exfiltrate files and information in encrypted archives, the indictment said.
The hacking group also allegedly broke into more than 40 computers and obtained sensitive personal data from more than 100,000 U.S. Navy personnel, including Social Security numbers, email addresses and phone numbers, according to the indictment.
The APT10 organization also gained access to computers in a least 12 countries, the indictment claims, including Brazil, Canada, Finland, France, Germany, India, Japan, Sweden, Switzerland, the United Arab Emirates, the United Kingdom and as the United States.
Zhu and Zhang, who are unlikely to ever face trial in the United States, are each charged with one count of conspiracy to commit computer intrusions, which carries a maximum sentence of five years in prison; a single count of conspiracy to commit wire fraud, which carries a maximum sentence of 20 years; and one count of aggravated identity theft, which carries a mandatory sentence of two years in prison.
The indictment comes as the DOJ steps up efforts to crack down on alleged economic espionage. “In the last few months of this year, our Department has announced charges in three cases alleging crimes committed at the behest of a branch of the Chinese Ministry of State Security,” Rosenstein said in a statement. He said 90 percent of its economic espionage cases in the last seven years have involved China.
Assistant U.S. Attorney Sagar K. Ravi of the Southern District of New York's cybercrime unit is in charge of the prosecution. Trial attorney Matthew Chang of the National Security Division's counterintelligence and export control section is assisting, according to a news release.
|Read more:
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllGoogle Fails to Secure Long-Term Stay of Order Requiring It to Open App Store to Rivals
'Am I Spending Time in the Right Place?' SPX Technologies CLO Cherée Johnson on Living and Leading With Intent
9 minute read'It Was the Next Graduation': How an In-House Lawyer Became a Serial Entrepreneur
9 minute readRenee Meisel, GC of UnitedLex, on Understanding and Growing the Business
6 minute readTrending Stories
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250