Silent Cyber Heist: Unmasking the Year-long Data Theft

A Chinese-linked hacking group, UNC6508, discreetly stole data from U.S. and Canadian academic, medical, and military research institutions over a year. They targeted defense intelligence and other sensitive information, exploiting REDCap software vulnerabilities. Google identified multiple affected organizations and notified them, but the Chinese Embassy denies any involvement.

Silent Cyber Heist: Unmasking the Year-long Data Theft
This image is AI-generated and does not depict any real-life event or location. It is a fictional representation created for illustrative purposes only.

In a covert cyber operation, a Chinese-associated hacking group targeted U.S. and Canadian academic, medical, and military research sectors for over a year, Google disclosed on Monday. The group sought sensitive information about defense intelligence, artificial intelligence, and medical research, operating from September 2023 until they were recently detected.

According to Google's Threat Intelligence Group, the hackers, known as UNC6508, focused on organizations with extensive research capabilities, spanning drug discovery to military readiness. Despite not naming the specific targets, Google underscored the financial and intellectual magnitude involved, indicating the campaign's scale and ambition.

Beijing denies involvement, but the hackers exploited REDCap software vulnerabilities to gain access and monitored strategic communications through email forwarding systems. Google has informed compromised institutions about the breach, which underscores an ongoing cyber challenge linked to Chinese interests.

Give Feedback

Use this form for editorial or site feedback. We usually reply within 2 to 3 working days.

By submitting, you agree that we may use your email address to respond.