Former headquarters of Google China in Beijing

Chinese hackers attacked Gmail Google claims

Suspected Chinese hackers tried to steal the passwords of hundreds of Google email account holders, Google claims.

The world's top search engine Google said this included details of senior U.S. government officials, Chinese activists and journalists.

Beijing has responded angrily and said blaming China was "unacceptable", threatening to increase tensions in an already strained relationship with Google.

The perpetrators appeared to originate from Jinan, the capital of China's eastern Shandong province, Google said.

Jinan is home to one of six technical reconnaissance bureaus belonging to the People's Liberation Army and a technical college U.S. investigators last year linked to a previous attack on Google.

Google's claims are being investigated by Washington while the FBI said it was working with Google following the attacks.

Governments need to pay more attention to hacking wherever it originates from, said Andrew Davies of the Australian Strategic Policy Institute, an independent security and defence think tank.

"I think there has been a certain lack of appreciation of the looming threat around the world," he said.

"It's been hard to wake up western governments to the magnitude of the threat."

The hackers recently tried to crack and monitor email accounts by stealing passwords, but Google detected and "disrupted" their campaign, and has notified the victims.

The revelation comes more than a year after Google disclosed a cyberattack on its systems that it said it traced to China.

Google partially pulled out of China, the world's largest internet market with 450 million users, last year after a dispute with the government over censorship and a serious hacking episode.

"We recently uncovered a campaign to collect user passwords, likely through phishing," Google said, referring to the practice where computer users are tricked into giving up sensitive information.

"The goal of this effort seems to have been to monitor the contents of these users' emails."

The personal Gmail accounts of hundreds of users were affected, including senior U.S. government officials, Chinese political activists, officials in several Asian countries (predominantly South Korea), military personnel and journalists.

A Washington-based security expert, Mila Parkour, first reported the Gmail attacks on her blog in February, saying they appeared to have started last year and were invasive.

China's Foreign Ministry said it "cannot accept" accusations hackers in China tried to break into hundreds of Gmail accounts.

Google did not say the Chinese government was behind the attacks or say what might have motivated them.

However cyberattacks originating in China have become common in recent years, said Bruce Schneier, chief security technology officer at telecommunications company BT.

"It's not just the Chinese government. It's independent actors within China who are working with the tacit approval of the government," he said.

The United States has warned that a cyberattack - presumably if it is devastating enough - could result in real-world military retaliation, although analysts say it could be difficult to detect its origin with full accuracy.

Lockheed Martin, the U.S. government's top information technology provider, said last week it had thwarted "a significant and tenacious attack" on its information systems network, though the company and government officials have not yet said where they think the attack originated.

"We have no reason to believe that any official U.S. government email accounts were accessed," said White House spokesman Tommy Vietor.

A spokesman at South Korea's presidential office said the Blue House had not been affected, but added they did not use Gmail. 

South Korea's Ministry of Strategy and Finance said it had warned all staff "not to use, send or receive any official information through private emails such as Gmail."

Technical reconnaissance bureaus, including the one in Jinan, oversee China's electronic eavesdropping, according to an October 2009 report by the U.S.-China Economic and Security Commission, a panel created by Congress to monitor potential national security issues related to U.S.-China relations.

The bureaus "are likely focused on defense or exploitation of foreign networks", the commission report states.

U.S. investigators said last year there was evidence suggesting a link between the Lanxiang Vocational School in Jinan and the hacking attacks on Google and over 20 other firms, which was denied by the school.

"Blaming these misdeeds on China is unacceptable," Chinese Foreign Ministry spokesman Hong Lei said.

"Hacking is an international problem and China is also a victim. The claims of so-called Chinese state support for hacking are completely fictitious and have ulterior motives."

China has said repeatedly it does not condone hacking, which remains a popular hobby in the country, with numerous websites offering cheap courses to learn the basics.

Three Chinese dissidents told Reuters their accounts had been infiltrated, although eight others who were contacted said they had no problems.

Google's security team on Thursday sent an email to dissident Jiang Qisheng, who was a student negotiator jailed for years for his role in the 1989 pro-democracy protests in Tiananmen Square, that it "recently detected suspicious activity" on his account.

"The suspicious activity appears to have originated in China as an attempt to establish and maintain access to your account without your knowledge," said the email.

Cui Weiping, a professor at the Beijing Film Academy who has called for ending the official silence about the Tiananmen crackdown, said she could not open her Gmail account this morning and believed it had been hacked into.

While Google said last year's attack was aimed at its corporate infrastructure, the latest incident appears to have relied on tricking email users into revealing passwords, based on Google's description in its blog post.

It said the perpetrators changed the victims' email forwarding settings, presumably secretly sending the victims' personal emails to other recipients.

In Parkour's blog, screenshots show a highly personalised message and a document for the recipient to download. The analyst managed to trace some of these examples back to the China Unicom Shandong province network in Jinan.

The events leading to Google's withdrawal from China exacerbated an often difficult relationship between Washington and Beijing, with disputes ranging from human rights to trade.

Google announced last year it was the target of a sophisticated cyberattack using malicious code dubbed "Aurora", which compromised the Gmail accounts of human rights activists and succeeded in accessing Google source code repositories.

The company, and subsequent public reports, blamed the attack on the Chinese government.

"We'll certainly see more of this in the future, as Chinese hackers target Google because of its global popularity and its decision to defy the Chinese government on censorship, which some hackers will misconstrue as being anti-Chinese," said Michael Clendenin, managing director of RedTech Advisors, a technology consulting firm.

Recent articles

Info Message

Our sites use cookies to support some functionality, and to collect anonymous user data.

Learn more about IET cookies and how to control them

Close