U.S. and allies accuse China of global hacking spree

By Steve Holland and Doina Chiacu

WASHINGTON (Reuters) – The United States and its allies accused China on Monday of a global cyberespionage campaign, mustering an unusually broad coalition of countries to publicly call out Beijing for hacking.

The United States was joined by NATO, the European Union, Britain, Australia, Japan, New Zealand and Canada in condemning the spying, which U.S. Secretary of State Antony Blinken said posed “a major threat to our economic and national security.”

Simultaneously, the U.S. Department of Justice charged four Chinese nationals – three security officials and one contract hacker – with targeting dozens of companies, universities and government agencies in the United States and abroad.

The Chinese Embassy in Washington did not immediately respond to a request for comment. Chinese officials have previously said China is also a victim of hacking and opposes all forms of cyberattacks.

While a flurry of statements from Western powers represent a broad alliance, cyber experts said the lack of consequences for China beyond the U.S. indictment was conspicuous. Just a month ago, summit statements by G7 and NATO warned China and said it posed threats to the international order.

Adam Segal, a cybersecurity expert at the Council on Foreign Relations in New York, called Monday’s announcement a “successful effort to get friends and allies to attribute the action to Beijing, but not very useful without any concrete follow-up.”

Some of Monday’s statements even seemed to pull their punches. While Washington and its close allies such as the United Kingdom and Canada held the Chinese state directly responsible for the hacking, others were more circumspect.

NATO merely said that its members “acknowledge” the allegations being leveled against Beijing by the U.S., Canada, and the UK. The European Union said it was urging Chinese officials to rein in “malicious cyber activities undertaken from its territory” – a statement that left open the possibility that the Chinese government was itself innocent of directing the espionage.

The United States was much more specific, formally attributing intrusions such as the one that affected servers running Microsoft Exchange earlier this year to hackers affiliated with China’s Ministry of State Security. Microsoft had already blamed China.

U.S. officials said the scope and scale of hacking attributed to China has surprised them, along with China’s use of “criminal contract hackers.”

“The PRC’s Ministry of State Security (MSS) has fostered an ecosystem of criminal contract hackers who carry out both state-sponsored activities and cybercrime for their own financial gain,” Blinken said.

U.S. security and intelligence agencies outlined more than 50 techniques and procedures that “China state-sponsored actors” use against U.S. networks, a senior administration official said.

Washington in recent months has focused heavy attention on Russia in accusing Russian hackers of a string of ransomware attacks in the United States.

The senior administration official said U.S. concerns about Chinese cyber activities have been raised with senior Chinese officials. “We’re not ruling out further action to hold the PRC accountable,” the official said.

The United States and China have already been at loggerheads over trade, China’s military buildup, disputes about the South China Sea, a crackdown on democracy activists in Hong Kong and treatment of the Uyghurs in the Xinjiang region.

Blinken cited the Justice Department indictments as an example of how the United States will impose consequences.

The defendants and officials in the Hainan State Security Department, a regional state security office, tried to hide the Chinese government’s role in the information theft by using a front company, according to the indictment.

The campaign targeted trade secrets in industries including aviation, defense, education, government, health care, biopharmaceutical and maritime industries, the Justice Department said.

Victims were in Austria, Cambodia, Canada, Germany, Indonesia, Malaysia, Norway, Saudi Arabia, South Africa, Switzerland, the United Kingdom and the United States.

“These criminal charges once again highlight that China continues to use cyber-enabled attacks to steal what other countries make, in flagrant disregard of its bilateral and multilateral commitments,” Deputy U.S. Attorney General Lisa Monaco said in the statement.

(Reporting by Steve Holland, David Shepardson, Doina Chiacu and Lisa Lambert; Editing by Chizu Nomiyama and Grant McCool)