- From the BBC Verify Team and Global China Unit
- bbc news
A Chinese cybersecurity company claimed to have the ability to hack the UK Foreign Office, according to leaked documents.
British government agencies, think tanks, businesses and charities are also included in the leaked i-Soon data.
Other documents suggest successful hacks of public institutions and businesses across Asia and Europe, although it is not yet clear whether any were compromised.
The identity of the leaker is unknown.
The British embassy in China said it was unaware of the leak and said China “resolutely opposes and combats all forms of cyber-attacks in accordance with the law.”
However, Chinese police and i-Soon are reportedly investigating the data dump, according to the Associated Press.
The BBC has contacted the British government for comment.
the leak seems real
i-Soon is one of many private companies providing cybersecurity services to China’s military, police and security agencies.
The Shanghai headquarters has fewer than 25 employees.
A collection of 577 documents and chat logs was leaked on GitHub, an online developer platform, on February 16th.
Three security researchers told the BBC that the breach appeared to be genuine.
These files reveal eight years of work by i-Soon to extract data and access systems in the United Kingdom, France, and several countries in Asia, including Taiwan, Pakistan, Malaysia, and Singapore. .
In one case, a government agency in southwest China paid around $15,000 (£11,900) to access the Vietnam Traffic Police website.
In another case, software to run a disinformation campaign on X (formerly Twitter) cost $100,000 (£79,000).
“Boss Lu”
Undated chat logs between “Boss Lu” and another anonymous user reveal that the British Foreign Office is i-Soon’s preferred target.
Anonymous participants said they were accessing vulnerabilities in Ministry of Foreign Affairs software. However, his boss Lou tells him to focus on another organization because a rival contractor has won the job.
In another chat log, a user sends i-Soon a list of UK targets, including the UK Treasury, Chatham House, and Amnesty International.
“I don’t have this, but I can work with it,” says the recipient.
The two then discuss an advance payment from the client for unspecified information about the target.
Other chat logs show i-Soon staff discussing a deal involving NATO Secretary General Jens Stoltenberg.
Unusual interior view
John Hultquist, principal analyst at Mandiant Intelligence, said the breach could provide rare inside information about “high-stakes intelligence operations for commercial purposes.”
The data shows how contractors are serving “not just one agency, but multiple agencies at once,” he added.
Experts say there could be many motives behind the data breach.
It could be a malicious leak by a disgruntled former employee, a foreign intelligence agency, or a competitor to undermine i-Soon’s public credibility.
The mechanics of China’s cyber espionage operations have been widely reported, but this leak sheds light on the unusual ways in which the private sector engages in these operations.
Dakota Carey, a non-resident researcher at the Atlantic Council’s Global China Hub, said it’s unlikely Chinese authorities will make public their findings.
Reporting by Joshua Cheetham, Daniele Palumbo and Gordon Corera
