Cyber-assault HQ: how US is under attack from this office in Shanghai

Online security firm traces breaches to building occupied by Chinese military

A barrage of malicious cyber-attacks against computer networks in the United States and other countries over several years has been sourced by a private US security firm to a single building on the fringes of Shanghai, which, it says, is occupied by the Chinese military.

A 60-page report released by Mandiant, a Virginia-based firm that specialises in cyber-espionage, concludes that hundreds or perhaps thousands of English-speaking Chinese computer experts toil daily inside the anonymous-looking 12-storey building in the Pudong district of Shanghai. ‘Unit 61398’, as it is known, hacks into foreign networks on behalf of the People’s Liberation Army (PLA), Mandiant alleges.

“The nature of Unit 61398’s work is considered by China to be a state secret; however, we believe it engages in harmful computer network operations,” the security firm said in the report, which drew instant rebukes from the Chinese government. “It is time to acknowledge the threat that is originating in China, and we wanted to do our part to arm and prepare security professionals to combat that threat effectively.”

The company asserted that the unit, one of several in China believed to be involved in invading overseas computer systems, had “stolen hundreds of terabytes of data from at least 141 organisations across a diverse set of industries beginning as early as 2006”.  While most of the activity targeted corporations in the United States are smaller number is located in Canada and Britain, it said.

Cyber-espionage is becoming an increasingly urgent worry in Washington.  The concern is not just that China, as well any number of other countries, is successfully stealing corporate information – for example merger plans, design blueprints, pricing documents or negotiating strategies – but that it is developing the capacity to sabotage physical infrastructure networks in the US like gas pipelines or power grids.

“In the cold war, we were focused every day on the nuclear command centres around Moscow,” one senior defence official was cited as saying by the New York Times, which first revealed the contents of the Mandiant report. “Today, it’s fair to say that we worry as much about the computer servers in Shanghai.”

President Barack Obama included a call to arms to confront the cyber-threat in his State of the Union address last week.  “We know foreign countries and companies swipe our corporate secrets,” he said. “Now our enemies are also seeking the ability to sabotage our power grid, our financial institutions, our air-traffic control systems. We cannot look back years from now and wonder why we did nothing.”

Beijing continues to deny sanctioning such activity. “Hacking attacks are transnational and anonymous,” foreign ministry spokesman Hong Lei said.  “Determining their origins are extremely difficult. We don’t know how the evidence in this so-called report can be tenable.” When BBC journalists approached the building they were briefly detained and forced to relinquish their footage.

Unit 61398 has been known both to private cyber-security firms as well as US intelligence for a while and is sometimes referred as the ‘Comment Crew’ because it has been known to infiltrate online forums and leave comments.  The Mandiant report does not name any victims but says that the 141 companies already infiltrated span 20 major industries.

American companies known to have been targeted by Comment Crew, however, include Coca Cola at a time when it was considering a take-over of a Chinese juice company and RSA, a technology company that creates computer codes to protect confidential corporate and government databases. Alarm bells sounded last September when a unit of Telvent which supplies equipment enabling utility companies remotely to operate valves and switches on gas and oil networks had been invaded by unidentified cyber-intruders.

Responding to the report, White House spokeswoman Caitlin Hayden reiterated only that the United States “has substantial and growing concerns about the threats to U.S. economic and national security posed by cyber intrusions, including the theft of commercial information.” 

The Mandiant report acknowledges that while it has traced assorted cyber-intrusions to servers precisely in the rather run-down district of Pudong where the building occupied by Unit 61398 stands, it cannot be certain they are actually within its walls.  But to suppose they are not is barely plausible, the firm says.

Start your day with The Independent, sign up for daily news emails
Have you tried new the Independent Digital Edition apps?
ebooks
ebooksAn introduction to the ground rules of British democracy
Latest stories from i100
Have you tried new the Independent Digital Edition apps?
Independent Dating
and  

By clicking 'Search' you
are agreeing to our
Terms of Use.

iJobs Job Widget
iJobs General

Recruitment Genius: Sales Administrator - Spanish Speaking

£17000 - £21000 per annum: Recruitment Genius: This is a fantastic opportunity...

Recruitment Genius: Sales Administrator - German Speaking

£17000 - £23000 per annum: Recruitment Genius: This is a fantastic opportunity...

Recruitment Genius: Sales Administrator - Japanese Speaking

£17000 - £23000 per annum: Recruitment Genius: If you are fluent in Japanese a...

Recruitment Genius: Graphic Designer - Immediate Start

£16000 - £25000 per annum: Recruitment Genius: This is a fantastic opportunity...

Day In a Page

Is this the future of flying: battery-powered planes made of plastic, and without flight decks?

Is this the future of flying?

Battery-powered planes made of plastic, and without flight decks
Isis are barbarians – but the Caliphate is a dream at the heart of all Muslim traditions

Isis are barbarians

but the Caliphate is an ancient Muslim ideal
The Brink's-Mat curse strikes again: three tons of stolen gold that brought only grief

Curse of Brink's Mat strikes again

Death of John 'Goldfinger' Palmer the latest killing related to 1983 heist
Greece debt crisis: 'The ministers talk to us about miracles' – why Greeks are cynical ahead of the bailout referendum

'The ministers talk to us about miracles'

Why Greeks are cynical ahead of the bailout referendum
Call of the wild: How science is learning to decode the way animals communicate

Call of the wild

How science is learning to decode the way animals communicate
Greece debt crisis: What happened to democracy when it’s a case of 'Vote Yes or else'?

'The economic collapse has happened. What is at risk now is democracy...'

If it doesn’t work in Europe, how is it supposed to work in India or the Middle East, asks Robert Fisk
The science of swearing: What lies behind the use of four-letter words?

The science of swearing

What lies behind the use of four-letter words?
The Real Stories of Migrant Britain: Clive fled from Zimbabwe - now it won't have him back

The Real Stories of Migrant Britain

Clive fled from Zimbabwe - now it won’t have him back
Africa on the menu: Three foodie friends want to popularise dishes from the continent

Africa on the menu

Three foodie friends want to popularise dishes from the hot new continent
Donna Karan is stepping down after 30 years - so who will fill the DKNY creator's boots?

Who will fill Donna Karan's boots?

The designer is stepping down as Chief Designer of DKNY after 30 years. Alexander Fury looks back at the career of 'America's Chanel'
10 best statement lightbulbs

10 best statement lightbulbs

Dare to bare with some out-of-the-ordinary illumination
Wimbledon 2015: Heather Watson - 'I had Serena's poster on my wall – now I'm playing her'

Heather Watson: 'I had Serena's poster on my wall – now I'm playing her'

Briton pumped up for dream meeting with world No 1
Wimbledon 2015: Nick Bollettieri - It's time for big John Isner to produce the goods to go with his thumping serve

Nick Bollettieri's Wimbledon Files

It's time for big John Isner to produce the goods to go with his thumping serve
Dustin Brown: Who is the tennis player who knocked Rafael Nadal out of Wimbeldon 2015?

Dustin Brown

Who is the German player that knocked Nadal out of Wimbeldon 2015?
Ashes 2015: Damien Martyn - 'England are fired up again, just like in 2005...'

Damien Martyn: 'England are fired up again, just like in 2005...'

Australian veteran of that Ashes series, believes the hosts' may become unstoppable if they win the first Test