Beijing-linked hackers ‘tried to steal’ coronavirus vaccine data

US charges two men accused of targeting drug companies during global cybertheft campaign

Coronavirus vaccine
(Image credit: Pedro Vilela/Getty Images)

Two Chinese men linked to Beijing’s intelligence service targeted vaccine development research during a six-year cybertheft campaign in which trade secrets worth hundreds of millions of dollars were hacked, US prosecutors claim.

Li Xiaoyu, 34, and Dong Jiazhi, 33, are alleged to have stolen data from a wide range of technology companies in countries across the world, including one unnamed “UK artificial intelligence and cancer research firm”, The Times reports.

Subscribe to The Week

Escape your echo chamber. Get the facts behind the news, plus analysis from multiple perspectives.

SUBSCRIBE & SAVE
https://cdn.mos.cms.futurecdn.net/flexiimages/jacafc5zvs1692883516.jpg

Sign up for The Week's Free Newsletters

From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.

From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.

Sign up

Having previously stolen information about “other Chinese intelligence targets like human rights activists”, the duo shifted their focus to trying to steal coronavirus vaccine research this year, the newspaper reports. It is not clear whether the Covid-related hacking was successful.

According to the DOJ indictment, when “they were stealing information of obvious interest” to the Chinese government, the hackers “were assisted by, and operated with the acquiescence of” the Ministry of State Security (MSS), China’s intelligence agency.

The indictment lists 11 criminal charges against Li and Dong, including conspiracies to commit computer fraud and theft, as well as multiple counts of aggravated identity theft.

According to The Times, the hackers “would often find a way into a network by looking for flaws in software products, especially vulnerabilities that had just been announced and for which most businesses had not had time to install an update to fix”.

Computer security expert Alan Woodward, a visiting professor at Surrey University’s Cyber Security Centre, told the paper that the aim with such a strategy is to “establish a toe hold using one of these vulnerabilities and then directly access data or establish a shell which provides you with your own direct access to the system”.

Announcing the charges against the two Chinese men, US Assistant Attorney General John Demers said that “China has now taken its place, alongside Russia, Iran and North Korea, in that shameful club of nations that provide a safe haven for cybercriminals in exchange for those criminals being ‘on call’ to work for the benefit of the state”, reports Al Jazeera.

The goal for Li and Dong was “to feed the Chinese Communist Party’s insatiable hunger for American and other non-Chinese companies’s hard-earned intellectual property, including Covid-19 research”, added Demers, who leads the DOJ’s National Security Division.

Joe Evans is the world news editor at TheWeek.co.uk. He joined the team in 2019 and held roles including deputy news editor and acting news editor before moving into his current position in early 2021. He is a regular panellist on The Week Unwrapped podcast, discussing politics and foreign affairs. 

Before joining The Week, he worked as a freelance journalist covering the UK and Ireland for German newspapers and magazines. A series of features on Brexit and the Irish border got him nominated for the Hostwriter Prize in 2019. Prior to settling down in London, he lived and worked in Cambodia, where he ran communications for a non-governmental organisation and worked as a journalist covering Southeast Asia. He has a master’s degree in journalism from City, University of London, and before that studied English Literature at the University of Manchester.