What do we know about China's global cyber operations?
A tranche of leaked documents offers new insight into Beijing's sprawling mercenary hacking operation

Throughout much of former President Donald Trump's administration, national attention was focused on various allegations, insinuations, and affirmations of massive Russian hacking efforts to penetrate and influence various American cyber targets. For many, it was their first real exposure to the shadowy, clandestine world of cyber warfare that has become a major pillar of geopolitical jockeying. But while Russia and its digital sorties may have grabbed headlines over the past decade or so, a tranche of newly leaked files from Shanghai-based data collection firm iSoon has opened a rare window into China's massive cyber warfare operations. The leak, posted this month to GitHub, not only raises questions about Beijing's sprawling digital capacity but also highlights the intricate network of for-hire hackers China allegedly uses to expand its reach throughout the world — and snoop on its own citizens.
While the exact source of the leak remains at the moment unknown, the nearly 600 documents that comprise this breach have been widely verified as legitimate by numerous cybersecurity experts. Although the tranche does not include much in the way of specific data harvested by the Chinese hackers, it does illuminate the otherwise murky contours of who Beijing is watching, and who it's paying to watch.
Based on these new documents, here's what we know about China's global cyber operations.
Subscribe to The Week
Escape your echo chamber. Get the facts behind the news, plus analysis from multiple perspectives.

Sign up for The Week's Free Newsletters
From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.
From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.
What did the commentators say?
The leak is an "unprecedented look" inside just one of the many companies the Chinese government contracts with for its "on-demand, mass data-collecting operations," The Washington Post said. It's rare to get "such unfettered access to the inner workings of any intelligence operation," cybersecurity expert John Hultquist said to the paper. While the documents are light on what iSoon uncovered throughout its investigations, it does feature "contracts, marketing presentations, product manuals, and client and employee lists," PBS News Hour said, adding that in total the leak shows how Chinese intelligence agencies "surveil dissidents overseas, hack other nations and promote pro-Beijing narratives on social media."
The leak exposes an eight-year-long data gathering operation that reached across Asia, including into India, Taiwan, Malaysia, and Hong Kong, as well as monitoring "activities of ethnic minorities in China and online gambling companies," said The New York Times.
The leak also highlights the "maturing nature of China's cyber espionage ecosystem," in which "government targeting requirements drive a competitive marketplace" for third-party hackers, information security analysts at Sentinel Labs said. The documents show an "ecosystem of contractors that has links to the Chinese patriotic hacking scene, which developed two decades ago and has since gone legit," Hultquist said in a separate interview with the Times.
In addition to targets and client agencies, the leaked documents also show some of the methodology used by hired hacking firms to conduct their espionage. Beyond unmasking users on social media, breaking into various communications accounts, and covering their investigatory tracks, hackers as described in the documents also utilized "devices disguised as power strips and batteries that can be used to compromise Wi-Fi networks," The Associated Press said.
What next?
The fallout from these leaked documents comes amid heightened tensions between the United States and China. This week FBI Director Chris Wray lashed out at an alleged Chinese effort to plant malware in various pieces of American infrastructure as operating on a "scale greater than we'd seen before."
"It's the tip of the iceberg," Wray added during an appearance at the Munich Security Conference. "One of many such efforts by the Chinese." In October, Wray called Chinese cyber operations the "biggest hacking program in the world by far, bigger than ever other major nation combined" in an interview with CBS News.
China, meanwhile, continues to outsource cybersecurity operations to a "large network of actors competing to exploit vulnerabilities and grow their businesses" with lucrative government contracts, said the Post.
Chinese officials are actively investigating the source of the iSoon leak, said AP. While the documents were first discovered by a "Taiwanese threat intel technical analyst who wasn't sure of the source" they could have come from "a disgruntled employee of iSoon, or even one of the characters mentioned in the chats" former FBI Cyber investigator Adam Kozy told SpyTalk.
Sign up for Today's Best Articles in your inbox
A free daily email with the biggest news stories of the day – and the best features from TheWeek.com
Rafi Schwartz has worked as a politics writer at The Week since 2022, where he covers elections, Congress and the White House. He was previously a contributing writer with Mic focusing largely on politics, a senior writer with Splinter News, a staff writer for Fusion's news lab, and the managing editor of Heeb Magazine, a Jewish life and culture publication. Rafi's work has appeared in Rolling Stone, GOOD and The Forward, among others.
-
Who is actually running DOGE?
TODAY'S BIG QUESTION The White House said in a court filing that Elon Musk isn't the official head of Donald Trump's Department of Government Efficiency task force, raising questions about just who is overseeing DOGE's federal blitzkrieg
By Rafi Schwartz, The Week US Published
-
How does the Kennedy Center work?
The Explainer The D.C. institution has become a cultural touchstone. Why did Trump take over?
By Joel Mathis, The Week US Published
-
What are reciprocal tariffs?
The Explainer And will they fix America's trade deficit?
By Joel Mathis, The Week US Published
-
Who is actually running DOGE?
TODAY'S BIG QUESTION The White House said in a court filing that Elon Musk isn't the official head of Donald Trump's Department of Government Efficiency task force, raising questions about just who is overseeing DOGE's federal blitzkrieg
By Rafi Schwartz, The Week US Published
-
How will Keir Starmer pay for greater defence spending?
Today's Big Question Funding for courts, prisons, local government and the environment could all be at risk
By Sorcha Bradley, The Week UK Published
-
Will Trump lead to more or fewer nuclear weapons in the world?
Talking Points He wants denuclearization. But critics worry about proliferation.
By Joel Mathis, The Week US Published
-
'What Americans really need is access to safer products'
Instant Opinion Opinion, comment and editorials of the day
By Justin Klawans, The Week US Published
-
Why are Europe's leaders raising red flags about Trump's Ukraine overtures to Putin?
TODAY'S BIG QUESTION Officials from across the continent warn that any peace plan without their input is doomed from the start
By Rafi Schwartz, The Week US Published
-
A running list of Tulsi Gabbard's controversies
In Depth Trump's nominee for Director of National Intelligence has a history of ideological reversals
By David Faris Published
-
Modi goes to Washington
The Explainer Indian PM's 'clever' appeasement strategy could secure US president an ally against China and other Brics states
By The Week UK Published
-
Trump's wildest unfulfilled White House ideas
In Depth The President of the United States is not one to let material reality stand in the way of a sound-bite ready pie-in-the-sky proposal
By Rafi Schwartz, The Week US Last updated