Tens of thousands of Australian companies may have been compromised by the Chinese Regime’s cyber hacking campaign, one of Australia’s top cyber security advisor has warned.
The announcement comes amidst reports the Chinese Regime’s intelligence services hacked into the world’s biggest Managed Service Providers (MSPs) such as Hewlett Packard, IBM, and SAP (Systems Applications and Products).
Commercial secrets, client data, information related to human resources and account management are among the information likely to have been accessed.
“It’s the biggest and most audacious campaign I’ve seen,” said Alastair MacGibbon, head of the government’s Australian Cyber Security Centre. “This is massive in its scope and its scale. It’s breathtaking.”
Mining Companies Targeted
Mining companies in Western Australia have also been victims of the Chinese regime’s cyber hacking activities, and reportedly lost billions of dollars in revenue in the past decade.Data related to production levels at both big and small mining companies, were used by the Chinese regime’s state owned enterprises that buy Australian minerals, as leverage while negotiating contracts.
Codan chief executive Donald McGurk said the Australian Security Intelligence Organisation (ASIO) had informed him that an employee’s laptop had been hacked into by the Chinese regime.
International Condemnation
Countries such as Australia, New Zealand, Canada, the United Kingdom, United States, and Japan have publicly condemned China, following the indictment of two Chinese nationals, Zhu Hua and Zhang Jianguo, for a malicious global hacking campaign widely known as Cloud Hopper.Both Zhu and Zhang were part of the hacking group known as Advanced Persistent Threat 10, or APT10. The men had been involved in hacking operations with APT10 since 2006, according to the U.S. Justice Department.
Together with our allies, we are holding elements of the Chinese government responsible for an extensive cyber campaign targeting intellectual property and sensitive commercial data in Europe, Asia and the US.
? https://t.co/NsJ5z67mVQ pic.twitter.com/dE3k1uLyCi
Australian Foreign Affairs Minister Marise Payne described cyber attacks from APT10 as significant and undermined global economic growth, national security, and international stability.
https://twitter.com/MarisePayne/status/1075783915086827521
Advice to Companies Affected
According to the Australian Cyber Security Centre (ACSC), MSP customers should contact their responsible MSPs to ensure they are doing everything necessary to investigate whether they have been compromised and what effect it has had.- implementing best practice cyber security guidance
- regularly assessing customer cyber security posture
- protecting access to customer systems
- protecting users from socially engineered emails
- backing up customer data
- prepared for and actively reporting cyber security incidents