Chinese Hackers Exploit Google Workspace to Access Sensitive Emails

A Chinese hacking group infiltrated North American research networks, stealing sensitive emails through Google Workspace manipulation.

3 min readCybersecurity

An espionage group linked to China has successfully infiltrated various North American medical, academic, and military research institutions over the course of more than a year. This group managed to extract sensitive emails related to research and defense by exploiting vulnerabilities in Google Workspace. The hackers gained entry by utilizing a backdoor on REDCap research servers, which allowed them to capture login credentials from their targets. What sets this attack apart is the method of data exfiltration; the attackers ingeniously modified the Google Workspace rules of the victims. By doing so, they were able to automatically duplicate and forward any email messages, effectively siphoning off sensitive information without raising immediate suspicion. This operation highlights the ongoing risks posed by state-sponsored cyber threats and the need for enhanced security measures within research and defense sectors.

Cybersecurity