Countries such as the UK, along with Taiwan, India, Indonesia, Nigeria are discovered to have been implicated in global surveillance operations following a massive data leak originating from a Chinese cybersecurity vendor called I-Soon.
The leaked information, which is made up of around 190 megabytes of data, was recently discovered on GitHub.
The information offers a glimpse into China’s state-sponsored cyber apparatus, as I-Soon is a Shanghai-based company believed to be one of numerous private contractors assisting the government in intelligence gathering, hacking, and surveillance gathering.
“They are part of an ecosystem of contractors that has links to the Chinese patriotic hacking scene, which developed two decades ago and has since gone legit,” said John Hultquist, chief analyst at Google’s Mandiant Intelligence to the New York Times.
In response to the allegations, Chinese authorities have denied any knowledge of the data leak. Mao Ning, a spokesperson for the Chinese Ministry of Foreign Affairs, asserted during a press briefing that she was unaware of any data leak from I-Soon.
“As a matter of principle, China firmly opposes and cracks down on all forms of cyber-attacks in accordance with the law,” Mao stated
Data discovered on GitHub include emails, conversations, images, and a number of documents detailing contracts and communications between I-Soon and Chinese authorities, and thought by cyber experts to be genuine. The cache of more than 500 leaked files discuss targets such as Nato and the UK Foreign Office
Recommended reading
- NCSC Issues Joint Warning About Chinese Cyber Threats
- Chinese-owned App TikTok Banned on UK Government Phones
- LockBit Leaks MoD Contractor Data In “Sophisticated Cyber-Attack”
Analysis of the documents by cybersecurity experts indicate a systematic campaign that spanned around eight years, with targets in at least 20 foreign governments. One example being 95 gigabytes of immigration data from India, and 3 terabytes of call logs from South Korea’s LG U Plus telecoms provider.
According to an assessment from SentinelOne, I-Soon utilises an array of hacking tools to gather intelligence, including methods to unearth identities on social media platforms and access emails, despite platforms like Facebook being inaccessible in China. Of particular concern are I-Soon’s sophisticated Remote Access Trojans (RATs) capable of infiltrating major operating systems, including Linux, Windows, macOS, iOS, and Android.
Most alarming is the revelation regarding the Android attack code, allegedly capable of extracting extensive messaging histories from Chinese chat applications and Telegram. The leaked documents also outline the use of hardware hacking devices by I-Soon, including a malicious power bank designed to surreptitiously upload data into victims’ systems.





