RSS Amplifier

HUMINT · Jul 21, 2026

Inside China's cyber espionage business

0
Sign in to vote or save

Sasha Ingber · HUMINT

Ahana Datta Fasel became the British government’s first ethical hacker in 2014, testing vulnerabilities in computer systems and networks which hackers could potentially exploit. She was only 23.

But that gave her an early look at state-sponsored cyber intrusions, which have grown only more serious and sophisticated. Her book, Full Stack Spies: Cyber Espionage in the Age of U.S.–China Competition, explores China’s ecosystem of spying online.

She joined me from London to talk about the competition, vanities, and betrayals between hackers, tech companies, and the government… through leaks and some of Beijing’s most destructive military and civilian cyber operations.

Ahana, a self-described “inveterate scroller,” started investigating a company called I-Soon after its data leaked in 2024. The company compromised healthcare firms in the U.S. and areas in the South China Sea — though none of their cyber weaponry or capabilities were leaked.

These were group chats that spanned nearly five years, a “painting of continuous dissatisfaction internally.” Ahana was interested in how the company culture evolved, staff’s patterns of life, their vulnerabilities and alliances. The chatroom consisted of the CEO, whose hacker name was “Shutdown,” a man full of energy and opportunism. He was bragging about who he was having dinner with. In contrast was his COO, a “constant worrywort… worrying about everything from the kind of quality of wine at office parties to how do they get their next contract.”

Ahana said what stood out to her was how little they actually discussed hacking, despite their work with China’s Ministry of State Security and People’s Liberation Army. “Their primary worry is, in this order, drinking, girls, and how they’re going to afford the infrastructure for all their ambitions,” she said.

How good were they really, if that was their version of Maslow’s hierarchy of needs? “These are young men who are in their first or second jobs, so straight out of university,” she said. “It is almost exclusively young men who are in this slightly one-upmanship state-of-mind where yes, of course, their ability technically and their respect of their peers is highly prized, but even more than that is, are they cool?”

When the Justice Department shut down another hacker group, Advanced Persistent Threat 41, Shutdown the CEO joked, “‘We'll invite them to drink 41 glasses of wine,’” Ahana said. Then they hired those hackers and argued internally about non-competes, who gets to use what malware.

Understanding the human aspect of these Chinese hackers is important. “If a hacker group is guided by vanity … and aren't prizing the sophistication in their tradecraft, then that is a vulnerability that, for example, counterintelligence analysts in the U.S. can find useful,” she told me.

Tradecraft takes a backseat to guanxi, Ahana added. Guanxi is an informal Chinese relationship built around hierarchy, patronage, and deference rather than strict reciprocity, she said. Junior members build goodwill with a senior person. “That is how, historically, government officials and military personnel have been promoted. But that is also how these hacker teams or these front companies have continued to receive their state sponsorship or their patronage from within the government. So long as they’re currying enough favor with government officials, they will somewhat be taken care of, because their government work isn't exactly high-paying.”

We also discussed Volt Typhoon, which she said showed the PLA’s ability to be able to introduce and prioritize stealth into its operations, as well as the Ministry of State Security’s Salt Typhoon attack on U.S. telecommunications.

She said there is no consensus on how hackers gained access but that Salt Typhoon is “simply the latest in a long trajectory of supply chain compromises of infrastructure attacks that the Ministry of State Security has done again and again and again.” Ahana went on to say that “it wouldn't be surprising at all that Salt Typhoon is in fact not one group, but a collection of different hacker collectives.”

Where might Chinese cyber warfare be going with AI, after China’s state-sponsored hackers in 2025 exploited Anthropic’s AI to automate cyberattacks? “The real game changer is the time element,” Ahana said, “both for defenders and offensive actors.” How long it takes a cyber actor to breach a system, to how long it takes them to carry out the work, to when they are detected and repelled.

Episode length: 37 minutes

Listen: On Spotify | On Apple Podcasts

Upgrade to support me

Read the original on sashaingber.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.