German gov summons China ambassador to complain about attack from 'state-controlled Chinese cyber criminals'
China's obfuscation networks didn't obfuscate enough.
Germany’s Federal Foreign Office in Berlin has summoned the Chinese ambassador over a cyberattack that targeted the Federal Agency for Cartography and Geodesy (BKG) in 2021. A spokesperson for the Foreign Office bluntly declared, “Today, we know that state-controlled Chinese cyber actors have infiltrated the BKG’s network for espionage purposes,” reports Germany's Zeit newspaper.
The BKG is Germany’s agency that deals with mapping and geodata for the entire country. Aside from producing original data, it also works with other government and private sources to provide a comprehensive and up-to-date geographical map of Germany. Although mapping data is readily available on Google Maps and can also be captured by satellites, up-to-date information including the location of government offices, demographics, and other collected are crucial for state security. Furthermore, other critical infrastructure providers rely on BKG data as well, including energy, water supply and treatment, and transportation companies.
It is exactly for this reason that China scrambles its GPS data — if you look at Google Maps and turn on satellite view in Chinese locations, you’ll notice that the road markings do not line up with the satellite images.
The Chinese cyber espionage attack was discovered after a “thorough technical analysis” with assistance from the intelligence community. According to the investigation, the attack was routed through compromised devices used by individuals and companies to obfuscate its source. “This serious cyberattack on a federal agency shows how great the danger of Chinese cyberattacks and espionage is,” says Federal Interior Minister Nancy Faeser.
The threat of cyberattacks, whether for profit or statecraft, has never been more significant. Because of this, the German cabinet passed a draft law that required large organizations in crucial industries, like communications, energy, transportation, and water works, to implement the European NIS 2 Directive. This law will affect almost 30,000 corporations when passed, which shows how vulnerable the entire system could be.
Aside from the successful Chinese intrusion on the BKG network, the German government noted that there were several cyberattacks on IT service providers that work with government contracts, although it did not indicate if these attacks came from one party alone. After all, the German Office for the Protection of the Constitution says that there are three other main players in espionage acts against Germany aside from China. These countries include Russia, Iran, and, notably, Turkey, which is also a NATO member.
Nevertheless, the Federal Ministry of the Interior said that China is pursuing an “offensive cyber strategy that is intended to make an important contribution to the country’s industrial and geopolitical goals through extensive knowledge transfer.” Whether the recent summoning and official protestations to the Chinese ambassador in Germany will make much difference, remains to be seen. However, it may be good to put this incident on official diplomatic records.
Stay On the Cutting Edge: Get the Tom's Hardware Newsletter
Get Tom's Hardware's best news and in-depth reviews, straight to your inbox.
Jowi Morales is a tech enthusiast with years of experience working in the industry. He’s been writing with several tech publications since 2021, where he’s been interested in tech hardware and consumer electronics.
-
zsydeepsky just for journalism's sake, you'd better attach the statement from the other side when reporting an accusation. Writers can attach whatever their opinions are after that, and readers can choose whatever they want to believe, but unilateral reporting is just bad practice.Reply
so I did a quick search on Twitter, here's China's response:
China rejects the German government’s “Chinese cyberattack” accusation. There have been enough unsubstantiated, unverified & deliberately made-up stories to call China a cyber threat. Time to stop this disinformation campaign. -
pug_s
This article is a joke. It says:jp7189 said:Funny how you're so fast to respond to every article about China with a determined pro China spin. In fact, you don't comment on any other articles. It's almost like it's your job...
"The Chinese cyber espionage attack was discovered after a “thorough technical analysis” with assistance from the intelligence community. According to the investigation, the attack was routed through compromised devices used by individuals and companies to obfuscate its source. "
The 'technical analysis' didn't even mention who, and where the attack is coming from a Chinese origin? For all we know, some CIA spook planted some flase flag to hack Germany using compromised computers with an Chinese ip address. -
COLGeek Folks, stay on topic or be silent. No personal attacks or insults.Reply
If you feel something warrants a report, please do so and the moderation team will assess.
Thank you.