Pages

23 October 2015

Chinese HUMINT Spying in U.S. and Elsewhere Continues Unabated

October 21, 2015

Intelligence: Cocky, Sloppy, Fearless And Unstoppable

In early October 2015 a Chinese businessman (Xiwen Huang) was indicted in the United States for stealing trade secrets from American companies as well as the U.S. government over a ten year period. Huang was caught in part because he and Chinese firms are becoming bolder in how they exploit stolen software, trade secrets and other technology. Often Chinese will describe their espionage feats in print (almost always in Chinese only) and that is becoming more common. For example one of the most damaging pieces of evidence against was a detailed description of his activities Hwang sent home via email. He even gave this account a title; “Trip of Dream Realization” apparently with the intention of later expanding it into a magazine article or book. The article was also a detailed confession of theft of trade secrets and other intellectual property between 2004 and 2014. Huang was arrested in May 2015 on one of his trips back to the United States from his new home (and job) in China. 

Since 2012 most American officials have come to openly admit that a whole lot of American military and commercial technical data has been stolen via Chinese Internet espionage efforts as well as more conventional methods like Huang used. The Americans are not providing details of exactly how they collected all the evidence, but apparently it is pretty convincing for many American politicians and senior officials who had previously been skeptical. 

It’s no secret that Chinese intelligence collecting efforts since the late 1990s have been spectacularly successful. As the rest of the world comes to realize the extent of this success, there is a building desire for retaliation. What form that payback will take remains to be seen. Collecting information, both military and commercial, often means breaking laws and hacking back at the suspected attackers will involve even more felonies. China has broken a lot of laws. Technically, China has committed acts of war because of the degree to which it penetrated military networks and carried away copies of highly secret material. The U.S., and many other victims, has been warning China there will be consequences. As the extent of Chinese espionage becomes known and understood, the call for “consequences” becomes louder. 

China has always tried to conceal its espionage efforts. Not just denying anything and everything connected to its hacking and conventional spying but also by taking precautions. But as their success continued year after year, some of the Chinese hackers and spies became cocky and sloppy. At the same time, the victims became more adept at detecting Chinese efforts and tracing them back to specific Chinese government organizations or non-government hackers inside China. 

Undeterred, China has sought to keep its espionage effort going and has even expanded operations. For example, since 2008 China has opened National Intelligence Colleges in many major universities. In effect, each of these is an “Espionage Department” where, each year, several hundred carefully selected applicants are accepted in each school, to be trained as spies and intelligence operatives. China has found that espionage is an enormously profitable way to steal military and commercial secrets and rewards those who have talent and make a career of it. The Internet based operations, however, are only one part of China’s espionage efforts. 

While Chinese Cyber War operations in this area get a lot of publicity, the more conventional spying brings in a lot of stuff that is not reachable on the Internet. One indicator of this effort is the fact that American counter-intelligence efforts are snagging more Chinese spies. This is partly due to increased spying effort by China, as well as more success by the FBI and CIA. All this espionage, in all its forms, has played a large part in turning China into one of the mightiest industrial and military powers on the planet. China is having a hard time hiding the source of the new technologies they are incorporating into their weapons and commercial products. Many of the victims initially had a hard time accepting the fact that the oh-so-eager (to export) Chinese were robbing their best customers of intellectual property on a grand scale. Now Western firms are a lot more wary about dealing with the Chinese. 

China has been getting away with something the Soviet Union never accomplished, stealing Western technology and then using it to move ahead of the West. The Soviets lacked the many essential supporting industries found in the West (largely founded and run by entrepreneurs) and was never able to acquire all the many pieces needed to match Western technical accomplishments. Soviet copies of American computers, for example, were crude, less reliable, and less powerful. It was the same situation with their jet fighters, tanks, and warships. 

China gets around this by making it seemingly profitable for Western firms to set up factories in China, where Chinese managers and workers can be taught how to make things right. At the same time, China allows thousands of their best students to go to the United States to study. While many of these students will stay in America, where there are better jobs and more opportunities, some will come back to China and bring American business and technical skills with them. Finally, China energetically uses the “thousand grains of sand” approach to espionage. This involves China trying to get all Chinese going overseas, and those of Chinese ancestry living outside the motherland, to spy for China, if only a tiny bit. 

This approach to espionage is nothing new. Other nations have used similar systems for centuries. What is unusual is the scale of the Chinese effort, and that makes a difference. Supporting it all is a Chinese intelligence bureaucracy back home that is huge, with nearly 100,000 people working just to keep track of the many Chinese overseas and what they could, or should, be trying to grab for the motherland. This is where many of the graduates of the National Intelligence College program will work. 

It begins when Chinese intelligence officials examine who is going overseas and for what purpose. Chinese citizens cannot leave the country, legally, without the state security organizations being notified. The intel people are not being asked to give permission. They are being alerted in case they want to have a talk with students, tourists, or business people before they leave the country. Interviews are often held when these people come back as well. 

Those who might be coming in contact with useful information are asked to remember what they saw or bring back souvenirs (legal or otherwise). Over 100,000 Chinese students go off to foreign universities each year. Even more go abroad as tourists or on business. Most of these people were not asked to actually act as spies but simply to share, with Chinese government officials (who are not always identified as intelligence personnel), whatever information they obtained. The more ambitious of these people are getting caught and prosecuted. But the majority are quite casual and individually bring back relatively little and are almost impossible to catch. 

Like the Russians, the Chinese are also employing the traditional methods, using people with diplomatic immunity to recruit spies and offering cash, or whatever, to get people to sell them information. This is still effective and when combined with the “thousand grains of sand” methods brings in a lot of secrets. The final ingredient is a shadowy venture capital operation (sometimes called Project 863) that offers money for Chinese entrepreneurs who will turn the stolen technology into something real. No questions asked, if you can get back to China with the secrets, you are home free and potentially very rich. 

But there are some legal problems. When the Chinese steal some technology, and produce something that the Western victims can prove was stolen (via patents and prior use of the technology), legal action can make it impossible, or very difficult, to sell anything using the stolen tech outside of China. This is what many recent cases are all about. For that reason, the Chinese long preferred stealing military technology and tried to avoid using stolen commercial tech in a way that made it easy to determine the source of stolen data. This meant keeping stolen commercial tech inside China. And in some cases, like manufacturing technology, there’s an advantage to not selling it outside of China. Because China is still a communist dictatorship, the courts do as they are told, and they are rarely told to honor foreign patent claims when stolen tech is discovered in China by its foreign owners. 

But increasingly, Chinese firms are boldly using their stolen technology, daring foreign firms to try and use Chinese courts to get justice. Instead, the foreign firms are trying to muster support from their governments for lawsuits outside China. Naturally, the Chinese government will howl and insist that it’s all a plot to oppress China. This has worked for a long time, but many of the victims are now telling China that this conflict is being taken to a new, and more dangerous, level.

No comments:

Post a Comment