Loading summary
A
You're listening to the Cyberwire Network, powered by N2K.
B
Welcome to Spycast, the official podcast of the International Spy Museum. I'm your host, Sasha Ingber, and each week I take you into the shadows of espionage, intelligence and covert operations across the globe. Ahanadatta Fazel became the British government's first ethical hacker in 2014, testing vulnerabilities in computer systems and networks which hackers could potentially exploit. She was only 23, but that gave her an early look at style state sponsored cyber intrusions, which of course have grown more serious and sophisticated today. Her book Full Stack Cyber Espionage in the Age of US China Competition explores China's business of spying online. She joins me from London to talk about the competition, vanities and betrayals between hackers, tech companies and the government through some of Beijing's most destructive military and civilian cyber operations. Hey, Ahana, how are you?
A
Yes, very well, thank you. How are you, Sasha?
B
I'm good. Starting off the day here in dc. I know you're in London. Thank you for joining me.
A
It's a pleasure to be here. Thank you for having me.
B
So in our very first conversation, you described yourself as an inveterate scroller, which was a term I found very amusing using. And you told me that you went down this rabbit hole. There was this Chinese cyber security services company called isoon that saw its data leak back in 2024. And this is a company that conducted cyber espionage with the People's Liberation army, with the Ministry of State Security. So first off, why did this data leak?
A
It was this sort of painting of continuous dissatisfaction internally that seems to have resulted in this kind of leak. We have their group chats, this sort of company, WeChat, for a period of almost five years. And then in February 2024, when this group chat was leaked, suddenly it had the attention of China watchers and cybersecurity professionals all around the world trying to figure out what this tells us about the Chinese ecosystem. And what I did instead was to look over the entire sort of years and years worth of conversations and try and figure out why, what changed in the company, what sort of organizational behaviors changed here that led to this leak. And so what it feels like is that over the course of five years, there was quite a lot of internal unhappiness and disgruntlement with not being paid properly or being asked to do a bit too much or being stretched beyond their regular hours, although I don't think we'll ever know for certain. But it was quite interesting in the way that the Leak encompassed all their marketing materials, but none of their actual cyber weaponry. So none of the capabilities that held intrinsic financial value, but certainly enough of their marketing and their group chats to be able to bring the company itself down.
B
So maybe this was a disgruntled worker who had limitations in what they chose to leak, and this was actually discovered by a Taiwanese security firm. Can you tell me about who ISOON was targeting before we move into what the actual Leak had in it?
A
Yeah, I mean, ISOON was spread over three locations in mainland China. So they had a Beijing bureau, they had a bureau in Chengdu, and really that's kind of the two main bureau where the CEO and the CEO are based. They had this sort of floating third bureau in Shanghai. They were targeting essentially anything and everything they could get their hands on. And it is, I suppose, a slightly damning view of Western security researchers that we saw ISIM's activities under the guise of a wider hacker ring and followed their activities over the course of over 12 years, but not really pinning it down to them being isoon, but part of a wider collective based out of Chengdu. So over the course of 15 odd years, they compromised hundreds of organizations all over the world, whether that was in healthcare companies in the us, whether that was towards the South China Sea provinces and territories. So they had quite a wide and scattered remit. And the reason for that is that the relationships that they built within organizations like the Ministry of State Security were quite decentralized. So they were essentially hedging for contracts wherever they could get them. And their operations ran the gamut of whatever those interests might have been.
B
So let's go into this leak now. What were you looking for as you're scrolling through what ends up being about five years of conversation on WeChat?
A
Well, I was looking for what kind of patterns might come out of these chats, the pattern of life, to try and sort of see the commonalities in behavior, to understand what makes these people tick, but also how the company culture might have changed over the course of five years. I was looking for their reactions to sort of big events like having their sort of comrade hacker groups being indicted and what they thought of that. And I was looking for who they name check, who they brag about, what sort of worries they might have, the sort of state of their financial health and where their pressure points were, who
B
was in this chat and what were the dynamics like.
A
It was quite a small group, they have a CEO and all their Christian names are provided by the DOJ's indictment notice. So What I'll do is use their hacker names, which is kind of, you know, for us hackers, it's kind of like our artist names. That's how we would rather refer to each other. So the CEO was called Shutdown, and Shutdown is this bombastic creature that's full of energy and full of opportunism. And over the course of five years, whenever he's sort of in the chat, whenever he's on the scene, he's talking about, oh, I had dinner with this lieutenant general and I had a meeting with this sort of regional middle management official and we're going to take on a couple of junior officers from the army and try and train them. So this really larger than life character and in great contrast is his operations manager or the coo, who's called Langmo, real name Chen Cheng. And he presents as this constant worrywart. He is this perpetually anxious, sort of looking at the books, not quite adding up, sort of worrying about everything from the kind of quality of wine at office parties to how do they get their next contract. So you really have these two very different characters. And then in the middle you have this rotating cast of people who come and go, whether that's freelancers, whether that's a group that has been indicted by the doj, who's now essentially homeless and jobless, who they've brought into their company, whether that's interns, who they've got on just because these interns are well connected with regional government officials. The most notable thing I found, as you know, as a person of a technical background, was that they don't really talk about the hacking very much at all. Their primary worry is, well, are in this order drinking girls and how are they going to afford the infrastructure for all their ambitions?
B
Order of importance.
A
Yeah. The day that one of the most notorious front companies in Chengdu, called the Chengdu 404 Network Technology Company, and this is another sort of Ministry of State, State security fronted offensive cyber companies. The day they're indicted by the DOJ, sometime in 2020, our warrior COO, Legmo comes onto the chat. He was like, oh my goodness, they've been indicted. Their mug shots are all over the Internet. This is outrageous. And the CEO, this bombastic shutdown Persona, starts laughing and says, well, great, next time we'll invite them to drink 41 glasses of wine because they've been caught out. And the reason, he says 41 is because the US intelligence community identified the group in Chengdu as the Advanced Persistence threat group number 41. So they were mocking both the US and their comrades who had been caught out. But they knew that they get that they won't be unemployed for too long. And so they subsume them and then they fall out with them.
B
What happened?
A
Well, what we think happened, at least going by the chats, was that they brought in these former Chengdu 404 people who brought with them cyber capabilities that, and this sounds really prosaic that I soon thought that they didn't have a non competer over and the Chengdu 404 guys thought that they did. And so there's this internal dispute about using software, which is actually offensive cyber capability, about who gets to use what. And so if you look at the chats and if you look at, say, forensic reports on this sort of wider ring that researchers at, for example, Google have published in 2022, there's this period of complete silence. And that's because they're trying to wade through the dispute. And it may very well have had an impact on who eventually leaked the group chat. It's a messy relationship that is full of egos and full of conflict of interest and opposing perspectives.
B
You had also traced some of the cultural aspects at play in this dynamic. And there was a concept called Quangxi. Can you tell us about that and how it also played out in the chat room?
A
Yeah, I mean, because hackers are hackers, they sort of, they're mainly motivated by breaking down any sort of sense of hierarchy. And Guangzi is kind of the opposite of that. It's, it's this, it's this kind of an informal relationship. It's in Chinese culture that works on the principle of hierarchy and it is not always reciprocal. And it's almost a system of informal patronage in which the sort of junior member of this relationship will always be deferential to the senior person. And that is how sort of historically government officials and military personnel have been promoted. But that is also how these hacker teams or these front companies have continued to receive their state sponsorship or their patronage from within the government. So that so long as they're carrying enough favor with government officials, they will somewhat be taken care of because their government work isn't exactly high paying. So this isn't exactly, well, remunerated work. But they do it so that they have that umbrella of protection over them.
B
At the same time, though, they also were deceiving the Chinese government to some extent, is my understanding.
A
Yeah, I mean, they were deceiving them in the sense that this offensive cyber economy, the reality of that is that they have to be able to make a living. And often because government work isn't well paid, they have to make that living through various other revenue streams. They have to be able to repurpose some of the technology they use for espionage into those criminal campaigns to steal data, to be able to launch ransomware attacks, to be able to hold these sort of extortion based methods as a revenue stream.
B
We're dissecting the conversations between some of the people who are working for ISOON as a way to understand some of the dynamics of the hacking groups that the Chinese Communist Party goes to for its espionage and for campaigns that harm the United States. So as we keep thinking about this, when you tell me that their number one priority is girls and drinking and then getting government contracts, are they actually serious about what they're doing? What's behind that?
A
These are quite fundamental human impulses that are common to hackers everywhere. You know, these are young men who are in their first or second jobs. So straight out of university, it is almost entirely young men. Towards the end of the chat in the ISOON case, you see the presence of one young woman who is kind of flirting with the operations manager, but you don't really see the impact that she has on the business from the chants. So it is almost exclusively young men who are in this slightly one upmanship state of mind where yes, of course their ability technically and the respect of their peers is highly prized. But even more than that is, are they cool? Are they seen as cool by their hacker comrades? Are they seen as successful?
B
The human interactions here are pretty fascinating. I mean, I'm just imagining you sitting there being an inveterate scroller and getting into these weird interactions.
A
Yeah, I mean, it was hugely fun. Because I think one of the things that we miss when we read a cyber adjacent story is that these are human stories. And these are human stories because they are underpinned by the fallibilities within human nature. If a hacker group is guided by vanity and being seen as successful and aren't prizing so much the sophistication in their trade craft, then that is a vulnerability that, for example, counterintelligence analysts in the US can find useful. Because these hackers will not necessarily spend loads of time inventing the best offensive cyber capability. What they'll do is rely on tools that are already out there, throw them at US assets and see what works. And if that's successful, and curries them favor with the state that's in their eyes, a victory, not so much as being seen as the Most technically proficient.
B
And beyond the human interactions that you were tracking inside isoon, or what were some of your biggest takeaways about the interactions with the people who would be giving them those contracts, whether it be the People's Liberation army or the Ministry of State Security, both supporting China's Communist Party.
A
The one thing that stuck out was that this was not a proactive relationship from on part of the government. It was very much competing groups, front companies going over to government officials, military officials, to essentially flog their data to them and see whether or not they bite and whether or not they're willing to pay for it. So what emerges is this picture of how hands off the technical details of these offensive cyber operations, of these espionage campaigns government officials really are, that they sort of leverage their relationships with these hacker groups to just sort of let them do their own thing while they turn the other way.
B
2024 isn't just when this leak happens. There was a major restructuring of the People's Liberation army that same year, in part because of major corruption inside the pla. Part of the restructuring here, which analysts have said reflects a shift toward domain special. More highly focused intelligence enabled combat support, tighter political control. Part of this also involved creating a new strategic arm called the Information Support Force. Tell us more about what it does in relation to the cyber ecosystem that we've been talking about.
A
So the Information Support Force is an evolution of the previous structure of the People's Liberation Army. Its previous incarnation was called the Strategic Support Force. So the Information Support Force sort of came towards the end of a number of purges of senior military officials. To be able to centralize and make this power vertical at the level of every single theater command, at the level of PLA Air and PLA Navy. To be able to show that information operations were as important to the Chinese military as any other command.
B
And what exactly is it doing?
A
That remains somewhat shrouded in mystery. But what commentators think is that it is the culminating department that subsumes a lot of capability, like network warfare, like information operations, like the PLA's offensive capabilities, that up until 2020 were sort of written off because commentators thought that the Ministry of State Security, the foreign intelligence arm, was far superior in terms of tradecraft.
B
When we come back, we look at some of China's greatest vulnerabilities in the cyber ecosystem. In the modern AI enterprise, adversaries no longer break in. They log in as autonomous AI agents and machines gain privileged access. Your risk is becoming invisible and legacy tools can't keep up. Introducing IDERA from Palo Alto Networks. IDERA is the next generation identity platform built for the scale of the AI workforce. It helps you discover hidden risks instantly, eliminate static privileges with just in time enforcement and automate governance at machine speed. Secure every identity, human, machine and agentic with IDERA by Palo Alto Networks. Visit paloaltonetworks.com Idira to get started. We know today that the People's Liberation army was behind Volt Typhoon. This was an intrusion that was first detected in 2023 by Microsoft in Guam, where the United States has naval ports and bases, but also found on the mainland here in the US in critical infrastructure, potentially to prepare for future disruption, especially in the event of conflict over Taiwan, conflict with China. Can we take all of these pieces and talk about what it ultimately means and whether or not this actually put China ahead when we're talking about cyber warfare?
A
When the infiltration was discovered in this naval logistics hub in Guam, Microsoft employees started following this traffic being sent through by the PLA's hackers. Microsoft President Brad Smith called it a generational threat. And the reason he called it that is because for the first time it seemed as though the People's Liberation army was really invested into stealth and their stealth capabilities. Because for gaining entry into this naval network, they weren't using massively sophisticated capabilities or tradecraft once they got into the network. They were using ordinary tools that any kind of infrastructure manager would use just to poke around the network and see what access they could gain. I would see it as a proof of the sophistication of the People's Liberation
B
Army's tradecraft if, if the PLA was ultimately using simple tools. And here we have been discussing the practices and priorities of a company like isoon. What is that telling us?
A
Well, it's telling us that the offensive ecosystem in China, whether that's military or foreign intelligence over the past five years has decided to prioritize stealth rather than being as noisy as possible about their interventions. Up until 2015, when President Xi met President Obama, stealth wasn't a huge factor. But obviously the Chinese state realized that they had to be better at this. So when Volt Typhoon showed its ability to, to be able to introduce stealth into its operations, that was quite a seismic thing for the pla. And the second part that made this operation different was that in a closed door meeting in Geneva, the Wall Street Journal reported, when the US side asked the Chinese Foreign Ministry about the involvement of China for the first time, the answer wasn't a vehement no. And that is a huge departure for how China usually handles accusations like this. But to be very specific, the Chinese side responded something to the effect of it wasn't us, but if we had done it, it shouldn't be of surprise to you. And that is essentially a power play. It's a perception shaping device. It's them saying that we have clearly stepped up our capabilities and we are going to leave this in a place of ambiguity where now your behavior is going to be shaped by the lack of a denial. So for the first time, military cyber espionage was fulfilling these different roles, strategic goals, not just of real time counterintelligence, but also of shaping their adversary's perception.
B
So let's also then move on to the Ministry of State Security, which is of course foreign focused, but spread out across China more in an FBI like way. And it was behind Salt Typhoon, which was a very destructive intrusion in that it entered the US telecommunications system. And there are many different ways that can present threats, including learning about communications between government officials who could now be subject to blackmail. Can you talk more about that attack in light of what you've just shared?
A
As far as my own analysis goes, Salt Typhoon is simply a more extreme version of what the Ministry of State Security has been doing since all the way back to the attack on the Office of Personnel Management.
B
And that was a 2015 attack which targeted US federal workers who had filled out security forms. So millions and millions of Americans now had been targeted back in 2015.
A
That's right. And in the run up to the Office of Personnel Management attack, China origin hackers had been probing middle managers, middle players, intermediaries like data brokers, insurance companies, and probing their networks for the same kind of data until it led to the OPM breach. With Salt Typhoon, there is no open consensus on what the hackers must have compromised to gain entry into the backbone of American telco. But it is simply the latest in a long trajectory of supply chain compromises of infrastructure attacks that the Ministry of State Security has done again and again and again to ever more egregious campaigns.
B
And this is suggesting the long term thinking that we all know China has, that the 2015 OPM hack was really just the start of you're saying.
A
Absolutely. I mean, if you think about Western responses to these campaigns, they have been quite chop and change. We respond to a campaign and we respond to the actors in that campaign.
B
It's very siloed and you are connecting it here. And I'm wondering, we've seen so many examples of China stealing our data and our technology, whether it's through hacking or through intelligence officers, between the People's Liberation army and the Ministry of State Security, how innovative are they actually? Or is it really just that they have this long term thinking and strategy?
A
I think one of the things that is really crucial to this ecosystem, but especially in the foreign intelligence ecosystem, is the ability of the Chinese state to be able to amass a certain scale. And the scale is probably the single most crucial asset because that scale provides fungibility, that scale provides the diffusion of capabilities and the ability to contract out a job to multiple different actors. So that scale is really a massive asset to the Ministry of State Security. But on the other hand, the pla, the People's Liberation army, is also showing its ability to prioritize offensive cyber operations by investing in them, by showing signals that they look at information operations at the same level as any other kind of military offensive. And that mentality, that change in mindset is quite big for the Chinese.
B
Is that from working with these companies like isoon?
A
The Salt Typhoon campaign is a very interesting one, because when Salt Typhoon became public, and just to remind your listeners that it is still going on right now. So when it was made public back in 2024, the American intelligence community and private sector researchers traced back Seoul Typhoon to a bureau of the Ministry of State Security in Sichuan. It's based in Chengdu. So if you just think about the different front companies that we've talked about that have had a presence in Chengdu, it wouldn't be surprising at all that Salt Typhoon is in fact not one group, but a collection of different hacker collectives. Whether that's front companies or whether that's internal Ministry of State Security staff. And to be able to lump them together into this sort of actor name like Salt Typhoon is both a benefit to be able to track their activities, but also a slight disservice because we can't get far down enough into the nitty gritties of who makes up these campaigns.
B
So when we think about how back in 2025, China's state sponsored hackers used Anthropic's AI to automate cyber attacks, according to Anthropic, where do we see this all going? AI presents a new landscape of threat vectors. And it doesn't look pretty from where I'm sitting.
A
The real game changer is the time element. And that both for defenders and offensive actors, is a massive variable. Now that will define the future of how cyber competition plays out. Because for defenders to be able to preempt and design their infrastructure to account for these sort of AI enabled campaigns and for offensive actors to be able to maintain stealth despite the opportunities afforded by AI, these are not trivial considerations. So the time element of not just being able to defend, not just being able to know when to attack, but also what to do in response to an attack, these are not only technical questions, these are also political questions.
B
And when you talk about time, you're specifically saying, from when they are able to get in to what they're doing in there to when they're detected when.
A
That's right.
B
So how should the west handle the threat coming out of China? Here in the United States, President Trump's cyber strategy has stated that it will deploy a, quote, full suite of US Government defensive and offensive cyber operations. We will unleash the private sector by creating incentives to identify and disrupt adversary networks and scale our national capabilities. We must detect, confront and defeat cyber adversaries before they breach our networks and systems. We will erode their capacity and capabilities and use all instruments of national power to raise the costs for their aggression. Is that the approach that you would recommend?
A
I think that we must be very cautious when taking an aggression first approach. I understand completely the administration's desire to take that kind of tone because a lot of the things that the US has done in response to Chinese cyber operations hasn't really worked. I would argue that it's not for the lack of aggressive cyber operations, but from a lack of understanding this continuity that is seen in China's cyber operations over the course of 15 years. What we know about their ecosystem, what we know about the hacker groups, how they're incentivized, and to try and break through that side of adversarial behavior rather than trying to big up how powerful offensive cyber operations conducted by the US Will be.
B
So what would that look like?
A
We would have to ask ourselves, how can we raise the costs on the adversaries enough? Like President Trump's strategy says, what are the mechanisms through which we can raise the costs where the likes of isoon find it too expensive to carry much success? Now, if you look at the kind of tools that most Chinese hackers have used in the past 15 years, these are quite low level tools. If we look at the trajectory of Chinese cyber operations, they've been successful repeatedly because they've managed to leverage small time vulnerabilities in our operating systems. And the truth is that we simply haven't prioritized defense, cyber defense quite enough to be able to say that somehow offensive cyber operations will have a deterrent effect.
B
I remember a conversation I had with someone who was working in counterintelligence, especially looking at China, and described to me conversations from years ago where they approached lots of different government entities. What is most important to protect, what is most critical, and there was never any clarity on that, what to prioritize. Even if you just look at critical infrastructure, what's most critical of critical infrastructure, and that seems like it is the obstacle here. If you're describing low level tools that have been able to be successful because our defenses are low, I think that
A
is a very useful way to look at it.
B
So then let's look at this from the other side, where we know that China plays this long game and because it is not a democracy, it can maintain more of a consistent stance strategy. What are some of China's greatest vulnerabilities in the cyber ecosystem space whereby those can be exploited by the United States, by the uk, by other actors?
A
I think it's the same thing that makes the uk, the US and other Western allies so strong, which is the resilience of our relationships. If you think about the offensive Chinese ecosystem, their allied relationships are pretty much either quite brittle or non existent. What makes the Five Eyes the most powerful intelligence alliance in the world is the quality of our relationships that we're able to develop offensive cyber capability at whatever level in concert with our allies, whereas China doesn't necessarily have that kind of relationship even with its closest partners.
B
Ahana, thank you so much for sitting down with me today.
A
It's such a pleasure, Sasha, and it's been such a great conversation. I mean, I'm sure we could talk about this for hours and hours because there's so much.
B
Yeah, yeah, yeah. There is a lot to cover. Really appreciate you coming. Thanks again.
A
It's been a pleasure. Thank you so much.
B
Thanks for listening to this episode of Spycast. If you like the episode, give us a follow on Apple, Spotify or wherever you get your podcasts and leave us a rating or review. It really helps. If you have any feedback or you want to hear about a particular topic, you can reach us by email@spycastpymuseum.org I'm your host Sasha Ingber and the show is brought to you by N2K Network's goat rodeo and the International Spy museum in Washington, D.C.
Episode: Inside China's Cyber Espionage Business
Host: Sasha Ingber
Guest: Ahanadatta Fazel
Release Date: July 14, 2026
This episode delves into the shadowy world of Chinese cyber espionage. Host Sasha Ingber interviews Ahanadatta Fazel, ethical hacker and author of Full Stack Cyber Espionage in the Age of US China Competition. The conversation centers on China’s growing cyber-espionage business, illustrated by the infamous 2024 leak from the hacking contractor “ISOON.” Fazel and Ingber explore the internal dynamics of Chinese hacking groups, their relationships with the government, cultural motivations, and the implications for global cyber defense and strategy.
Source of the Leak:
Targets and Operations:
Volt Typhoon (PLA, 2023):
Salt Typhoon (Ministry of State Security):
On Hacker Motivations:
On Guanxi:
On U.S. Counterintelligence Opportunities:
On PLA’s Shifting Strategy:
China’s Unprecedented Response to Volt Typhoon:
On the Scale of Chinese Operations:
On Defensive Priorities:
On Western Strengths:
This episode provides a rare, deeply human insight into the structure and motivation of Chinese state-affiliated hacking groups. Fazel underscores the importance of understanding cultural, economic, and organizational dynamics—arguing that vanity, opportunism, and brittle relationships offer adversaries (especially the U.S. and allies) as much of an opening as technical exploits do. True resilience, she concludes, lies in robust defensive prioritization and the strength of international alliances.