This page has been proofread, but needs to be validated.


  1. The cyber threat from China emanates principally from the Ministry of State Security and the PLA. These organisations are almost certainly responsible for ***, and their cyber activity is closely correlated with the Chinese government's economic and military development goals.[1]


    APT10[2] is one of the best-known Chinese hacking groups, and has carried out numerous malicious cyber campaigns on behalf of the Chinese Ministry of State Security (MSS). *** it has targeted government, defence, mining, information technology, *** with victims identified worldwide, including in Europe, Asia, and the United States ***. ***.[3]

    In 2016, *** it was detected that there had been a large-scale compromise of a number of Managed Service Providers (MSPs) (companies which provide IT and network support, including hosting emails). The attack, widely known as 'Cloud Hopper', facilitated economic and strategic espionage.

    The UK Government publicly attributed the Cloud Hopper MSP campaign to APT10 in December 2018, linking the group explicitly to the MSS. This was the first time that HMG had publicly named elements of the Chinese government as being responsible for a cyber campaign.[4]

  2. China's sophisticated cyber capabilities could, in theory, be employed to conduct a cyber attack against UK infrastructure. ***. In the words of NCSC:

    on cyber attacks that [the Chinese] undertake, ***.

    *** they use their intelligence capabilities very much for ***. They do have offensive cyber capabilities. *** exercising those cyber capabilities *** … around the blurring of some of their capabilities … I think absolutely we're alive to them using cyber as a means to enable HUMINT and the other way round and so work very closely together to sort of make sure that ***.[5]

EEE. We welcome the Government's attribution of attacks to the Chinese hacking group APT10. Public condemnation of such groups explicitly linked to the Chinese government is an essential tool in tackling the increasing cyber threat from China. The Government should continue to work with allies to highlight and condemn hostile Chinese government activity.

  1. Written evidence—NCSC, October 2021.
  2. APT10 stands for 'Advanced Persistent Threat 10'.
  3. Written evidence—NCSC, August 2018.
  4. 'UK and Allies reveal global scale of Chinese cyber campaign', HMG press release, 20 December 2018.
  5. Oral evidence—NCSC, *** December 2020.