Suspected Chinese hackers have broken into Microsoft Exchange email servers used by foreign ministries, according to new findings from Palo Alto Networks. The security company’s Unit 42 division has been tracking the group for nearly three years. Researchers said the operation is a long-running effort to read and collect the private communications of diplomats across […]Suspected Chinese hackers have broken into Microsoft Exchange email servers used by foreign ministries, according to new findings from Palo Alto Networks. The security company’s Unit 42 division has been tracking the group for nearly three years. Researchers said the operation is a long-running effort to read and collect the private communications of diplomats across […]

Suspected Chinese hackers break into foreign ministries' email servers

2025/09/30 20:14

Suspected Chinese hackers have broken into Microsoft Exchange email servers used by foreign ministries, according to new findings from Palo Alto Networks.

The security company’s Unit 42 division has been tracking the group for nearly three years. Researchers said the operation is a long-running effort to read and collect the private communications of diplomats across the world.

Unit 42 confirmed the hackers had full access to search for information inside the email servers of some ministries. They specifically hunted for terms tied to a China-Arab summit held in Riyadh, Saudi Arabia, in 2022, said senior researcher Lior Rochberger.

The team said the hackers also searched for the names of Chinese President Xi Jinping and Peng Liyuan, his wife, in connection to that summit. Researchers declined to identify which countries were hit but said the activity “align consistently with the People’s Republic of China (PRC) economic and geopolitical interests.”

Researchers track hackers to Phantom Taurus campaign

“When I found them searching for specific diplomatic keywords and then exfiltrating emails from embassies and military operations, I realized this was a serious intelligence collection effort,” Rochberger said. Palo Alto Networks calls the hacking group Phantom Taurus.

The company said the breaches went beyond simple spying, showing a focus on strategic events and military movements.

Liu Pengyu, a spokesperson for the Chinese Embassy in Washington, responded that hacking is a problem for all countries, including China, and that the government opposes all forms of cyberattacks.

“Cyberspace is highly virtual, difficult to trace, and involves a diverse range of actors,” he said. “Tracing the source of cyber attacks is a complex technical issue, that requires solid and full evidence.”

The Palo Alto Networks report also highlighted how suspected Chinese hackers are now targeting industries worldwide. On September 24, Alphabet Inc.’s Google stated that a Chinese group had compromised US technology companies.

Earlier in September, suspected attackers impersonated the Republican chair of the House Select Committee on China in attempts to steal sensitive data on trade negotiations, according to the committee.

Assaf Dahan, director of threat intelligence at Palo Alto Networks, said many of Phantom Taurus’ breaches had a “tight correlation to specific geopolitical events or military maneuvers.” The report also said that other espionage activities sought information related to countries, including Afghanistan and Pakistan.

Claim your free seat in an exclusive crypto trading community - limited to 1,000 members.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Share Insights

You May Also Like

One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

The post One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight appeared on BitcoinEthereumNews.com. Frank Sinatra’s The World We Knew returns to the Jazz Albums and Traditional Jazz Albums charts, showing continued demand for his timeless music. Frank Sinatra performs on his TV special Frank Sinatra: A Man and his Music Bettmann Archive These days on the Billboard charts, Frank Sinatra’s music can always be found on the jazz-specific rankings. While the art he created when he was still working was pop at the time, and later classified as traditional pop, there is no such list for the latter format in America, and so his throwback projects and cuts appear on jazz lists instead. It’s on those charts where Sinatra rebounds this week, and one of his popular projects returns not to one, but two tallies at the same time, helping him increase the total amount of real estate he owns at the moment. Frank Sinatra’s The World We Knew Returns Sinatra’s The World We Knew is a top performer again, if only on the jazz lists. That set rebounds to No. 15 on the Traditional Jazz Albums chart and comes in at No. 20 on the all-encompassing Jazz Albums ranking after not appearing on either roster just last frame. The World We Knew’s All-Time Highs The World We Knew returns close to its all-time peak on both of those rosters. Sinatra’s classic has peaked at No. 11 on the Traditional Jazz Albums chart, just missing out on becoming another top 10 for the crooner. The set climbed all the way to No. 15 on the Jazz Albums tally and has now spent just under two months on the rosters. Frank Sinatra’s Album With Classic Hits Sinatra released The World We Knew in the summer of 1967. The title track, which on the album is actually known as “The World We Knew (Over and…
Share
BitcoinEthereumNews2025/09/18 00:02
Share