Google reports hacking is linked to China
Says U.S. and Canadian research groups targeted
By: AJ Vicens
Reuters
..... A Chinese-linked hacking group secretly stole data from U.S. and Canadian academic, medical and military research institutions before being detected, Google said on June 15. [2026]
.....
Between September 2023 and November 2025, the hackers sought information related to defense intelligence, military strategy in the Indo-Pacific, artificial intelligence, unmanned vehicles, cyber warfare programs and medical research, Google's Threat Intelligence said in a report.
..... Google has attributed the campaign to a hacking group in calls UNC6508, a relatively new and little-known cyberspiionage player. Luke McNamara deputy chief analyst at Google Threat Intelligence Group, said the organization's methods are broadly consistent with Chinese-linked hacking activity seen over many years , focused on gathering information likely to be of inters to the Chinese government.
.....
The Chinese Embassy in Washington did not immediately respond to a request for comment.
..... The earliest known activity tied to the campaign dates to September 2023, when the hackers exploited vulnerabilities in serves running REDCap,
a web application widely used by nonprofits to build and manage Online surveys and databases.
..... Using custom-built malicious software, the hackers stole legitimate REDCap
login credentials to gain access to the targeted networks, then set up a system to automatically forward emails containment any of nearly 150 keywords and search terms to a Gmail account they controlled, the researchers said.
..... The keywords and search terms include phone numbers and email addresses for people at targeted organizations as well as terms related to nonstrategic policy, military strategy, advanced technology and medical research.