Copyright © 2026 VPM, all rights reserved.
PBS is a 501(c)(3) not-for-profit organization.
VPM News Morning Edition
NEXT UP: 9:00 AM

Thanks to our sponsors – Become a Sponsor

U.S. Security Company Tracks Hacking To Chinese Army Unit

Cyberattacks on dozens of American companies have been traced to an area on the outskirts of Shanghai that houses a Chinese military unit, according to a report out Tuesday by Mandiant, a U.S. cybersecurity company.

The 60-page document, first reported by The New York Times, says the group behind the attacks — nicknamed “Comment Crew” — is the most prolific the company has ever tracked and has been hacking U.S. companies since at least 2006.

Mandiant says the hackers’ real identity is Unit 61398 of China’s People’s Liberation Army, or PLA.

The unit sits near the Yangtze River in Shanghai’s sprawling Pudong district, which is home to more than 5 million people. The walled compound stands out in an otherwise typical Shanghai neighborhood of restaurants, karaoke clubs and grocery stores.

The complex, which covers nearly three acres, has a 12-story tower with satellite dishes on the top and few signs other than those that indicate it’s run by China’s military.

Photos and filming are not permitted, and a BBC reporter was detained Tuesday after trying to videotape the complex.

When an NPR reporter showed up, a plainclothes police officer in a blue down coat was pacing the sidewalk out front, scanning the street and looking agitated as he spoke on a cellphone.

Wide-Ranging Attacks

Mandiant says the hackers have stolen hundreds of terabytes of data, including technology blueprints, proprietary manufacturing processes, business plans and partnership agreements.

“They’ve compromised over 141 corporations across 20 different industries and stolen just a wealth of intellectual property,” says Dan McWhorter, who oversees Mandiant’s threat intelligence business unit. Most of the companies were American.

McWhorter says the hackers appeared to be trying to steal intellectual property to help Chinese companies compete against U.S. and other foreign firms.

“In China, the government is very intimately involved in industry,” McWhorter says, “so I think the PLA is motivated to take these documents for huge economic gain.”

At a briefing Tuesday, China’s Foreign Ministry dismissed Mandiant’s report. Hong Lei, the ministry spokesman, questioned anyone’s ability to track down hackers with certainty.

“Cyberattacks are anonymous and transnational, and it is hard to trace the origin,” said Hong, “so I don’t know how the findings of the report are credible.”

Hong said that China has also suffered from cyberattacks, and that in 2012, foreign hackers seized control of 14 million Chinese computers. Hong seemed to point the finger at America, if not the U.S. government.

“China is also a victim of cyberattacks,” he said. “In the attacks mentioned above, the number of attacks originating from the U.S. ranks first.”

A Long-Running Operation

McWhorter says tracking the attacks to the PLA wasn’t that hard, because the volume of data stolen was enormous, and the operation has been going on for so long.

“We just followed the data, followed the breadcrumbs,” says McWhorter. “All the network communication kept going back to Shanghai, again and again.”

Mandiant says it tracked the hackers back to four large networks in Shanghai, two in the Pudong area where Unit 61398 is located.

“We started doing our research as far as what kind of organizations could be that large doing this type of activity,” says McWhorter, “and that’s what led us to discover Unit 61398.”

Beyond corporate espionage, Mandiant found hacking that was more worrisome, such as the infiltration of crucial U.S. infrastructure, including electric power grids and gas lines.

McWhorter says there is no sign that Chinese hackers tried to disable such operations, but the capability existed.

“If you have the ability to steal the documents, you could have just as easily crashed the hard drives,” he said. “From a national security standpoint, that’s very scary.”

In his State of the Union address, President Obama alluded to this threat without directly naming China.

“Now our enemies are also seeking the ability to sabotage our power grid, our financial institutions, our air traffic control systems,” Obama said.

The president said the nation could not look back years from now and wonder why it didn’t do anything to stop it.

Copyright 2024 NPR

Tags

Frank Langfitt is NPR's London correspondent. He covers the UK and Ireland, as well as the war in Ukraine and its implications in Europe. Langfitt has reported from more than fifty countries and territories around the globe.

Langfitt was one of three NPR correspondents in Ukraine when Russia invaded in February, 2022. He has reported on battlefield tactics, Europe's political response, the impact of Western weapons, Finland and Sweden's push to join NATO, and the war's effect on front-line states, including Moldova and Poland.

Langfitt arrived in London in June 2016. A week later, the UK voted for Brexit. Since then, he's covered the most tumultuous period in British politics in decades, including five prime ministers. Langfitt has also reported on Chinese influence campaigns, terror attacks, the renewed push for Scottish independence, political tensions in Northern Ireland and the death of the Queen.

In 2022, Langfitt won an Edward R. Murrow award for a journey across London exploring the evolution of the English pub. Langfitt has contributed to NPR podcasts, including Consider This, The Indicator from Planet Money, Code Switch and Pop Culture Happy Hour. He also appears on the BBC and PBS Newshour.

Before Europe, Langfitt spent five years as an NPR correspondent in China, where he covered the first term of Chinese President Xi Jinping. Based in Shanghai, Langfitt also drove a free taxi around the city for a series on a changing China as seen through the eyes of ordinary people. As part of the series, he drove passengers back to the countryside for Chinese New Year and served as a wedding chauffeur. Langfitt expanded his reporting into a book, The Shanghai Free Taxi: Journeys with the Hustlers and Rebels of the New China (Public Affairs, Hachette).

While in China, Langfitt also reported on the government's infamous "black jails" — secret detention centers — as well as his own travails taking China's driver's test, which he failed three times.

Before moving to Shanghai, Langfitt was NPR's East Africa correspondent based in Nairobi. He covered the civil war in Somalia, helped track elephants in South Sudan, and interviewed imprisoned Somali pirates, who insisted they were just misunderstood fishermen. During the Arab Spring, Langfitt covered the crushing of the democracy movement in Bahrain.

Prior to Africa, Langfitt was NPR's labor correspondent based in Washington, DC. He covered coal mine disasters in West Virginia, the 2008 financial crisis and the bankruptcy of General Motors. His story with producer Brian Reed on how GM failed to learn from a joint-venture factory with Toyota was featured on This American Life.

Langfitt also won an Edward R. Murrow award for NPR's team coverage of the 2008 Beijing Olympics, an Overseas Press Award for The Baltimore Sun's team coverage of environmental pollution in China and a citation from the White House News Photographers Association for documenting the destruction of a Beijing neighborhood.

Before coming to NPR, Langfitt spent five years as a correspondent in Beijing for The Baltimore Sun, covering a swath of Asia from East Timor to the Khyber Pass.

Langfitt spent his early years in journalism stringing for the Philadelphia Inquirer and living in Hazard, Kentucky, where he covered the state's Appalachian coalfields for the Lexington Herald-Leader. Prior to becoming a reporter, Langfitt dug latrines in Mexico and drove a taxi in his hometown of Philadelphia. Langfitt is a graduate of Princeton and was a Nieman Fellow at Harvard.

Related Stories