U.S. Data Security against Chinese Counterintelligence

U.S. relations with the People's Republic of China (PRC) were established in 1979 after the U.S. confirmed its recognition and established diplomatic ties. However, since then, relations between the two countries have been contentious, with the U.S. and China experiencing strict political and economic competition with each other. In an effort to gain the upper hand, both states have launched counterintelligence programs that focus on collecting data from tragically important nations. Both China and the U.S. have their own intelligence services focused on collecting information abroad; however, this brief will focus on Chinese counterintelligence efforts towards the U.S. Specifically, it aims to detail the actors involved in the creation of China’s intelligence programs, as well track the actions they have engaged in to collect crucial U.S. data. Furthermore, it highlights current events and respective positions, which it uses to predict possible issues that could arise with tensions between the two countries. Lastly, it considered how the U.S. should approach handling Chinese counterintelligence efforts.

Published on  

March 28, 2023

  by

At YIP, nuanced policy briefs emerge from the collaboration of six diverse, nonpartisan students.

HeadingHeading 3

Card Title

Lorem ipsum dolor sit amet conse adipiscing elit

Card Title

Lorem ipsum dolor sit amet conse adipiscing elit

Card Title

Lorem ipsum dolor sit amet conse adipiscing elit

Card Title

Lorem ipsum dolor sit amet conse adipiscing elit

Support

History

After the Cold War, counterintelligence as a means of warfare or state-sponsored espionage peaked even after moderate use in the past. China, in particular, involved itself in weaponizing “information” against foreign entities starting from 1983, the year establishment of the Ministry of State Security, which is “responsible for conducting counterintelligence and foreign intelligence activities, as well as political security for the PRC,” became realized quickly.

The MSS’s focus on “identifying and influencing the foreign policy of other countries”, including the United States, by seeking to obtain information on political, economic, and security policies that might affect the PRC, became increasingly clear. In collecting this information, they would use it with regard to the military, scientific, and technical operations of the PRC.

Before 1994, state entities tied to the PRC, such as the MSS, primarily relied on Human Intelligence Programs and Activities, as access to the internet was limited before 1994. Later, China placed a heavy focus on developing its internet and technological infrastructure.

The  2009 Chinese White Papers on National Defense reveal that the Chinese government suggests that in order to be part of a “harmonious world of enduring peace and common prosperity,” China should invite foreign nations to “cooperate” or collaborate in “defense-related science, technology, and industry.”

Emboldened by this new vision for technological pursuit, China’s embedded data-driven technology and cybersecurity as a part of its military strategy, as noted by the three biggest divisions of intelligence agencies in China: The People’s Liberation Army (PLA), Technical Reconnaissance Bureaus (which was later restructured into the SSF), and The Ministry of State Security (MSS). 

China played a “catch-up” game in terms of technology ever since, but, the country decided to take it to a further extent: cyber attacks. After just a decade, reported cases of Chinese cyberattacks were making their way, with the infamous case in 2003. The operation Titan Rain, a string of cyber operations that compromised a number of agencies within the U.S. and UK governments, breached the unclassified networks of the U.S. Departments of State, Homeland Security, and Energy, and UK defense and foreign ministries.”

It was an event that catalyzed a decades-long effort by the U.S. government to reduce the breadth and scope of Chinese cyber operations against U.S. targets. However, despite these efforts, the push from China to interfere in foreign privacy and infrastructure has greatly expanded.   

Tried Policy 

As stated, China’s first large-scale cyber attack was “Titan Rain” in 2003, which targeted American and British government databases. Since that time, China has continuously ramped up its hacking capabilities. In the following years, China continued cyber strikes against both the US and NATO. These attacks caught the attention of American intelligence, as in 2009, in a classified National Intelligence Estimate (the consensus of 16 American intelligence agencies), China was regarded as one of America’s top online enemies.

The attacks on the American internet continued through the 2010s but shifted to more commercial interests. This was signified in Operation Aurora, a coordinated cyberattack against American companies like Google, Yahoo, Morgan Stanley, and more. The goal of these attacks was to steal personal information from companies. Google disclosed that they were a victim of the attacks and confirmed hackers had acquired the Gmail accounts of some Chinese human rights activists.

The public blaming of China for the cyberattacks was highly significant because it broadcasts the dangers of cyberattacks to corporations to a wider audience. In the wake of these attacks, Google ended work in China.

This corporate espionage led to the Obama administration indicting five Chinese military hackers in 2014. The hackers were members of PLA Unit 61398, the unit blamed for many of the security breaches. In 2015, China hacked into the American Office of Personnel Management (OPM), which compromised the personal data of millions of federal workers. In the attack, more than 5.6 million fingerprints were stolen. In response to the hack, Obama threatened sanctions against China.

These threats led to an agreement between the US and China, where China agreed to cease the industrial hacking of US companies. The agreement served its purpose, as in the year following the attack, Chinese hacking activities dropped significantly. However, attacks rose again during and after Trump came to office. An example of this is in 2017, when Equifax announced that it had been hacked, exposing the personal information of 147 million people. Four Chinese military hackers were charged with the attacks.

Current Stances 

Concerns regarding Chinese counterintelligence efforts hit the headlines once again earlier this year in early February after residents of Northwest Montana reported seeing a balloon on the horizon. Shortly after initial reports, the U.S. Department of Defense announced that the foreign object was a Chinese surveillance balloon, supposedly capable of conducting signaling intelligence operations.

Due to concerns about the possible fallout, officials hesitated in taking the balloon down, until, on February 4th, a U.S. fighter jet was sent to shoot it down off the coast of South Carolina. According to the Chinese Ministry of Defense, the balloon was indeed Chinese; however, it argues that it was a “civilian airship used for research, mainly meteorological purposes" that had been blown off-course.

Therefore, the Ministry claims the US ``seriously violated international practices and set a very bad precedent." With little constructive dialogue between the two parties, fears arise that miscommunication regarding the event could spiral into a greater ordeal. In most instances, China has denied the usage of cybertechnology to hack or infiltrate government or commercial data. For instance, in mid-2021, the White House publicly blamed China for an attack on Microsoft's Exchange email server software that “compromised tens of thousands of computers worldwide, allowing hackers to gain access to sensitive data.”

However, China rejected the accusations and demanded that all charges be dropped. According to Chinese spokesman Zhao Lijian, “China firmly opposes and combats any form of cyberattacks, and will not encourage, support or condone any cyberattacks.”

In regards to the Chinese Spy Balloon, the US intelligence services have “linked the Chinese spy balloon to a vast surveillance program run by the PLA”, and “US officials have begun to brief allies and partners who have been similarly targeted”. According to The Washington Post, the surveillance program, which has operated for several years, has collected information on military formations in nations of “emerging strategic interest to China including Japan, India, Vietnam, Taiwan, and the Philippines.”

The United States has also blacklisted six Chinese entities that were tied to China’s aerospace programs in response to the February spy balloon. The economic restrictions are followed by the Biden Administration pledging to consider “broader efforts to address Chinese surveillance activities,” as well as make it more difficult for Chinese companies that aid in surveillance efforts to “gain access to American technology.” 

Policy Problem

Stakeholders 

While the U.S. is China’s biggest competitor, other nations have also experienced Chinese cyber attacks, particularly in Western Europe and Taiwan. From stealing defense-related intellectual property from Europe to outright cyber-attacking Europe’s industries, China is regarded as a present danger to the EU. For instance, EU Commission President Ursula von der Leyen suggested that China might have been behind cyberattacks against hospitals in Europe during COVID-19 in 2020. 

Furthermore, FireEye, a leading cybersecurity firm, suspected that state-backed Chinese hackers exploited networking devices to spy on high-value government, defense industry, and financial sector entities in the U.S. and Europe. More recently, in December 2022, a Chinese-linked hacking group known as Mustang Panda reportedly used lures related to the Russo-Ukrainian War to attack European officials through phishing.

As such, in specific response to the 2021 Microsoft hacking, the White House released a joint statement with the EU, U.K., and NATO condemning China for the cyberattacks, with the US committing to network defense action and cyber operations to safeguard vulnerable systems. Ultimately, the U.S. and its allies are staunch in their opposition to China’s malicious cyber operations and have taken steps to bolster their own software and systems security. 

Meanwhile, the hotly contested island –  of Taiwan – has been under heightened political and military pressure from China, and cyberattacks are not an exception. According to the Dyadic Cyber Incident and Campaign Data (DCID) categorizing state-sponsored cyber activity between 2000-2020, there have been 13 reported cyber interactions between China and Taiwan, twelve of which were started by China and eight of those which were intended for Chinese espionage.

While these cyber operations are unlikely to cause an escalation, the Council on Foreign Relations points out that China can exploit cyberspace to gain an advantage over Taiwan through information operations and espionage, as well as signal political pressure on Taiwan. Finally, chances of escalation may rise if China’s cyberattacks begin targeting critical infrastructure in Taiwan or are posited as a precursor to a conventional attack. 

Nonpartisan Reasoning

With tensions between China and the U.S. rising, the consequences of escalating cyberattack missions are more imminent. In fact, Beijing has the legal and political power to compel private Chinese companies to provide access they may have to software and hardware systems used in the United States. Furthermore, both Chinese and U.S. intelligence agencies can launch cyberattacks targeting key infrastructure, causing the collapse of power lines and the internet.

Attacks on critical infrastructure are already increasing. In June 2022, Trend Micro Incorporated announced that new research found “89 percent of electricity, oil and gas, and manufacturing firms have experienced cyber-attacks impacting production and energy supply over the past 12 months”.  In the U.S., attacks on a power grid or pipeline would undoubtedly plunge millions of homes and businesses into turmoil.

Furthermore, failure to prevent intellectual property theft and illicit technology transfers could weaken American economic and national security interests. According to the IP Commission report, intellectual property theft already costs businesses in the US over $600 billion annually. Indeed, with access to the right information, both parties have the power to halt key exports, imports, and people-to-people exchanges to inflict economic damage. 

Policy Options

The spy balloon has generated pressure on policymakers to take action on an issue that typically flies below the radar of most of the electorate. As Washington evaluates its next steps, it must be sober yet cautious. The U.S. must take more aggressive positive action toward reducing its vulnerability to Chinese cyber espionage.

At the same time, it remains critical that Washington does not overreact to the threats posed. To this end, the U.S. must procure offensive cyber capabilities while avoiding over-investment traps. 

Washington must enhance investments in offensive, not just defensive, cyber capabilities. 

Investments in cyber defense must, without a doubt, be a top priority of Washington’s military spending. Nevertheless, defensive measures will never be perfected, and thus the U.S. must be able to impose a deterrence-inducing countermeasure. Beijing has long been emboldened to continue its cyber espionage missions because the U.S. lacks the sufficient capability to engage them at the same point in the escalatory ladder.

Almost always, it would be unreasonable for Washington to respond to, say, a Chinese attack on private data infrastructure with the deployment of military force. Without a credible threat of reprisal, Beijing has little incentive to cease cyber operations. 

The U.S. needs not necessarily to engage, but to be able to engage China in the grey zone of cyber conflict. Empirically, offensive responses from the U.S. have sobered nations into compliance with global cyber norms — halting ongoing offensive operations. 

Moreover, a deterrence-based approach helps protect private, not just public, information. A sizable portion of American sensitive information critical infrastructure is owned by private companies, meaning cyber defense for government agencies does little to ensure their protection. Offensive capabilities, however, deter attackers from infiltrating both public and private sources. 

Policymakers must make sure not to fall into the cyber weapons gap myth. 

There seems to be this enduring narrative that the West is far behind China (and Russia) in terms of cyber security and grey-zone tactics. In some cases, this might be true, but by and large, the U.S.’s prosperous private sector ensures it can outperform Beijing — given proper investments. At present, the U.S. invests 5 times more in defensive than offensive capabilities. It is not the case that the U.S. has fallen behind and can’t catch up, but shifting priorities can enable America’s cyber protection better. 

Cyber espionage is a national security threat, but we must also be clear about what isn’t happening in cyberspace. Beijing has not carried out comprehensive attacks on U.S. critical infrastructure, and — as America knows well — many forms of espionage are permissible under international law. The U.S. should certainly take steps to protect its data and create more stringent international cyber norms, but an overreaction may trigger an escalatory spiral that produces more harm than good.