Image credit: U.S. Department of Justice
The Justice Department says a Chinese government-linked hacking group spent years inside some of the country's most sensitive institutions, before it was shut down this week. The campaign, which the FBI and National Security Agency trace back to at least 2018, gave Chinese state hackers a foothold inside the US Senate, Federal Reserve, NASA, and the US Justice Department itself. The FBI also named the Energy Department, the Department of Health and Human Services, and the National Institutes of Health as targets.
The department's announcement doesn't say what data was taken from any of them, only that they were among the campaign's targets.
The hackers didn't reach any of the US agencies directly. Instead, they built access by hijacking ordinary internet-connected devices – routers, security cameras, and similar gadgets – then routed their intrusions through those hijacked devices to disguise the true origin of the attacks. Agents seized the domains the platforms depended on to operate. Because the domains were coded directly into the malware, redirecting them cut both platforms off from the hackers.
Assistant Attorney General John Eisenberg said the court-ordered seizure of the domains behind that system was meant to "deny PRC-linked hackers access to tools they use to mount online attacks against our Nation's critical infrastructure."
The government hasn't said which device brands or models the malware leveraged, so there's no simple way to check whether a specific gadget in your home was swept up in the campaign. However, basic security practices can help keep your home or business from becoming a route for these attacks. Always change the default administrator password on your router and any internet-connected devices, install firmware updates when they're available, and turn off remote administration unless you specifically need those features.
Read next: How hackers use your home internet without you knowing