Chinese hackers exploit Google Workspace to steal sensitive research data
A China-linked hacking group spent over a year inside North American research networks, using a built-in Google Workspace feature to exfiltrate sensitive data

A China-linked espionage group spent more than a year undetected inside North American medical, academic, and military research networks. During the intrusion, the attackers focused on stealing sensitive data and defense-related emails from the compromised organizations.[1]
The attackers initially gained access to the networks through a backdoor on REDCap research servers. To exfiltrate the stolen information, they employed an unusual method by rewiring the victims' own Google Workspace rules to automatically copy and forward matching messages.[1][2]



