01 / Executive brief
Executive summary
The United States alleged that from 2011 through 2018, officers of the Hainan State Security Department—a provincial arm of the PRC Ministry of State Security—used Hainan Xiandun Technology Development Company as a front to recruit and manage hackers. Four named defendants were charged with a campaign targeting companies, universities, research institutes, governments, and other organizations. S1S2S3
The alleged target list read like a strategic technology portfolio: submersibles and autonomous vehicles, aircraft servicing, chemicals, genetic sequencing, Ebola research, and railway information, among other sectors. U.S. and allied agencies publicly attributed the activity to APT40 and published technical indicators, but the indictment has not produced trial findings; the named individuals are presumed innocent unless proved guilty. S1S2S4
02 / The vignette
What happened
A front company supplied the operating layer
The campaign followed useful technologies
Victims were not confined to one defense contractor or one country. Prosecutors alleged intrusions against dozens of organizations in at least twelve countries and identified targets spanning maritime systems, aviation, biomedicine, transportation, and research. That breadth is the central vignette: cyber access can be managed as a continuing collection program rather than a one-company theft. S1S2
Attribution is not adjudication
CISA, the FBI, and partner agencies released technical advisories linking tools and methods to APT40, while the FBI published a wanted poster naming Zhu Yunmin, Wu Shurong, Ding Xiaoyang, and Cheng Qingmin. Those are official allegations and attributions. Because no cited judgment establishes guilt, this file uses allegation language throughout and does not count the case as adjudicated. S2S3S4
03 / Anatomy
How access became transfer
This chain reconstructs the sequence supported by the cited record. It does not imply that every legitimate relationship follows the same path.
- 01
- 02
- 03
Information acquired
Strategic data targeted
The indictment alleged collection from technology, research, government, and industrial victims. S1
- 04
- 05
- 06
04 / Evidence boundary
What is established—and what is not
Established in the record
05 / Sequence
Timeline
06 / People and institutions
Who appears in the public record
Zhu Yunmin
Hainan State Security Department officer named in the indictment
Outcome: Indicted; not adjudicated
Wu Shurong
Computer hacker named in the indictment
Outcome: Indicted; not adjudicated
Ding Xiaoyang
Hainan State Security Department officer named in the indictment
Outcome: Indicted; not adjudicated
Cheng Qingmin
Hainan State Security Department officer named in the indictment
Outcome: Indicted; not adjudicated
Hainan Xiandun Technology Development Company
Alleged front company used to recruit and support hackers
Originator / affected institution
Targeted companies, universities, and public institutions
Creators and custodians of the allegedly targeted technology and data
07 / Consequences
Documented and attributed harm
Authorities alleged intrusions against dozens of organizations in at least twelve countries, but the public record does not quantify verified losses across the campaign. S1
08 / Hindsight analysis
Where leadership could have seen risk
These are our analytic judgments based on the public record, not court findings. They are framed to improve controls without treating nationality as a risk factor.
One campaign crossed many sectors
Organizations evaluating only sector-specific criminals could miss infrastructure and methods reused against unrelated technology portfolios.
Commercial cover obscured sponsorship
A contractor-style company allegedly supplied recruiting and operational support while shielding an intelligence relationship.
09 / Apply the lesson
Actions leaders can take
- both
Use current government indicators
Map CISA and FBI indicators and techniques to telemetry, identity systems, vulnerability management, and incident-response playbooks.
- both
Share cross-sector signals
Participate in sector and government information-sharing channels so repeated infrastructure is visible beyond one institution.
- both
Preserve attribution limits
Separate observed technical behavior, official attribution, charged allegations, and court findings in every executive briefing.
10 / Source record
Sources
Links point to the public record reviewed for this file. Government releases can summarize court proceedings but remain government-authored sources; the source note identifies those limits.
- S1 government release
Four Chinese Nationals Working with Ministry of State Security Charged in Global Computer Intrusion Campaign ↗
U.S. Department of Justice · Published Jul 19, 2021 · Retrieved Aug 23, 2026
Charging allegations; defendants are presumed innocent.
- S2 government release
U.S. Government Releases Indictment and Advisories Detailing Chinese Cyber Campaign ↗
Cybersecurity and Infrastructure Security Agency · Published Jul 19, 2021 · Retrieved Aug 23, 2026
- S3 government release
APT40 Cyber Espionage Activities Wanted Poster ↗
Federal Bureau of Investigation · Published Jul 19, 2021 · Retrieved Aug 23, 2026
- S4 government release
Tactics, Techniques, and Procedures of Indicted APT40 Actors Associated with China's MSS Hainan State Security Department ↗
Cybersecurity and Infrastructure Security Agency · Published Jul 19, 2021 · Retrieved Aug 23, 2026