← All case files CS-025 / Last reviewed Aug 23, 2026 Jump to sources ↓

AI, semiconductors & telecommunications / 2011–2021

A Hainan intelligence bureau allegedly used a front company to run a global technology-hunting campaign

A 2021 federal indictment and joint cyber advisories attributed a multiyear intrusion campaign to officers of the Hainan State Security Department and a contractor front company. The defendants remain accused, not convicted.

Finding

U.S. authorities officially attributed the campaign to the PRC Ministry of State Security's Hainan bureau and alleged targeting across industries and countries. The charges are unresolved and every operational claim remains an allegation unless independently attributed.

01 / Executive brief

Executive summary

The United States alleged that from 2011 through 2018, officers of the Hainan State Security Department—a provincial arm of the PRC Ministry of State Security—used Hainan Xiandun Technology Development Company as a front to recruit and manage hackers. Four named defendants were charged with a campaign targeting companies, universities, research institutes, governments, and other organizations. S1S2S3

The alleged target list read like a strategic technology portfolio: submersibles and autonomous vehicles, aircraft servicing, chemicals, genetic sequencing, Ebola research, and railway information, among other sectors. U.S. and allied agencies publicly attributed the activity to APT40 and published technical indicators, but the indictment has not produced trial findings; the named individuals are presumed innocent unless proved guilty. S1S2S4

FBI wanted poster showing three identified APT40 defendants and a silhouette for a fourth
document

The FBI's official APT40 poster identifies Zhu Yunmin, Wu Shurong, Ding Xiaoyang, and Cheng Qingmin; no photograph is shown for Cheng. A wanted poster records accusations, not convictions.

Federal Bureau of Investigation · Public domain U.S. government work

02 / The vignette

What happened

A front company supplied the operating layer

According to the indictment, Hainan intelligence officers coordinated hackers through Hainan Xiandun rather than operating only under visible government names. The company allegedly helped recruit technical personnel, provide a workplace, and give state-directed activity a commercial exterior. S1S4

The campaign followed useful technologies

Victims were not confined to one defense contractor or one country. Prosecutors alleged intrusions against dozens of organizations in at least twelve countries and identified targets spanning maritime systems, aviation, biomedicine, transportation, and research. That breadth is the central vignette: cyber access can be managed as a continuing collection program rather than a one-company theft. S1S2

Attribution is not adjudication

CISA, the FBI, and partner agencies released technical advisories linking tools and methods to APT40, while the FBI published a wanted poster naming Zhu Yunmin, Wu Shurong, Ding Xiaoyang, and Cheng Qingmin. Those are official allegations and attributions. Because no cited judgment establishes guilt, this file uses allegation language throughout and does not count the case as adjudicated. S2S3S4

03 / Anatomy

How access became transfer

This chain reconstructs the sequence supported by the cited record. It does not imply that every legitimate relationship follows the same path.

  1. 01

    Relationship established

    Front-company structure alleged

    Hainan intelligence officers allegedly used Hainan Xiandun to recruit and employ hackers. S1S4

  2. 02

    Sensitive access gained

    Remote entry into victim networks

    Advisories attributed exploitation, credential theft, and other intrusion techniques to the campaign. S2S4

  3. 03

    Information acquired

    Strategic data targeted

    The indictment alleged collection from technology, research, government, and industrial victims. S1

  4. 04

    Assets moved

    Network exfiltration alleged

    Compromised infrastructure allegedly enabled information to move from victim systems to campaign operators. S1S4

  5. 05

    Technology put to use

    Intelligence benefit attributed

    U.S. authorities attributed the campaign to a PRC intelligence bureau seeking strategic and commercial information. S1S2

  6. 06

    Competitive harm

    Names, indicators, and charges published

    The United States unsealed charges and agencies released defensive indicators, but no conviction followed in the cited record. S1S2S3

04 / Evidence boundary

What is established—and what is not

Established in the record

  • U.S. authorities formally charged four people and publicly attributed the campaign to the Hainan State Security Department. S1S2S3
  • Government advisories published technical behaviors and indicators associated with APT40 to support network defense. S2S4

Uncertain, limited, or unresolved

  • The charges have not been adjudicated in the cited record; the named defendants are presumed innocent and the alleged victim counts and objectives have not been tested at trial. S1S3

Subject response / procedural context

  • The reviewed U.S. sources present the indictment and attribution. They do not contain an adjudicated response from the defendants or a trial-tested PRC government account. S1S2

05 / Sequence

Timeline

  1. Campaign period begins

    The indictment alleged that the charged conspiracy operated from at least 2011. S1

  2. Charged campaign period ends

    The public charging document described activity continuing through 2018. S1

  3. Indictment and advisories released

    DOJ, FBI, CISA, and partners named the actors and published attribution and defensive guidance. S1S2S3S4

06 / People and institutions

Who appears in the public record

Zhu Yunmin

Hainan State Security Department officer named in the indictment

Outcome: Indicted; not adjudicated

Wu Shurong

Computer hacker named in the indictment

Outcome: Indicted; not adjudicated

Ding Xiaoyang

Hainan State Security Department officer named in the indictment

Outcome: Indicted; not adjudicated

Cheng Qingmin

Hainan State Security Department officer named in the indictment

Outcome: Indicted; not adjudicated

Hainan Xiandun Technology Development Company

Alleged front company used to recruit and support hackers

Originator / affected institution

Targeted companies, universities, and public institutions

Creators and custodians of the allegedly targeted technology and data

07 / Consequences

Documented and attributed harm

Potential / interrupted harm

Authorities alleged intrusions against dozens of organizations in at least twelve countries, but the public record does not quantify verified losses across the campaign. S1

08 / Hindsight analysis

Where leadership could have seen risk

These are our analytic judgments based on the public record, not court findings. They are framed to improve controls without treating nationality as a risk factor.

One campaign crossed many sectors

Organizations evaluating only sector-specific criminals could miss infrastructure and methods reused against unrelated technology portfolios.

Commercial cover obscured sponsorship

A contractor-style company allegedly supplied recruiting and operational support while shielding an intelligence relationship.

09 / Apply the lesson

Actions leaders can take

  1. both

    Use current government indicators

    Map CISA and FBI indicators and techniques to telemetry, identity systems, vulnerability management, and incident-response playbooks.

  2. both

    Share cross-sector signals

    Participate in sector and government information-sharing channels so repeated infrastructure is visible beyond one institution.

  3. both

    Preserve attribution limits

    Separate observed technical behavior, official attribution, charged allegations, and court findings in every executive briefing.

10 / Source record

Sources

Links point to the public record reviewed for this file. Government releases can summarize court proceedings but remain government-authored sources; the source note identifies those limits.

  1. S1

    Four Chinese Nationals Working with Ministry of State Security Charged in Global Computer Intrusion Campaign ↗

    U.S. Department of Justice · Published Jul 19, 2021 · Retrieved Aug 23, 2026

    Charging allegations; defendants are presumed innocent.

    government release
  2. S2

    U.S. Government Releases Indictment and Advisories Detailing Chinese Cyber Campaign ↗

    Cybersecurity and Infrastructure Security Agency · Published Jul 19, 2021 · Retrieved Aug 23, 2026

    government release
  3. S3

    APT40 Cyber Espionage Activities Wanted Poster ↗

    Federal Bureau of Investigation · Published Jul 19, 2021 · Retrieved Aug 23, 2026

    government release
  4. S4

    Tactics, Techniques, and Procedures of Indicted APT40 Actors Associated with China's MSS Hainan State Security Department ↗

    Cybersecurity and Infrastructure Security Agency · Published Jul 19, 2021 · Retrieved Aug 23, 2026

    government release