China 'hackers' attack Google

Read more below

By JOHN MARKOFF AND DAVID BARBOZA NEW YORK TIMES NEWS SERVICE
  • Published 3.06.11
  •  

San Francisco, June 2: Google said yesterday that hundreds of users of Gmail, its email service, had been the targets of clandestine attacks apparently originating in China that were aimed at stealing their passwords and monitoring their email.

In a blog post, the company said the victims included senior government officials in the US, Chinese political activists, officials in several Asian countries, military personnel and journalists.

It is the second time Google has pointed to an area of China as the source of an Internet intrusion. Its latest announcement is likely to further ratchet up the tension between the company and Chinese authorities.

Today, the Chinese government rejected suggestions that it was linked to the attack.

Last year, Google said it had traced a sophisticated invasion of its computer systems to people based in China. The accusation led to a rupture of the company’s relationship with China and a decision by Google not to cooperate with China’s censorship demands. As a result, Google decided to base its Chinese search engine in Hong Kong.

The more recent attacks were not as technically advanced, relying on a common technique known as phishing to trick users into handing over their passwords. But Google’s announcement was unusual in that it put a spotlight on the scale, apparent origins and carefully selected targets of a coordinated campaign to hijack email accounts.

Google said that once the intruders had logged into the accounts, they could change settings for mail forwarding so that copies of messages would be sent to another address. The company said it had “disrupted” the campaign and had notified the victims as well as government agencies. Executives at Google declined to comment beyond the blog post.

The company recommended that Gmail users take additional security steps, like using a Google service known as two-step verification, to make it more difficult to compromise their email accounts. But it emphasised that the password thefts were not the result of a general security problem with Gmail.

The Chinese foreign ministry said today that the government had no involvement in any such attacks, declaring that it “consistently opposes any criminal activities that damage the Internet and computer networks including hacking and cracks down these activities according to law”.

“Hacking is an international issue, and China is also a victim of hacking,” according to an official transcript of a foreign ministry spokesman’s remarks. “The claim that China supports hacking is completely created out of nothing, and is out of ulterior motives.”

The official Chinese news agency’s report on the episode repeatedly cast doubt on Google’s own credibility and past practices.

Google acknowledged that it had been alerted to the problem in part by Mila Parkour, a security researcher in Washington who posted evidence of a type of phishing attack on her blog in February. She documented examples of what has recently been described as a “man-in-the-mailbox” attack, in which the intruder uses the account of one victim and his email contacts to gain the trust of a new victim.