Although the media world seems to predominantly be concerned with the various goings-on in Russia at the moment, there is another country that is receiving more and more journalistic scrutiny. If the allegations that have been made are true, then this country may very well, through the use of both hacking and manipulation of online opinion, play a serious part in not only the next UK general election but the presidential election in the United States. We are talking, of course, about China. In this article, we shall take a look at the allegations leveled at the Chinese government, the evidence to support these claims, and just exactly what the ramifications might be if these accusations turn out to be true.
Background
In order to properly explain all of this, it is necessary to take a short journey back in time. On the 13th of January 2010, Google issued a statement saying that it had been the victim of an extremely sophisticated cyber attack. According to Dmitri Alperovitch, the then Vice President of Threat Research for McAfee:
“The attackers used nearly a dozen pieces of malware and several levels of encryption to burrow deeply into the bowels of company networks and obscure their activity. The encryption was highly successful in obfuscating the attack and avoiding common detection methods. We haven’t seen encryption at this level. It was highly sophisticated.”
Key Takeaways
- China is under scrutiny for alleged hacking and manipulation of online opinion in UK and US elections.
- APT 31, a Chinese hacking group, has targeted high-ranking officials and voter databases in the UK and US.
- The UK Electoral Commission’s voter database breach raises concerns about election integrity and public trust.
- Chinese hacking efforts aim to gain insights into political views and potentially manipulate elections.
- Previous US accusations against China were later found to be hypocritical due to similar US activities.
Now, even back in 2010, this kind of covert espionage by the Chinese government was not new. In fact, about 33 other US companies were involved. However, up until this point, companies had remained largely silent on the matter, preferring instead to deal with matters in-house, as it were, rather than risking the inevitable loss of public trust that such a breach would bring about.
In going public, although Google never actually directly accused the Chinese government at that point, they certainly gave the press the opportunity to do so, and do so they did. For a long time after that, pretty much every non-Chinese news company on the planet happily lambasted China, its government, and its tech firms. After all, they had compromised the security of Google, the world’s favorite search engine; what else would they be prepared to do?
In 2012, Intelligence Committee Chairman Mike Rogers even appeared on 60 Minutes during a time when many people were starting to doubt Chinese-made telecommunications equipment, to say: “Find another vendor [than Huawei] if you care about your intellectual property; if you care about your consumers’ privacy, and you care about the national security of the United States of America.”
Now, we are by no means saying that either the press or the United States government behaved inappropriately. Almost everything that China had been accused of would later turn out to be true. However, it is a sad fact that whenever an organization, be that press or political, begins to spout such concentrated righteous indignation at any one target, then they are often, not always but often, engaging in that most famous of magician’s tricks: look over there, not over here.
In 2014, following revelations made by former National Security Agency contractor Edward Snowden, it turned out that the United States government had been doing exactly this. An article published in The Guardian on the 22nd of March 2014 stated that:
“The National Security Agency created ‘backdoors’ into networks maintained by the Chinese telecommunications company Huawei.”
Sadly for the United States government, this, along with the thousands of other documents released by Snowden, quickly dispelled the elaborately constructed illusion that China were the only bad guys when it came to hacking.
This inconvenient truth may very well have permanently diverted attention away from China if it were not for the events of 2015. In July of that year, the US Office of Personnel Management announced that the private records of more than 22 million American civil servants had been stolen.
Although the American government did not officially blame the Chinese, several of its security analysts were not so diplomatic. One government employee told Vice that:
“I think the intelligence community feels pretty confident that we know who is involved.” When asked to explain what was taken he said: “SF86 and SF85s, which are the standard forms which employees fill out to obtain security clearances. On those forms, you had a lot of proprietary information about you, about the people that you live with, your Social Security number, your date of birth, what schools you went to, your employment history.
Basically, a lot of personally identifiable information that we consider to be extremely sensitive.” When asked just how damaging this was, he went on to say that the data contained within these forms could be used to target United States government employees for many, many years to come.
From then until now, blame has been passed back and forth between China and pretty much every country in the Western world. However, recent claims made by both the British and United States governments seemed to indicate that China has taken hacking well beyond corporate espionage and mass data gathering and is now attempting to artificially alter the structure of politics.
What We Know So Far
APT 31
Throughout the Western cybersecurity community, the acronym APT (or Advanced Persistent Threat) is used to identify hacking groups which have been proven to be linked to foreign governments. According to Mandiant, an American cybersecurity company, there are currently about 40 of these groups, at least 20 of which are believed to be linked to China. So, why is this significant? Well, one of these China-linked groups, APT 31, has spent quite a lot of time in the headlines recently.
Before we get into what they may or may not have done, let us first find out who they are.
Watch The Project Briefing
Open Video
Video Briefing
Chinese Hacks: What They Mean for the World
Into the Shadows Insider
Cases and investigations, straight from Simon's notes.
One email each week — fresh projects, deep dives, and behind-the-scenes notes.
APT 31, also referred to on occasion as Zirconium, is believed to have been formed at some point during 2010. Although to the casual observer they appeared to be nothing more than an IT business, operating under the name Wuhan Xiaoruizhi Science and Technology Company, they were in fact a sophisticated, well-organized group of State-sponsored intelligence officers and contract hackers. Over the years, they appear to have racked up quite an impressive number of high-profile hits. Not only were they responsible for a massive breach of Microsoft mail servers in 2021, the significance of which we shall return to shortly, but, according to the website of ENISA (The EU Cybersecurity Agency):
“In 2020, the Norwegian Police Security Service (PST) concluded a two years and a half investigation of a 2018 cyberattack against the Norwegian state administration and the cloud service provider Visma AG. According to public news, the threat actor behind the attacks was APT31. The Parliament of Finland had fallen victim to a breach in December 2020. In March 2021, the Finnish national authorities disclosed that their investigations pointed to APT31.
These claims would be officially verified in March 2024. In July 2021, the French national cybersecurity agency (ANSSI) warned of an ongoing campaign by the APT31 threat actor against a large number of French organizations.”
So, as you can see, they have been rather busy. But, as far as we can ascertain, and keep in mind that this is a developing story with new information coming out every day, the group’s most serious transgressions have involved hacking into the email accounts of high-ranking United States political officials. It was these crimes that led to the United States charging seven Chinese hackers with conspiracy to commit computer intrusions and conspiracy to commit wire fraud. But how and why did they do this?
Through a combination of the aforementioned Microsoft mail server attacks, previously unknown vulnerabilities in the now outdated web browser Internet Explorer, and an exceptionally widespread email phishing campaign, members of APT31 targeted journalists, members of the military, and politicians from both main parties along with their families. The reason? Primarily to gain insight into these individuals’ particular views on China in order to provide Beijing with better insight as to how future international opinion might change on such things as trade tariffs, intellectual property disputes, or any number of other things that might make the political stage difficult for the communist country.
In addition to providing advanced warning, such wide-reaching system control could very easily be used to manipulate an election in much the same way that Russian hackers attempted to do in 2016. To be clear, the current charges being brought by the Department of Justice are not claiming that this happened, just that the amount of data collected and systems compromised had made it a possibility.
As we previously mentioned, these concerns and retaliatory actions are not limited to the United States. In the UK, a similar digital espionage campaign, or perhaps an extension of the one that took place in the US, has recently been reported. The National Cyber Security Centre, a branch of GCHQ, has accused the Chinese hackers of two serious cyber attacks and placed sanctions on several individuals and one company.
The first of these was almost exactly the same as the email phishing attack used in the United States and was, presumably, carried out for similar reasons. As in the US, it was predominantly those who had previously spoken out against China who were targeted. Although the official government line is that this particular attack was unsuccessful, or at least that no useful information was obtained, the same can definitely not be said with regards to the second, and arguably much more sinister, incident.
In August 2021, copies of voter registration databases were stolen from the computer systems of the UK Electoral Commission. These registers contained the personal information of nearly 40,000,000 UK citizens. At this point, you may very well be wondering just exactly why this is more sinister than the security of top government officials being compromised?
Well, that depends on how you choose to look at the situation. In both cases, the security agencies and the Electoral Commission claim that neither attack, in the grand scheme of things, has caused too many problems. Whilst if you believe the government, and you’ll have to make up your own mind on that, attempts to compromise email accounts were quickly detected, the very fact that these vulnerabilities were available for exploitation in the first place brings into question the competence of those whose job it is to protect sensitive information.
As for the attack on the Electoral Commission, not only does losing the personal information of 40 million citizens further drive home the previous point, but we would argue that the situation is even worse than that. In spite of its plethora of political failings, the United Kingdom has, by and large, never encountered much controversy when it comes to general elections. The idea that an election could be tampered with has never, to the best of our knowledge, been given much, if any, credence.
However, since these security issues have been both exploited and widely reported on, seeds of doubt have started to spread among voters. Whereas suggesting that the election might be rigged would have previously got you laughed at, there are now people online and appearing on talk shows who are suggesting that this might indeed happen.
Therein, perhaps, lies the true power of these state-funded hacking campaigns. You don’t actually need to have the power to rig an election; you just have to be able to convince enough people that it is a possibility and the situation will snowball from there. The whole world saw what happened in America when some people believed that an election had been rigged; imagine the disarray that the Chinese government could cause throughout the Western world if the events that took place on the 6th of January in Washington could not only be repeated in America on a larger scale but orchestrated in many countries around the world? When looked at from this perspective, what appears to be an inconvenient data breach could have massive, world-changing ramifications.
Key Takeaways
- China is under scrutiny for alleged hacking and manipulation of online opinion in UK and US elections.
- APT 31, a Chinese hacking group, has targeted high-ranking officials and voter databases in the UK and US.
- The UK Electoral Commission’s voter database breach raises concerns about election integrity and public trust.
- Chinese hacking efforts aim to gain insights into political views and potentially manipulate elections.
- Previous US accusations against China were later found to be hypocritical due to similar US activities.

Simon Whistler
Simon Whistler is one of YouTube's most prolific documentary presenters, known for calm, authoritative deep dives into true crime, disappearances, and the world's most enduring unsolved cases. Into the Shadows is his companion archive for the cases he can't stop thinking about.
Frequently Asked Questions
What was the significant cyber attack on Google in 2010?
On January 13, 2010, Google issued a statement saying that it had been the victim of an extremely sophisticated cyber attack. The attackers used nearly a dozen pieces of malware and several levels of encryption to burrow deeply into the bowels of company networks and obscure their activity.
What is APT 31 and what are some of its notable activities?
APT 31, also known as Zirconium, is a state-sponsored hacking group linked to China. Notable activities include a massive breach of Microsoft mail servers in 2021, cyberattacks against the Norwegian state administration and the cloud service provider Visma AG in 2018, and breaches of the Parliament of Finland in December 2020 and the French national cybersecurity agency in July 2021.
What was the impact of the 2021 cyber attack on the UK Electoral Commission?
In August 2021, copies of voter registration databases were stolen from the computer systems of the UK Electoral Commission, containing the personal information of nearly 40 million UK citizens. This attack raised concerns about the possibility of election tampering and has led to seeds of doubt among voters.
What was the significance of the 2015 data breach at the US Office of Personnel Management?
In July 2015, the US Office of Personnel Management announced that the private records of more than 22 million American civil servants had been stolen. The data included sensitive personally identifiable information that could be used to target United States government employees for many years to come.
What did the US government accuse China of in 2012 regarding Huawei?
In 2012, Intelligence Committee Chairman Mike Rogers appeared on 60 Minutes and advised finding another vendor if you care about intellectual property, consumer privacy, and national security, implying concerns about Huawei’s involvement in cyber espionage.
What was the response of the US government to the 2010 Google cyber attack?
Although Google never directly accused the Chinese government, the press used the opportunity to lambast China, its government, and its tech firms. This led to widespread scrutiny and accusations against China for cyber espionage.
What revelations did Edward Snowden make in 2014 regarding the US and China?
In 2014, Edward Snowden revealed that the US National Security Agency had created ‘backdoors’ into networks maintained by the Chinese telecommunications company Huawei, dispelling the illusion that China was the sole perpetrator of hacking activities.
What are the potential ramifications of Chinese hacking on global politics?
Chinese hacking activities, if true, could significantly impact global politics by manipulating public opinion, compromising election integrity, and causing widespread disarray. The mere suggestion of election tampering can lead to significant distrust and unrest, as seen in the US.
What methods did APT 31 use to target US political officials?
APT 31 used a combination of Microsoft mail server attacks, vulnerabilities in Internet Explorer, and a widespread email phishing campaign to target journalists, military members, and politicians from both main parties, aiming to gain insights into their views on China.
What was the UK’s response to the Chinese cyber attacks in 2021?
The UK’s National Cyber Security Centre accused Chinese hackers of two serious cyber attacks and placed sanctions on several individuals and one company. The attacks included an email phishing campaign targeting those who had spoken out against China and a breach of the UK Electoral Commission’s voter registration databases.
Sources
- Original Into the Shadows video: Chinese Hacks: What They Mean for the World
- Hero image source by Singh PreetManak / openverse, by.
Related Coverage
Official Store
Support the channel and pick up exclusive gear and desk essentials at the official store.
Visit Store



