State-sponsored hacker arrested in Italy, US seeks extradition
A suspected Chinese state-sponsored hacker has been arrested in Italy and now faces extradition to the United States. The individual is accused of taking part in a series of intrusions between 2020 and 2021 that authorities link to campaigns associated with the HAFNIUM group. Those campaigns hit organisations worldwide, in government and the private sector alike. The arrest follows a US indictment and rests on cooperation between law enforcement agencies in several countries.
What this means for your organisation
The case does not change the threat picture in itself, but it says something about timescales. The intrusions took place five or six years ago and are only now reaching a courtroom. For a Norwegian organisation that carries two implications: state-sponsored actors work on a patience horizon that outlasts most internal project plans, and logs from back then are often the only thing that can tell you whether you were affected. If the case goes to trial, details of the operations will become public for the first time, which may provide fresh indicators to search for.
Berigo recommends
- Establish how long you actually retain security logs, and judge whether that period matches how long an advanced actor can stay undetected.
- Review whether the organisation was exposed to the known HAFNIUM campaigns of 2020 and 2021, and what was done at the time.
- Put a routine in place for tracking indicators published through court cases and government reporting, not only vendor advisories.
- Settle in the management team who owns the decision to notify police when state-sponsored activity is suspected.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch