FRIDAY, OCTOBER 9, 2026|No. 18022
News · Cyber · Espionage

Google Reveals Chinese Hackers Stole Data from US and Canada Research Institutions

Google reported that a Chinese-linked hacker group infiltrated academic, medical, and military research institutions in the US and Canada for over a year, stealing sensitive data.

Google threat analysts discovered a year-long cyber espionage campaign targeting research institutions in the US and Canada.
Google threat analysts discovered a year-long cyber espionage campaign targeting research institutions in the US and Canada.
1 sources
Pipeline ingest
3 reads
Positive / Neutral / Negative
3 countries
Related coverage

Illustration.

Google said on Tuesday that a hacker group linked to China secretly stole data from academic, medical, and military research institutions in the United States and Canada for more than a year without being detected.

According to a report released by Google's Threat Intelligence Group, the hackers between September 2023 and November 2025 attempted to steal information related to defense intelligence, military strategy in the Indo-Pacific region, artificial intelligence, drones, cyber warfare plans, and medical research.

Google did not disclose the names of the targeted institutions but said they covered a wide range of fields, including drug development, clinical trials, public health policy, and military preparedness, collectively employing thousands of people and holding billions of dollars in research funding.

Google said the theft was carried out by a hacker group called UNC6508, a relatively new and little-known cyber espionage group.

McNamara, deputy director of Google's Threat Intelligence Group, said the group's methods in many ways resemble the Chinese hacking activities observed over the years, focusing on collecting intelligence that the Chinese government might be interested in.

The Chinese embassy in the United States did not immediately respond to a request for comment. Beijing has consistently denied engaging in or harboring illegal hacking activities.

The cyberattacks can be traced back to at least September 2023, when the hackers exploited a vulnerability in REDCap servers. REDCap is a web application widely used by non-profit organizations to build and manage online surveys and databases.

Researchers said the hackers used self-made malware to steal legitimate REDCap login credentials, thereby gaining access to target networks, and set up systems to automatically forward emails containing nearly 150 keywords and search terms to Gmail accounts under their control.

REDCap did not respond to a request for comment.

The keywords and search terms set up included phone numbers and emails of personnel at targeted institutions, as well as terms related to geopolitics, military strategy, advanced technology, and medical research.

Researchers said Google eventually discovered that multiple U.S. and Canadian institutions had been breached and notified them one by one.

PAN's pipeline reviewed approximately 1 open sources for this article. No human editor reviewed this article before publication.

Related Reads

Show on timeline →

Earlier on PAN

More in Technology →