i-Soon leak: a Chinese hacking contractor
Verified: Documented in primary records or confirmed by reputable inquiry/reporting.
Internal files of the Shanghai company i-Soon, a contractor for Chinese security bodies, appeared on GitHub in February 2024. They included marketing documents and chat messages between staff and clients.
Confirmed
The Associated Press reported that two employees confirmed the leak's authenticity. SentinelOne said the company contracts for the Ministry of Public Security, the Ministry of State Security and the PLA, and that the leaked documents align with earlier threat intelligence on named groups.
Claimed, disputed or not established
Who leaked the files is unknown. A Mandiant analyst quoted by the AP floated a rival intelligence service, a dissatisfied insider or a rival contractor. China's foreign ministry deflected questions.
Reported impact
A rare view of China's commercial hacking industry; SentinelOne said the company appears to have compromised at least 14 governments, per its reading of the files.
Sources (opened in a new tab)
- Associated Press: Chinese cybersecurity leak document dump ↗https://apnews.com/article/china-cybersecurity-leak-document-dump-spying-aac38c75f268b72910a94881ccbb77cb
- SentinelOne: unmasking i-Soon ↗https://www.sentinelone.com/labs/unmasking-i-soon-the-leak-that-revealed-chinas-cyber-operations/
- The Record: China's commercial hacking industry and the i-Soon leaks ↗https://therecord.media/china-commercial-hacking-industry-isoon-leaks
Connected
- Agencies: MSS
- Related case files: Volt Typhoon: alleged PRC pre-positioning in US infrastructure · Salt Typhoon: alleged PRC targeting of telecommunications networks
- Related leaks: Knownsec leak claims (China) · Geedge Networks leak: exporting the Great Firewall
- Case board · Timeline (2024) · Document vault · How we verify leaks
This page describes and cites public reporting. It does not host or link to leaked files, and it names no private individuals.
