Chinese-linked Hackers Steal US, Canada Data
Analysis based on 7 articles · First reported Jun 15, 2026 · Last updated Jun 15, 2026
The cyberespionage campaign by UNC6508 against United States and Canada research institutions, linked to China, could lead to increased cybersecurity spending in the defense and healthcare sectors. The theft of sensitive data, particularly in AI and military strategy, may impact the competitive landscape and national security, potentially affecting technology and defense stocks negatively due to heightened risk.
A Chinese-linked hacking group, identified as UNC6508, conducted a prolonged cyberespionage campaign from September 2023 to November 2025, secretly stealing data from academic, medical, and military research institutions in the United States and Canada. The stolen information included defense intelligence, military strategy in the Indo-Pacific, artificial intelligence, unmanned vehicles, cyber warfare programs, and medical research. Alphabet Inc.'s Threat Intelligence Group detected the activity and attributed it to UNC6508, noting its methods are consistent with Chinese-linked hacking. The hackers exploited vulnerabilities in REDCap's web application to gain access and set up automated email forwarding for sensitive keywords. Alphabet Inc. notified the affected organizations, highlighting the persistent threat of state-sponsored cyberespionage.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard