Home Report says Chinese state-sponsored hackers breached US internet providers

Report says Chinese state-sponsored hackers breached US internet providers

tl;dr

  • Cybersecurity researchers say Volt Typhoon, a Chinese hacker group, exploited a zero-day flaw to breach ISPs in the U.S. and India.
  • The vulnerability in Versa Networks software impacted four U.S. entities, with ongoing risks reported.
  • This breach highlights Volt Typhoon's strategy of targeting key infrastructure, potentially threatening U.S. security in conflicts.

Volt Typhoon, a hacker group believed to be state-sponsored by China, exploited a software bug to penetrate American and Indian internet companies, researchers have reported.

Lumen Technologies’ threat research and operations division, Black Lotus Labs, says the hackers have taken advantage of a zero-day flaw to breach four U.S. entities, including internet service providers, and another company in India.

The vulnerability was traced to a Versa Networks server product, with the Black Lotus report expressing “moderate confidence” that Volt Typhoon was the perpetrator. The security researchers believe the incident is likely to be ongoing, with Versa offering patches and other mitigations since the flaw was announced last week.

Versa provides software to manage network configurations used by ISPs and managed service providers. Black Lotus Labs said this makes Versa “a critical and attractive target” for threat actors.

Potential for ‘real-world harm’ if conflict arises with U.S.

If this is the work of Volt Typhoon, it is another example of targeting key communications infrastructure for potential future use. Earlier this year, the U.S. government accused the hackers of infiltrating other crucial American utilities such as water and power grids.

With the group considered to be working on behalf of the Beijing administration, the accumulation of assets and access extends its ability to cause “real-world harm” in the event of any conflict situation with the United States, including an invasion of Taiwan.

“This wasn’t limited to just telecoms, but managed service providers and internet service providers,” Mike Horka, a security researcher who investigated this incident, said to TechCrunch.

Black Lotus Labs confirmed it alerted the US cybersecurity agency CISA to the zero-day vulnerability and the hacking campaign.

Featured image via Ideogram

About ReadWrite’s Editorial Process

The ReadWrite Editorial policy involves closely monitoring the gambling and blockchain industries for major developments, new product and brand launches, game releases and other newsworthy events. Editors assign relevant stories to in-house staff writers with expertise in each particular topic area. Before publication, articles go through a rigorous round of editing for accuracy, clarity, and to ensure adherence to ReadWrite's style guidelines.

Graeme Hanna
Tech Journalist

Graeme Hanna is a full-time, freelance writer with significant experience in online news as well as content writing. Since January 2021, he has contributed as a football and news writer for several mainstream UK titles including The Glasgow Times, Rangers Review, Manchester Evening News, MyLondon, Give Me Sport, and the Belfast News Letter. Graeme has worked across several briefs including news and feature writing in addition to other significant work experience in professional services. Now a contributing news writer at ReadWrite.com, he is involved with pitching relevant content for publication as well as writing engaging tech news stories.

Get the biggest iGaming headlines of the day delivered to your inbox

    By signing up, you agree to our Terms and Privacy Policy. Unsubscribe anytime.

    Gambling News

    Explore the latest in online gambling with our curated updates. We cut through the noise to deliver concise, relevant insights, keeping you informed about the ever-changing world of iGaming and its most important trends.

    In-Depth Strategy Guides

    Elevate your game with tailored strategies for sports betting, table games, slots, and poker. Learn how to maximize bonuses, refine your tactics, and boost your chances to beat the house.

    Unbiased Expert Reviews

    Honest and transparent reviews of sportsbooks, casinos and poker rooms crafted through industry expertise and in-depth analysis. Delve into intricacies, get the best bonus deals, and stay ahead with our trustworthy guides.