World June 15, 2026 10:05 AM

Google Says Chinese-Linked Hackers Infiltrated North American Research Networks for Over a Year

Campaign targeted a wide range of academic, medical and military research through REDCap vulnerabilities and credential theft

By Jordan Park
Share
Twitter Reddit Facebook LinkedIn

Google’s Threat Intelligence Group reported that a hacking collective it tracks as UNC6508 conducted a covert data-stealing campaign against U.S. and Canadian research institutions from September 2023 through November 2025. Attackers exploited REDCap server flaws to harvest credentials and set up automated email exfiltration tied to nearly 150 search terms, targeting topics from defense and Indo-Pacific military strategy to AI, unmanned systems and medical research.

Google Says Chinese-Linked Hackers Infiltrated North American Research Networks for Over a Year
Summarize with
ChatGPT Perplexity Claude Grok Gemini

Key Points

  • A hacking group tracked by Google as UNC6508 conducted an espionage campaign from September 2023 to November 2025 against U.S. and Canadian research institutions.
  • Attackers exploited vulnerabilities in REDCap servers to steal legitimate login credentials and installed automated forwarding of emails matching nearly 150 keywords to a Gmail account they controlled.
  • Targeted domains included defense intelligence, Indo-Pacific military strategy, AI, unmanned systems, cyber warfare programs, drug discovery, clinical trials and public health policy; affected organizations employ thousands and have combined research budgets in the billions.

Google's Threat Intelligence Group disclosed that a hacking operation linked to China infiltrated research institutions across the United States and Canada for more than a year before detection. The campaign - attributed by Google to a group it calls UNC6508 - ran from September 2023 until November 2025, and focused on collecting information spanning defense intelligence, military strategy in the Indo-Pacific, artificial intelligence, unmanned vehicles, cyber warfare programs and medical research.

The search and seizure of data, according to Google's report, encompassed organizations engaged in drug discovery, clinical trials, public health policy and military readiness. Google said these institutions employ thousands of people and operate with combined research budgets that reach into the billions of dollars.

Researchers from Google's Threat Intelligence Group said UNC6508 is a relatively new and not widely recognized actor in cyberespionage, but its tactics mirror patterns long associated with Chinese-linked operations. Luke McNamara, deputy chief analyst at the group, said the group's methods are broadly consistent with Chinese-linked hacking activity seen over many years, focused on gathering information likely to be of interest to the Chinese government.

The earliest activity tied to this campaign dates to September 2023. Google reported that the attackers exploited vulnerabilities in servers running REDCap, a web application commonly used by nonprofit organizations to create and manage online surveys and databases. Using bespoke malicious software, the hackers obtained legitimate REDCap login credentials and used those credentials to penetrate targeted networks.

Once inside, the attackers implemented an automated system to siphon potentially valuable communications. Google said the intruders set up a process that forwarded emails containing nearly 150 specific keywords and search terms to a Gmail account they controlled. The keyword set included contact details such as phone numbers and email addresses for people at the targeted institutions, as well as terms connected to geo-strategic policy, military planning, advanced technology and medical research.

Google said it ultimately identified multiple compromised organizations across the U.S. and Canada and notified each one. The company did not disclose the identities of the targeted institutions.

The Chinese Embassy in Washington did not immediately respond to a request for comment, the report noted. The statement also said Beijing regularly denies carrying out or condoning illicit hacking activity.


Context and implications

  • The campaign targeted a mix of academic, medical and military research, indicating cross-sector interest in the stolen material.
  • Techniques involved exploiting a widely used research tool - REDCap - and harvesting legitimate credentials rather than relying solely on zero-day exploits.
  • Automated email monitoring tied to a sizeable keyword list suggests a broad intelligence collection effort rather than narrow, case-by-case intrusions.

Google's disclosure provides a detailed account of the intrusion methods and the breadth of topics targeted, but it did not identify the affected organizations or quantify the precise volume of data exfiltrated. The company has attributed the campaign to UNC6508 based on its analysis of tactics, techniques and procedures.

Risks

  • Ongoing exposure of sensitive research data could affect national security and defense-related programs - impacting defense contractors and government research budgets.
  • Medical and biotech research organizations face risks to intellectual property and clinical data integrity, with potential downstream effects on drug development timelines and investment decisions.
  • Wider academic and public health institutions may experience operational disruption and reputational damage if intrusions remain undetected or if notification and remediation are incomplete - affecting funding and collaboration.

More from World

Four Palestinians Killed in Gaza as Mediators Resume Ceasefire Talks in Cairo Jun 15, 2026 Kyiv’s Dormition Cathedral Damaged in Strike; Authorities Assess Extent of Losses Jun 15, 2026 Houston Fan Festival Suspended Ahead of Forecast Flooding; Stadium Match Expected to Proceed Jun 15, 2026 Supreme Court to Review Challenge Over Extended Detention of Convicted Immigrants Without Bond Hearings Jun 15, 2026 Netanyahu and Trump at Odds After U.S.-Iran Halt Leaves Israel Constrained Jun 15, 2026