HeadlinesBriefing favicon HeadlinesBriefing.com

Palo Alto Softens China Hack Report Amid Beijing Retaliation Fears

Yahoo Tech •
×

Palo Alto Networks chose not to attribute a global cyberespionage campaign to China in its latest report, despite internal findings linking the hackers to Beijing. The cybersecurity firm made this decision following a Chinese government ban on its software and that of other U.S. and Israeli companies, according to sources familiar with the matter.

The company's Unit 42 initially drafted a report identifying the hacking group TGR-STA-1030 as connected to Beijing, but executives ordered the language softened to describe them only as a "state-aligned group that operates out of Asia." The sources said this change was driven by fears of retaliation against Palo Alto's personnel in China or its clients worldwide, particularly after the January software ban.

While Palo Alto's final report avoided naming China, researchers noted several clues pointing to Chinese involvement, including activity patterns matching the GMT+8 time zone and targeting decisions coinciding with diplomatic events. The incident highlights the difficult position cybersecurity firms face when attributing state-sponsored attacks, especially those with operations in the countries they're investigating. As one academic noted, companies must weigh the industry recognition of exposing foreign spies against the potential risks to their local staff.