Hackers linked to Chinese government stole millions in Covid benefits, Secret Service says

Hackers linked to the Chinese government stole at least $20 million in U.S. Covid relief benefits, including Small Business Administration loans and unemployment insurance funds in over a dozen states, according to the Secret Service.

The theft of taxpayer funds by the Chengdu-based hacking group known as APT41 is the first instance of pandemic fraud tied to foreign, state-sponsored cybercriminals that the U.S. government has acknowledged publicly, but may just be the tip of the iceberg, say U.S. law enforcement officials and cybersecurity experts.

The officials and experts, most speaking on condition of anonymity because of the sensitivity of the subject matter, say other federal investigations of pandemic fraud also seem to point back to foreign state-affiliated hackers.

“It would be crazy to think this group didn’t target all 50 states,” said Roy Dotson, national pandemic fraud recovery coordinator for the Secret Service, who also acts as a liaison to other federal agencies probing pandemic fraud.

The Secret Service declined to confirm the scope of other investigations, other than to say there are more than 1,000 ongoing investigations involving transnational and domestic criminal actors defrauding public benefits programs, and APT41 is “a notable player.”

And whether or not the Chinese government directed APT41 to loot U.S. taxpayer funds or simply looked the other way, multiple current and former U.S. officials say the fact of the theft itself is a troubling development that raises the stakes. One senior Justice Department official called it “dangerous” and said it had serious national security implications.

“I’ve never seen them target government money before,” said John Hultquist, head of intelligence analysis at cybersecurity firm Mandiant. “That would be an escalation.” 

The Chinese Embassy in Washington did not respond to requests for comment.

‘The horse is out of the barn’

 As soon as state governments began disbursing Covid unemployment funds in 2020, cybercriminals began to siphon off a significant percentage.

The Labor Department has reported an improper payment rate of roughly 20 percent for the $872.5 billion in federal pandemic unemployment funds, though the true cost of the fraud is likely higher, administration officials from multiple agencies say.

In-depth analysis of four states showed 42.4% of pandemic benefits were paid improperly in the first six months, the department’s watchdog reported to Congress last week.

Heritage Foundation analysis of Labor Department data estimated excess unemployment benefit payments of more than $350 billion between April 2020 and May 2021.

“Whether it’s 350, 400 or 500 billion, at this point, the horse is out of the barn,” said Linda Miller, the former deputy executive director of the Pandemic Response Accountability Committee, the federal government’s Covid relief fraud watchdog.

Acting U.S. Attorney for the District of Columbia Michael R. Sherwin speaks about charges and arrests related to a computer intrusion campaign tied to the Chinese government by a group called APT 41 at the Department of Justice on Sept. 16, 2020, in Washington.Tasos Katopodis / Pool via Getty Images file

By the time that Covid relief funds appeared as a target of opportunity in 2020, APT41, which emerged more than a decade ago, had already become the “workhorse” of cyberespionage operations that benefit the Chinese government, according to cyber experts and current and former officials from multiple agencies. The Secret Service said in a statement that it considers APT41 a Chinese state-sponsored, cyber threat group that is highly adept at conducting espionage missions and financial crimes for personal gain.”

Ambassador Nathaniel Fick, head of the State Department’s Bureau of Cyberspace and Digital Policy, said cyber espionage is a long-time Chinese national priority aimed at strengthening its geopolitical position.

“The United States is target number one, because we are competitor number one.” Fick told NBC News. “It’s a really comprehensive, multi-decade, well-considered, well-resourced, well-planned, well-executed strategy.”

American officials have blamed Chinese actors for the Office of Personnel Management breachthe Anthem Health breach, and the Equifax breach, among others.

The experts and officials describe the Chinese model of “state-sponsored” hackers as a network of semi-independent groups conducting contract work in service of government espionage. The Chinese government may direct a hacking group to attack a certain target. APT41, also known to cybersecurity firms as Winnti, Barium and Wicked Panda, fits the model and is considered a particularly prolific Chinese intelligence asset, known to commit financial crimes on the side.

Demian Ahn, a former assistant U.S. attorney who indicted five APT41 hackers in 2019 and 2020, said the evidence showed APT41 had tremendous reach and resources. The defendants, who were accused of infiltrating governments and companies around the world while conducting ransomware attacks and mining cryptocurrency, talked “about having tens of thousands of machines at one time, as part of their efforts to obtain information about others, and also to generate criminal profits.” None of the five Chinese nationals indicted have been extradited, and the cases remain open.

APT41’s intrusion methods have included hacking legitimate software and weaponizing it against innocent users, including businesses and governments. Another tactic involves tracking public disclosures about security flaws in legitimate software. APT41 uses that information to target customers who don’t immediately update their software, according to a former Justice Department official familiar with the group.

The primary purpose of APT41’s state-directed activity, say the experts and officials, is believed to be collecting personally identifying information and data about American citizens, institutions and businesses that can be used by China for espionage purposes.

“They have the patience, the sophistication and the resources to carry out hacking that has a direct impact on national security,” said a former Justice Department official familiar with the group.

Law enforcement officials and counterintelligence experts have testified to Congress that by now, every adult American has had all or most of their personal data stolen by the Chinese government. 

‘Wild West’

Beijing has increasingly turned its focus to breaching U.S. critical infrastructure in recent years, say current and former officials and China and cybersecurity experts, with worldwide campaigns driven by APT41.

China’s targets include state governments, which can have inadequate cybersecurity defenses. “The state governments don’t allocate a lot of cyber protection money to their state I.T. infrastructure,” said William Evanina, the former director of the National Counterintelligence and Security Center, part of the Office of the Director of National Intelligence. “So it’s really an unprotected Wild West.”

The Covid fraud scheme that the Secret Service has publicly linked to APT41 began in mid-2020 and spanned 2,000 accounts associated with over 40,000 financial transactions.

“Where their sophistication comes in is the ability to work heavily and quickly,” said the Secret Service’s Dotson.

The agency said it has been able to recover about half of the stolen $20 million.

But while Evanina and other officials and experts consider APT41’s breach of state systems a national security issue, they aren’t convinced that stealing Covid funds was a goal of the Chinese government. Such thefts increase the risk of criminal prosecution and make it harder for China to obscure the state’s role. They believe that the Chinese government may have simply tolerated the hackers making a profit off their labors.

Many believe the hackers are still inside state IT systems.

Mandiant, which contracts with over 75 state and local government organizations and agencies, issued a report in March that the APT41 had infiltrated six — and likely more — state governments using back doors in popular software and was exfiltrating data on citizens.

Hultquist told NBC News that Mandiant analysts discovered at least two occasions involving interactions with servers associated with state benefits after May 2021.

Current officials would not comment about whether APT41 still had access to state government networks after being discovered last year. 

The Department of Labor, the Small Business Administration, the Cybersecurity and Infrastructure Security Agency and the White House all declined to comment and referred NBC News to the DOJ. The FBI and DOJ declined to comment. The Department of Homeland Security did not respond to requests for comment.

But Evanina said, “Once you are in these systems with intent to promulgate theft of PII [Personally Identifying Information], you’re in forever,” noting that at the state and local level many disparate systems share an interconnected domain. “Unless,” he said, “you tear down the systems and replace everything.”

State agencies across the country continue to struggle against invisible online attackers, many lacking the proper funding and expertise to secure their online benefits systems. 

“If we can come together and really have open and honest conversations about what works well and what went very wrong, we would just be in a much better place to stop this,” said Maryland Secretary of Labor Tiffany Robinson, who said her state’s system is still bogged down by thousands of fraudulent applications and phone calls each week. “Because this is not over.”

Federal officials acknowledge they are nowhere close to fully accounting for what really happened to benefits programs in the pandemic. 

“A lot of these criminals, we’ll never be able to indict and locate,” said a federal law enforcement official with direct knowledge of fraud investigations involving China-based hackers. “With the internet and the dark web, it’s borderless.”


Football news:

<!DOCTYPE html>
Kane on Tuchel: A wonderful man, full of ideas. Thomas in person says what he thinks
Zarema about Kuziaev's 350,000 euros a year in Le Havre: Translate it into rubles - it's not that little. It is commendable that he left
Aleksandr Mostovoy on Wendel: Two months of walking around in the middle of nowhere and then coming back and dragging the team - that's top level
Sheffield United have bought Euro U21 champion Archer from Aston Villa for £18.5million
Alexander Medvedev on SKA: Without Gazprom, there would be no Zenit titles. There is a winning wave in the city. The next victory in the Gagarin Cup will be in the spring
Smolnikov ended his career at the age of 35. He became the Russian champion three times with Zenit

3:19 Diamondbacks World Series bettor four wins away from $1 million payout
3:09 Giants legend Carl Banks slams WFAN hosts for Kayvon Thibodeaux rip job
3:01 Struggling Oilers will be missing injured star Connor McDavid vs. Rangers
2:52 Elias Manoel notches hat trick as Red Bulls advance in playoffs
2:48 Disgraceful Karine Jean-Pierre’s words are just callous amid Hamas violence
2:46 SEAN HANNITY: The People's House is now officially back in business
2:42 At least 16 killed in shootings in Maine, law enforcement officials say
2:40 Georgia murder fugitive kills self when police on hunt for other escaped inmates show up at door
2:31 US Auto Workers Union Reaches Preliminary Deal With Ford
2:29 Jayson Tatum shades new Celtics teammate Jrue Holiday: ‘You old’
2:24 Magazine scrubs sections of Jake Sullivan’s essay praising Biden’s performance in the Middle East
2:21 Nets’ opening-night comeback falls short in last-second heartbreaker vs. Cavaliers
2:18 JESSE WATTERS: We have a compromised president in the White House
2:10 Kristaps Porzingis’ late heroics sink Knicks in crushing opening-night loss
2:09 FBI hindered Hunter probe — and David Weiss skipped briefing on Biden bribery allegations, US attorney testifies
1:54 At least 16 killed in shooting in Maine, law enforcement officials says
1:54 At least 16 killed in shooting in Maine, law enforcement officials say
1:51 Sterling Shepard in punt return mix vs. Jets despite Commanders muff
1:47 Craig Counsell’s true Mets intentions are about to become clear
1:45 Tim Wakefield's wife, Stacy, shares powerful message late husband left for her
1:41 Kyle Richards ‘taken aback’ by Mauricio Umansky, ‘DWTS’ partner Emma Slater holding hands: Something is ‘going on there’
1:37 Ford and UAW reach tentative agreement that would end 6-week strike
1:36 LAURA INGRAHAM: This is a propaganda victory for Hamas
1:35 Actor Zachery Ty Bryan pleads guilty to felony assault stemming from domestic violence arrest
1:26 NYC college's Jewish students seen locked inside library as anti-Israel protest moves through building
1:24 Blackpink’s Jisoo and actor Ahn Bo-hyun split after brief romance: report
1:20 Police respond to active shooter in Lewiston, Maine; medical center treating 'mass casualty event'
1:20 At least 22 dead, up to 60 wounded in mass shooting in Lewiston, Maine
1:20 Stream It Or Skip It: ‘30 Coins’ Season 2 on Max, The Return Of This Ambitious Religious Horror Series From Spain (Now With More Paul Giamatti!)
1:19 Panthers' Frank Reich voices support for QB Bryce Young amid winless start: 'We got the guy we wanted'
1:17 NYC driver, 40, charged with attempted murder for shooting at off-duty detective
1:15 Alligator gar caught in Texas weighing 283 pounds shatters multiple records: 'Four in one fell swoop'
1:06 Sen. Tim Scott calls for the deportation of foreign students supporting Hamas 
1:06 More than 10 dead, dozens injured in Lewiston, Maine mass shooting, sources say
1:04 Jets’ defensive line looking to up sack numbers in battle vs. Giants
1:03 John Stamos reveals what Mary-Kate and Ashley Olsen said at Bob Saget’s funeral: ‘It was so beautiful’
1:01 See ‘The Crown’ recreate Princess Diana’s historic landmine walk
1:00 Joe Rogan expresses nostalgia for Trump era, says country was 'without a doubt' better than under Biden
1:00 Erika Jayne Reveals ‘RHOBH’s Biggest Pot-Stirrer Now That Lisa Rinna Is Gone: “I Think We All Have Moments”
0:56 US, Australia Reaffirm Shared Values, Cooperation Against Chinese Ambitions 
0:56 Hunter Biden missing from state dinner guest list after backlash for attending others amid legal issues
0:55 Rams coach Sean McVay invokes 'higher power' when talking newborn son: 'There's something special going on'
0:47 Alexis Lafreniere finally could be primed for Rangers’ breakout
0:46 Giant pandas to leave the National Zoo in D.C. for China earlier than expected
0:43 Fans slam Mauricio Umansky for telling Kyle Richards he won’t ‘allow’ any more tattoos
0:42 ‘Southern Charm’ alum Kathryn Dennis’ SUV involved in alleged hit-and-run at elementary school
0:35 No sex please, we’re Gen Z — young viewers want deeper, more unique relationships in film, on TV: study
0:34 Cooper Union barricades Jewish students inside library as pro-Palestine protesters bang on doors
0:34 Active shooter situation in Lewiston, Maine: Police
0:34 UAW reaches tentative labor agreement with Ford
0:33 Giants’ Andrew Thomas practices lightly but unlikely to face Jets
0:31 Active shooter situation in Maine, city residents told to 'stay inside with doors locked'
0:28 Falcons head coach dismisses concerns after Bijan Robinson's surprisingly low usage: 'There's nothing'
0:24 AI predicts a third of breast cancer cases prior to diagnosis in breakthrough mammography study
0:24 UAW reaches tentative deal with Ford: Sources
0:19 Sean McVay’s wife Veronika Khomyn gives birth to baby boy
0:18 Ex-‘incel’ threatened to shoot up ‘chads and stacies’ at University of Arizona: feds
0:17 Florida duo allegedly stabbed man repeatedly, threw him over bridge, stole car and set it on fire: authorities
0:12 Who is Rep. Mike Johnson, the new House speaker?
0:11 Yankees have had 'preliminary' conversations to trade for Juan Soto: report
0:09 California man breaks into Jewish family's home, threatens to kill them, yells 'Free Palestine'
0:08 ‘Breakfast Club’ host DJ Envy has no apologies for promoting a con man newly arrested for fraud
0:08 Biden team sees 2024 opportunity with GOP's new speaker, and more campaign takeaways
0:07 UAW closing in on tentative labor agreement with Ford
0:05 Biden must stop using defense partnerships as an excuse to cut Pentagon spending
0:02 Shakira fans blame karma after singer’s ex Gerard Piqué falls into stage hole: ‘Don’t disrespect the stage queen’
0:00 Obama’s warning to Israel: Letters to the Editor — Oct. 26, 2023
0:00 Clarence Thomas loan for luxury RV was forgiven, Senate Democrats say
0:00 ACLU sues Tennessee for 'criminalizing HIV' with strict prostitution laws
23:59 Who is Rep. Mike Johnson, the House GOP's latest speaker nominee?
23:56 White House state dinner celebrates Australia ties, nods to Israel-Hamas war
23:56 Drone video shows Mexican drug cartels throwing explosives along Texas southern border
23:54 Bear attacks security guard in Aspen hotel, remains on the loose, Colorado wildlife officials say
23:51 Beyoncé shares rare video talking to fans as she unboxes her new perfume: ‘It’s finally here’
23:48 'The Young and Restless' star Christian LeBlanc reveals cancer diagnosis after 'fans caught' sign of disease
23:44 Diana Nyad goes the distance in new film on Cuba-Florida swim feat
23:41 Jewish American students outraged by rising antisemitism in US amid Hamas terror attacks on Israel
23:39 Mike Johnson Won The Worst Job In Washington: Speaker of a Broken House
23:38 Lindsay Clancy, Massachusetts mother who strangled her 3 children, researched 'ways to kill,' court docs say
23:38 Jets’ matchup with Giants a reminder of how quickly things change
23:32 Nikki Haley rips Biden over antisemitism on college campuses — and vows to fix it
23:30 Mel Tucker sexually harassed Brenda Tracy, Michigan State investigation reveals
23:29 Brian Austin Green slams ‘DWTS’ for excluding fiancée Sharna Burgess from Len Goodman tribute
23:24 LeBron James' minutes restriction likley the new norm as superstar enters new chapter
23:21 FDA looking into claim woman died after drinking Panera Bread lemonade
23:20 North Dakota Legislature rewrites budget bill, ending special session in 3 days
23:19 'Squad' Democrats vote against condemning 'barbaric' Hamas attack on Israel
23:18 Wisconsin officials pass new wolf management plan, but population goal absent
23:17 UN chief’s justification for Hamas attacks shows the organization is worse than useless
23:16 Former Congressman Mark Walker drops out of North Carolina gubernatorial race to launch Congressional bid
23:15 Over 70 left ill following multi-state salmonella outbreak tied to onions
23:14 Husband of Cardi B’s manicurist charged with setting wife’s new NYC salon on fire
23:10 Elon Musk rolls out audio, video on X as he seeks to make it an ‘everything app’
23:09 UnScientific American, Trump is yesterday’s man and other commentary
23:09 Customer freed after spending night trapped inside NYC bank vault
23:07 ‘F–k Israel’ graffiti scrawled across Cornell University campus sidewalks
23:03 Dennis Quaid to host Fox Nation series 'Top Combat Pilot' debuting in November
23:00 Don La Greca goes off on ‘weakling’ Chris Russo’s retirement ‘gimmick
23:00 New report shows a majority of students attend schools with high or extreme levels of chronic absence
23:00 Biden administration pushes for a humanitarian 'pause' in Israel’s military campaign in Gaza