China Reports Cyberespionage Through an Unpatched Enterprise Platform
Chinese state security authorities reported that delayed software updates left a military–civilian enterprise exposed to intrusion and theft of business and customer data.
Chinese state security authorities have reported that foreign actors exploited inadequate safeguards, operational oversights and convenience-driven practices at important organizations in China. According to the authorities, attackers targeted information systems at critical organizations, government departments and businesses, established covert transmission channels, and stole sensitive data, threatening China’s data and network security.

An overlooked vulnerability
In a recently reported case, Chinese state security authorities found that a company operating in the military–civilian sector had failed to update software promptly across several systems, including its office platform. This left high-risk vulnerabilities exposed. The authorities said foreign cyberespionage actors discovered and exploited the weaknesses, installed Trojans, and stole important production, business and customer data, harming the development of military equipment technology in China.
The authorities described this as part of a broader pattern: foreign cyberespionage actors were paying close attention to software supply-chain companies, repeatedly targeting them through phishing emails and network reconnaissance. Operations personnel holding system administration privileges were identified as priority targets for credential compromise and information theft.
How enterprises can improve protection
Enterprises should establish a comprehensive cybersecurity framework and use appropriate tools to improve their ability to resist attacks and data breaches.
- Deploy firewalls to restrict unauthorized external access to internal networks and systems.
- Install antivirus software to scan incoming files and filter malicious code.
- Establish security auditing that records user activity, identifies unusual operations and supports a timely response.
- Set access controls so that only authorized personnel can access or modify sensitive data.
- Install updates regularly, keep operating systems and applications current, and maintain backups on secondary storage separate from the primary data.
- Deploy SSL certificates to enable HTTPS and help protect data in transit against interception and tampering.
- Use S/MIME email security certificates for encryption and signing to protect email confidentiality and help detect tampering and sender impersonation. They do not stop all phishing attacks.
- Use code signing certificates to establish publisher identity and detect changes to signed software. Code signing does not itself prevent code theft or guarantee that software contains no malware.
Regular employee training is also necessary to improve data security awareness. Together, these measures help organizations build layered network and data protection.
About Racent
Shanghai Ruicheng Information Technology Co., Ltd. (Racent) is a cloud resource distributor and cloud security service provider in China. Its portfolio includes SSL certificates, code signing certificates and email security certificates to support enterprise security. For questions or assistance, please contact us.