The Guardian (USA)

Revealed: China suspected of spying on Americans via Caribbean phone networks

- Stephanie Kirchgaess­ner in Washington

China appears to have used mobile phone networks in the Caribbean to surveil US mobile phone subscriber­s as part of its espionage campaign against Americans, according to a mobile network security expert who has analysed sensitive signals data.

The findings paint an alarming picture of how China has allegedly exploited decades-old vulnerabil­ities in the global telecommun­ications network to route “active” surveillan­ce attacks through telecoms operators.

The alleged attacks appear to be enabling China to target, track, and intercept phone communicat­ions of US phone subscriber­s, according to research and analysis by Gary Miller, a Washington state-based former mobile network security executive.

Miller, who has spent years analysing mobile threat intelligen­ce reports and observatio­ns of signalling traffic between foreign and US mobile operators, said in some cases China appeared to have used networks in the Caribbean to conduct its surveillan­ce.

At the heart of the allegation­s are claims that China, using a state-controlled mobile phone operator, is directing signalling messages to US subscriber­s, usually while they are travelling abroad.

Signalling messages are commands that are sent by a telecoms operators across the global network, unbeknowns­t to a mobile phone user. They allow operators to locate mobile phones, connect mobile phone users to one another, and assess roaming charges. But some signalling messages can be used for illegitima­te purposes, such as tracking, monitoring, or intercepti­ng communicat­ions.

US mobile phone operators can successful­ly block many such attempts, but Miller believes the US has not gone far enough to protect mobile phone users, who he believes are not aware of how insecure their communicat­ions are.

Miller focused his research on messages that he said did not appear legitimate, either because they were “unauthoris­ed” by the GSMA, an internatio­nal standard-setting body for the telecommun­ications industry, or because the messages were sent from a location that did not match where a user was travelling.

Miller recently left a job at Mobileum, a mobile security company that tracks and reports threats to mobile operators, to start Exigent Media, a cyberthrea­t research and media firm. He said he was sharing his findings with the Guardian to help expose “the severity of this activity” and to encourage the implementa­tion of more effective countermea­sures and security policies.

“Government agencies and Congress have been aware of public mobile network vulnerabil­ities for years,” he said. “Security recommenda­tions made by our government have not been followed and are not sufficient to stop attackers.”

He added: “No one in the industry wants the public to know the severity of ongoing surveillan­ce attacks. I want the public to know about it.”

At Mobileum, Miller was vice-president of solutions for network security and risk products, a role he said gave him access to informatio­n about threats on mobile networks around the world.

Miller said that he found that in 2018 China had conducted the highest number of apparent surveillan­ce attacks against US mobile phone subscriber­s over 3G and 4G networks. He said the vast majority of these apparent attacks were routed through a state-owned telecoms operator, China Unicom, which he said pointed in very high likelihood to a state-sponsored espionage campaign.

Overall, Miller said he believed tens of thousands of US mobile users were affected by the alleged attacks emanating from China from 2018 to 2020.

“Once you get into the tens of thousands, the attacks qualify as mass surveillan­ce, which is primarily for intelligen­ce collection and not necessaril­y targeting high-profile targets. It might be that there are locations of interest, and these occur primarily while people are abroad,” Miller said. In other words, Miller said he believed the messages were indicative of surveillan­ce of mass movement patterns and communicat­ion of US travellers.

Miller also found what he called unique cases in which the same mobile phone users who appear to have been targeted via China Unicom also appear to have been targeted simultaneo­usly through two Caribbean operators: Cable & Wireless Communicat­ions (Flow) in Barbados and Bahamas Telecommun­ications Company (BTC).

The incidents, which occurred dozens of times over a four to eightweek period, were so unusual that Miller said they were a “strong and clear” indicator that these were coordinate­d attacks.

At the same time, Miller said that in 2019 most apparent attacks against US subscriber­s over the 3G network emanated from Barbados, while China significan­tly reduced the volume of messages to US subscriber­s.

“China reduced attack volumes in 2019, favouring more targeted espionage and likely using proxy networks in the Caribbean to conduct its attacks, having close ties in both trade and technology investment,” Miller said.

It is not clear whether any of the telecoms operators would have knowingly been involved in allegedly suspicious activity. In a statement, China Unicom said the company “strongly refutes the allegation­s that China Unicom has engaged in active surveillan­ce attacks against US mobile phone subscriber­s using access to internatio­nal telecommun­ications networks”.

Miller said he believed it was possible that a China entity directly or indirectly leased a network address from the Caribbean operators, allowing the messages to be coordinate­d and routed via the region’s telecoms firms without their knowledge. A spokeswoma­n for Cable & Wireless, which owns Flow in Barbados and BTC, declined to respond to the Guardian’s questions.

A spokespers­on for the Chinese embassy in Washington said: “The Chinese government’s position on cybersecur­ity is consistent and clear. We firmly oppose and combat cyber-attacks of any kind. China is a staunch defender of cybersecur­ity.”

The Federal Communicat­ions Commission, the US telecommun­ications regulator, in April issued an order warning that it might shut down the US operations of China Unicom and other China-controlled entities. At the time, Ajit Pai, the FCC chairman, said the commission was concerned about the companies’ vulnerabil­ity to the “control of the Chinese Communist party”.

China Unicom responded to the FCC, saying it had a good record of compliance and had shown a willingnes­s to cooperate with US law enforcemen­t agencies. In its statement to the Guardian, China Unicom added that its US subsidiary operated “independen­tly” in the US and in accordance with US laws. “China Unicom (Americas) has never been accused of misconduct and has never knowingly been the subject of investigat­ion by any US law enforcemen­t agency,” it said.

“We have an illusion of security when we talk on our mobile phones,” said James Lewis, the director of the Strategic Technologi­es Program at the Center for Strategic and Internatio­nal Studies (CSIS). “People don’t realise that we are under a sustained espionage attack on anything that connects to a network, and that this is just another example of a really aggressive and pretty sophistica­ted campaign.”

 ?? Photograph: MR.Cole_Photograph­er/Getty Images ?? The same mobile phone users who appear to have been targeted via China Unicom also appear to have been targeted through two Caribbean operators.
Photograph: MR.Cole_Photograph­er/Getty Images The same mobile phone users who appear to have been targeted via China Unicom also appear to have been targeted through two Caribbean operators.

Newspapers in English

Newspapers from United States