A Chinese national pleaded guilty to conducting an extended hacking campaign against two American defense contractors over the course of several years.
Su Bin, 50, a businessman based in China, helped hack the networks of two aerospace companies and stole technical data on the C-17 strategic transport aircraft produced by Boeing, as well as an unnamed military fighter jet made by another company.
Download: Su Bin Plea Deal
From October 2008 to March 2014, Su worked with two hackers, instructing them on which companies to target and what information he was looking for. Su would then translate the information into Chinese and forward it to his customers along with detailed reports.
The data on both aircraft are included on the U.S. Munitions List, a catalog of services and technologies protected under the International Traffic in Arms Regulations (ITAR).
Su was detained in Canada shortly after being indicted in 2014 and agreed to extradition to the U.S. in February.
“Protecting our national security is the highest priority of the U.S. Attorney’s Office and cybercrime represents one of the most serious threats to our national security,” U.S. Attorney Eileen Decker said, announcing the plea deal. “Today’s guilty plea and conviction demonstrate that these criminals can be held accountable no matter where they are located in the world and that we are deeply committed to protecting our sensitive data in order to keep our nation safe.”
Theft of defense-related materials from a private company falls into a murky area of international law.
Countries are expect to conduct a certain amount of espionage under international norms, as State Department Cybersecurity Coordinator Christopher Painter pointed out during a panel at this year’s RSA Conference.
“All countries are going to gather information and intelligence to protect their citizens,” he said. “But if you’re targeting trade secrets and intellectual property to benefit your commercial sector, that really is out of bounds and something that we don’t do.”
President Barack Obama and Chinese President Xi Jinping signed an agreement last year to stop economic espionage between the two countries. But differentiating between traditional espionage and theft of intellectual property has a lot to do with how you see the world.
“Historically speaking, in China, trade secrets originated as state secrets,” Jessica Malekos Smith, a student at University of California Davis School of Law studying cybersecurity issues, explained during the same RSA panel.
Smith is working on developing a cyber espionage predominant purpose test — a legal rule of thumb for determining whether an act falls under traditional intelligence gathering or the theft of intellectual property.
In Su’s case, the theft of proprietary information from private companies, as well as his personal financial gain, was enough to fall on the side of economic espionage.
According to his plea deal, Su faces a maximum of five years in prison and fines of $250,000 or twice the gross gain or loss as a result of his actions, whichever is more.
He is scheduled for sentencing on July 13.
“This investigation demonstrates the FBI’s resolve in holding foreign cyber actors accountable regardless of where they reside,” said David Bowdich, FBI Los Angeles Division assistant director in charge.




