Last updated 1 month ago
A China-linked espionage group compromised North American medical, academic, and military research networks for over a year, exfiltrating sensitive research and defense emails. The breach targeted REDCap research servers, which were used as initial access points. The disclosure date is June 2026, but the discovery date is not specified.
The attackers gained initial access via a backdoor on REDCap servers that stole login credentials. They then exploited Google Workspace rules to automatically copy and exfiltrate emails from compromised accounts. The threat actor is attributed to a China-linked espionage group, but specific TTPs or CVEs are not detailed. The exfiltrated data includes emails and login credentials.
No post-incident details are provided in the article regarding regulatory actions, litigation, ransom payments, or containment milestones.
Backdoor on REDCap research servers stole credentials; attackers rewrote Google Workspace rules to exfiltrate emails
The breach highlights the risk of credential theft from research servers (REDCap) and the abuse of cloud email rules for persistent exfiltration. Organizations should enforce multi-factor authentication on all research platforms and monitor for unauthorized changes to email forwarding or filtering rules. Additionally, restricting the ability to modify Google Workspace rules to a limited set of administrative accounts could have prevented this attack.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor