Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails

A Chinese espionage group abused Google Workspace mail-routing rules to silently exfiltrate defence and medical research emails for over a year after backdooring REDCap servers.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readRead at source ↗

A China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly stealing sensitive research and defense email.

The way in was a backdoor on their REDCap research servers that stole login credentials. The exfiltration was the unusual part: the attackers rewired the victims' own Google Workspace rules to copy any message

Editorial Analysis

Why it matters

Abusing legitimate cloud collaboration features for exfiltration evades traditional DLP; European research institutions sharing infrastructure with North American peers face similar exposure.

What to do

Audit Google Workspace mail-routing and forwarding rules for unauthorised destinations, and monitor REDCap instances for signs of compromise.

Board brief

State-sponsored attackers hid inside research networks for a year by manipulating routine cloud email settings.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the Threat Intel Desk