For more than a year, a hacking group sat quietly inside the networks of North American medical and military research institutions, reading sensitive email and stealing research data. Nobody noticed. Google’s threat hunters finally caught them, and the details reveal just how patient and clever modern state-linked espionage has become.
| Quick Answer Google’s Threat Intelligence Group found a China-linked group, tracked as UNC6508, that breached North American medical, academic, and military research networks from September 2023 to late 2025. It stole research and defense data, then abused a built-in Google Workspace email feature to quietly exfiltrate messages. |
What Google Discovered
Google’s Threat Intelligence Group, known as GTIG, uncovered a long-running cyber-espionage campaign. It attributed the activity to a group it tracks as UNC6508. Google describes the group as a PRC-nexus actor, meaning its activity aligns with the strategic interests of the People’s Republic of China.
Working with its Mandiant Consulting team, Google disrupted the group’s infrastructure, notified the affected organizations, and offered help with cleanup. The earliest known break-in dates back to September 2023, and the activity ran until late 2025.
| Why It Matters This was not a smash-and-grab. The attackers stayed hidden for over a year, which gave them time to map internal systems and steal a steady stream of sensitive data. That patience is the hallmark of state-linked espionage, and it makes these intrusions especially hard to catch. |
Who Was Targeted
The campaign focused on the research community across the United States and Canada. According to Google, the victims were not random, but high-value institutions with deep research budgets.
- Medical research institutions, including world-renowned clinical providers and premier academic centers.
- Military health organizations, including a medical university with ties to the US military.
- Health policy and regulatory bodies, along with professional advocacy groups.
Google noted that these organizations employ thousands of people and hold a combined research budget in the billions of dollars. That scale made them rich targets for intelligence collection.
How the Attack Worked
The intrusion followed a careful, multi-step pattern. At a high level, here is how the group operated, based on Google’s report.
| Stage | What Happened |
| Entry | Compromised externally facing research web servers used to collect study data |
| Credential theft | Deployed custom malware to capture legitimate research logins |
| Persistence | Stayed hidden for over a year, surviving software upgrades |
| Internal access | Used stolen credentials to reach sensitive internal networks |
| Exfiltration | Abused a built-in enterprise email feature to quietly forward matching messages out |

The most striking part was the exfiltration method. Instead of smuggling out large files, the attackers manipulated a legitimate email compliance rule to silently copy matching messages to an outside account. That let them collect a continuous feed of sensitive email without tripping the usual alarms.
| Worth Knowing The attackers turned a normal, trusted business feature into a spying tool. Because the email forwarding looked like routine administrative activity, it blended in with legitimate traffic. Google has since shut down the account used to receive the stolen data. |
What the Hackers Were Looking For
The group’s collection list was unusually broad, which puzzled even the researchers. Far beyond medicine, the attackers searched for material tied to national security and advanced technology.
- Defense and national security, including Indo-Pacific command operations and defense platform systems.
- Emerging technology, such as artificial intelligence and uncrewed vehicle systems.
- Cyber programs and offensive capability research.
- Specific medical research, including a particular mosquito-borne virus linked to a recent outbreak.
Google analysts called it one of the most unusual collection lists they had seen from a state-sponsored actor. Defense terms kept showing up inside medical networks, where you would not expect them.
Why This Matters Beyond Research Labs
The bigger lesson reaches well past universities and hospitals. Security experts warn that the same access used for quiet spying can later be reused for disruption or extortion.
In healthcare, that is a serious risk, since an attacker inside critical systems could threaten patient safety, not just data privacy. This case is a reminder that research and medical organizations are now front-line targets. Espionage and ransomware often share the same entry points. To understand the wider threat landscape, our guide on protecting yourself from modern scams covers many of the same warning signs.
Lessons for Organizations
You do not need to run a research lab to take something useful from this. The defensive takeaways apply to almost any organization.
- Watch external-facing apps. Internet-exposed web applications are a common entry point and need regular patching and monitoring.
- Audit email and admin rules. Review automatic forwarding and compliance rules, since attackers can hide inside trusted features.
- Assume long dwell times. Hunt for intruders who may already be inside rather than only blocking new ones.
- Protect credentials. Strong authentication limits the damage when a single login is stolen.
This campaign shows how quietly modern espionage can operate. A patient, state-linked group spent more than a year inside sensitive research networks. They used stolen logins and a trusted email feature to steal a steady stream of data. The good news is that it was caught and disrupted. The warning is clear. Medical and research institutions are now prime targets, and the basics of patching, monitoring, and strong authentication matter more than ever.
Read the Full Report
Google’s official threat intelligence report (Google Threat Intelligence Group)
CISA on China state-sponsored cyber threats (US government cybersecurity agency)
Frequently Asked Questions
Who Is Behind the Medical Research Hacking Campaign
Google’s Threat Intelligence Group attributed it to UNC6508, a China-linked, or PRC-nexus, threat group whose goals align with the strategic interests of the People’s Republic of China.
What Did the Hackers Steal
They collected sensitive email and research data spanning medical studies, defense and national security topics, artificial intelligence, and uncrewed vehicle systems.
How Long Were the Hackers Inside
The earliest known compromise was September 2023, and the activity continued until late 2025, so they remained undetected for over a year.
How Did They Steal the Data
They abused a legitimate enterprise email compliance feature to silently forward matching messages to an outside account, avoiding the usual alarms.
Has the Threat Been Stopped
Google disrupted the group’s infrastructure, disabled the account receiving the stolen data, and notified and assisted the affected organizations.
Who Was Affected
Medical, academic, and military research institutions across the United States and Canada, including major clinical providers and military health organizations.



