The Hackers Who Broke Into Google Went Looking for the Wiretap List
← Back to Blog

The Hackers Who Broke Into Google Went Looking for the Wiretap List

August 5, 2026 · 6 min read

Operation Aurora:
Featured book
Operation Aurora:
$3.99Free on Kindle Unlimited
Amazon

On January 12, 2010, Google published a blog post admitting it had been hacked.

That sentence is easy to skim past now. At the time it was close to unthinkable. Companies did not announce breaches. They contained them, notified whoever they were legally obliged to notify, and said nothing further. A public admission meant regulatory exposure, shareholder lawsuits, and a permanent line in every future news story about you. The standing advice from counsel was silence.

Google not only announced it. Google named the country it believed responsible, and then changed its business in China as a direct consequence.

To understand why a company would do that, you have to look at what the attackers were after — because it was not credit cards, and it was not, in the end, even source code.

The Shape of the Attack

The intrusions ran from roughly mid-2009 into January 2010. McAfee's researchers named the operation "Aurora" after a string found in the malware's file path, apparently a folder name on the developer's own machine.

The entry method was patient rather than brute. Employees at target companies received messages — often over instant messenger, often appearing to come from someone they knew — containing a link. The link led to a page that exploited a previously unknown use-after-free vulnerability in Internet Explorer, later catalogued as CVE-2010-0249. Visiting the page was sufficient. No download, no attachment, no dialog to click through.

From that first machine, the attackers moved laterally, harvested credentials, escalated privileges, and established persistence. Standard methodology now. In 2010 the fact that an intrusion was quiet and long-running was itself the notable part. The industry's mental model was still the smash-and-grab: get in, take something, get out. Aurora was designed to sit inside a network for months.

It was not one company. Public reporting put the target list somewhere between twenty and thirty-four organizations, including Adobe, Juniper Networks, Rackspace, Yahoo, Symantec, Northrop Grumman, Dow Chemical, and Morgan Stanley. This was a campaign against a sector.

At most of those companies, the attackers went for source code repositories. Not customer databases — configuration management systems, the actual crown jewels of a software company. Source code tells you how a product works, and more usefully, where it is weak. Stealing it is not theft of a product. It is the acquisition of a permanent advantage against every future version of that product.

Then There Is What They Did at Google

Two things were taken at Google, and the second one is the reason this attack still gets taught.

The first was consistent with everything else: intellectual property, plus access to the Gmail accounts of Chinese human rights activists. Google reported that the account access was limited — subject lines and metadata, largely, rather than message contents — and that separate campaigns had targeted the same activists elsewhere.

The second was the internal system Google used to comply with lawful intercept orders.

Every large communications provider operates one. When a government serves a court order requiring surveillance of a particular account, the company needs a mechanism to comply — a system that flags accounts under legal monitoring and routes the relevant data to law enforcement. It exists because the law requires it to exist. In the United States, that requirement traces back to CALEA, the 1994 statute obliging telecommunications carriers to build interception capability into their networks by design.

The attackers went for that system.

Think about what a list of accounts under active surveillance actually tells a foreign intelligence service. Not the contents of anyone's mail. Something far more valuable: which of our people have been identified. Which operations are known. Which cover identities have been burned. Every counterintelligence service on earth would rank that above almost any other single database in the world, and it existed only because a lawful process demanded that it exist.

This is the argument about surveillance backdoors, settled empirically, fifteen years ago. A mechanism that lets an authorized party bypass the security of a system is a mechanism. It does not check credentials at the door. Build the capability for a legitimate purpose and you have built it, full stop — and it will be attacked precisely because it is the highest-value target in the building.

Why Google Went Public

Google's response was disproportionate to a normal breach because the breach was not normal.

The company announced the attack. It stated publicly that the attacks originated from China. And it announced it would stop censoring search results on google.cn — which, given the terms of operating in the Chinese market, meant leaving that market. Traffic was redirected to Hong Kong. Google gave up the largest internet market on the planet.

Whether that decision was principle, strategy, or a market position that was already looking unwinnable has been argued ever since. All three readings have support. What is not arguable is the effect it had on everyone else.

Before Aurora, a breached company's playbook was silence. After a company of Google's stature published the details and attributed the attack, silence became a choice rather than the default — and one that looked worse each time a breach surfaced some other way. The modern practice of public breach disclosure and public attribution starts here.

There were other aftershocks. Germany and France issued government advisories telling citizens to stop using Internet Explorer until it was patched, which is not a thing national governments had previously done about a browser. Microsoft shipped an out-of-band emergency patch. And the term "advanced persistent threat" — coined earlier in defense circles — entered general commercial use, because Aurora gave the industry a concrete example of what one looked like when it happened to companies rather than to militaries.

China's government denied involvement. Attribution research over the following years connected the operation to a group given various names — the Elderwood gang, APT17 — and to a broader campaign that reused the same infrastructure and zero-days against defense contractors and supply chain targets for years afterward.

What It Established

Aurora is the moment several things stopped being theoretical at once.

It established that nation-state actors would target commercial companies directly, in peacetime, for strategic advantage rather than money — which meant a private company's security posture was now a matter of national interest whether or not the company saw it that way.

It established the modern intrusion profile: quiet entry through a browser, patient lateral movement, persistence measured in months, and objectives measured in strategic value rather than immediate cash.

And it demonstrated, at the cost of a real intelligence loss, that a compliance backdoor is an attack surface. That lesson is relitigated in every subsequent generation of the encryption debate, usually without reference to the case where it was already proven.

The most valuable thing in Google's network in 2010 was not built by Google to serve its users. It was built because the law said it had to be there.

Operation Aurora: A Tale of Digital Espionage covers the full campaign — the intrusion methods, the targets, the attribution work, Google's exit from China, and the diplomatic aftermath of the first breach a company chose to make public.

From the Catalog

Browse all
New
Wu Zetian
Wu Zetian
China's Only Female Emperor and How She Got There
New
Rapa Nui
Rapa Nui
What Really Happened on Easter Island
$3.99KU🎧
New
Thera
Thera
The Volcano That Shattered the Minoan World
$3.99KU🎧
New
Göbekli Tepe
Göbekli Tepe
The Temple Before Farming
$3.99KU🎧