{
  "id": "case-pla-unit-61398",
  "slug": "us-v-sun-kailiang-pla-unit-61398",
  "title": "U.S. v. Sun Kailiang et al. (PLA Unit 61398 / APT1)",
  "summary": "Historic first-ever criminal indictment against state military actors: five Chinese military officers in People's Liberation Army Unit 61398 charged with cyber espionage against Westinghouse, U.S. Steel, Alcoa, and the United Steelworkers union.",
  "case_number": "2:14-cr-00118",
  "court": "U.S. District Court for the Western District of Pennsylvania",
  "district": "W.D. Pa.",
  "country": "United States",
  "opened_at": "2014-05-01",
  "status": "fugitive",
  "victim_sector": "Nuclear Energy, Metals, Manufacturing, Clean Energy",
  "victim_country": "United States",
  "loss_amount_usd": 100000000,
  "loss_amount_note": "Theft of proprietary nuclear reactor designs, solar panel technology, and commercial negotiation strategies.",
  "first_seen_at": "2006-01-01T00:00:00Z",
  "last_updated_at": "2026-09-07T12:00:00Z",
  "actor_slug": "pla-unit-61398",
  "defendant_slugs": [
    "sun-kailiang",
    "huang-zhenyu",
    "wen-xinyu",
    "wang-dong",
    "gu-chunhui"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1566.001",
      "evidence_excerpt": "Defendants sent spearphishing emails containing malicious attachments to corporate engineers, appearing to come from colleagues or trade groups.",
      "evidence_locator": "Indictment \u00b6 15, Page 7",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Sun Kailiang",
      "source_url": "https://www.justice.gov/opa/pr/us-charges-five-chinese-military-hackers-cyber-espionage-against-us-corporations-and-labor",
      "technique_name": "Spearphishing Attachment",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1041",
      "evidence_excerpt": "Exfiltrated thousands of sensitive proprietary technical specifications including AP1000 nuclear reactor piping diagrams.",
      "evidence_locator": "Indictment \u00b6 29, Page 16",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov/opa/pr/us-charges-five-chinese-military-hackers-cyber-espionage-against-us-corporations-and-labor",
      "technique_name": "Exfiltration Over C2 Channel",
      "tactic": "Exfiltration"
    }
  ],
  "events": [
    {
      "event_type": "indictment",
      "event_date": "2014-05-01",
      "description": "Grand jury unseals 31-count indictment against five PLA Unit 61398 military officers."
    },
    {
      "event_type": "sanction",
      "event_date": "2015-09-25",
      "description": "Cyber espionage agreement signed between U.S. and PRC following sustained enforcement pressure."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Adversary breached the target network via Spearphishing Attachment. Defendants sent spearphishing emails containing malicious attachments to corporate engineers, appearing to come from colleagues or trade groups.",
    "blast_radius": "Theft of proprietary nuclear reactor designs, solar panel technology, and commercial negotiation strategies. Impacted Nuclear Energy, Metals, Manufacturing, Clean Energy infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Initial Access",
        "title": "Initial Perimeter Infiltration",
        "description": "Defendants sent spearphishing emails containing malicious attachments to corporate engineers, appearing to come from colleagues or trade groups.",
        "technical_artifacts": [
          "T1566.001",
          "Spearphishing Attachment"
        ],
        "mitre_technique_id": "T1566.001"
      },
      {
        "phase": "Phase 2: Exfiltration",
        "title": "Encrypted Cloud Data Exfiltration",
        "description": "Exfiltrated thousands of sensitive proprietary technical specifications including AP1000 nuclear reactor piping diagrams.",
        "technical_artifacts": [
          "T1041",
          "Exfiltration Over C2 Channel"
        ],
        "mitre_technique_id": "T1041"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}