Skip to content
ClaimUnverified

A China IP is not a finding that Beijing ran the 9 March hack

Routing fact · operator unknown

Open in cross-ref

CSM said exfiltrated mail went to an IP address in China. Headlines called it a Chinese hack. The agency did not publish a named operator. Compromised machines, third-party infrastructure and a false flag remain live. Not established, not ruled out.

Destination geolocation is the weakest form of attribution. The working chart is right to keep ‘unknown attacker(s)’ on the map and to list state-linked, non-state, third-party and false-flag as open. File the IP as CSM’s reported routing. File ‘China did it’ as unverified.

Sources

  • The Star / CSM, 20 Aug 2014; working chart · two waves

Related