Operation Aurora

lore

securityhacking

The 2009 espionage campaign against Google and dozens of companies that dragged nation-state hacking into the open.

Disclosed by Google in a January 2010 blog post that stunned the industry, Aurora used an Internet Explorer zero-day to penetrate Google, Adobe, and reportedly more than twenty other firms, seeking source code and the accounts of human-rights activists. Google's response, threatening to leave the Chinese market, made a breach a matter of foreign policy for the first time. Corporate transparency about state-level intrusion dates from this moment.

Operation Aurora was the 2009 campaign against Google and dozens of other companies, disclosed by Google in January 2010 in an unusually direct public statement that attributed the intrusion and described what was taken.

Its importance is not the technique, which was a browser vulnerability and targeted phishing. It is that a major company chose to disclose a state-linked intrusion publicly and specifically, at a time when the norm was silence. That decision changed what was sayable: attribution moved from something companies avoided to something they occasionally do, and the term advanced persistent threat entered general use to describe an adversary that is patient, funded and specific rather than opportunistic.

The detail that unsettled the industry was the target. Among the systems accessed was the interface Google used to manage lawful intercept requests, which is to say the mechanism built to satisfy legal surveillance became the thing an intelligence service went after. That is the exceptional-access argument demonstrated rather than debated: a facility for authorized access is a facility, and it does not check whose authorization it is honouring.

All glossary entries