Google disrupts hackers that attacked 53 groups globally

Google disrupts hackers that attacked 53 groups globally

February 25, 2026   05:10 pm

Google disrupted a Chinese-linked hacking group that breached at least 53 organizations across 42 countries, the company said Wednesday.

The hacking group, tracked as UNC2814 and “Gallium,” has a nearly decade-long history of penetrating government organizations and telecommunications companies, the company said in findings shared exclusively with Reuters.

“This was a vast surveillance apparatus used to spy on people and organizations throughout the world,” John Hultquist, chief analyst with Google Threat Intelligence Group, said.

Google and unnamed partners terminated Google Cloud projects controlled by the hacking group, identified and disabled internet infrastructure it was using and disabled accounts the group used to access Google Sheets, which it used to carry out its targeting and data theft operations.

Using Google Sheets allowed the group to evade detection and blend into normal network traffic and was not a compromise of any Google product, the company added.

Charlie Snyder, senior manager of Google Threat Intelligence Group, said the group had confirmed access to 53 unnamed entities across the 42 countries, with potential access in at least 22 more countries at the time of disruption.

Snyder declined to identify the compromised entities, but said in one case the group had installed a backdoor Google calls “GRIDTIDE” on a system containing full names, phone numbers, dates of birth, place of birth, voter ID and national ID numbers.

The targeting is consistent with efforts to identify and track select targets, the company said. “Similar campaigns have been used to exfiltrate call data records, monitor SMS messages, and to even monitor targeted individuals through the telco’s lawful intercept capabilities.”

Chinese Embassy spokesperson Liu Pengyu said in a statement that “cyber security is a common challenge faced by all countries and should be addressed through dialogue and cooperation.

“China consistently opposes and combats hacking activities in accordance with the law, and at the same time firmly rejects attempts to use cyber security issues to smear or slander China.”

The activity is distinct from separate high-profile, telecommunications-focused Chinese hacking activity tracked as “Salt Typhoon,” Google said. That campaign, which the U.S. government has linked to China, targeted hundreds of U.S. organizations and prominent U.S. political figures.

Source: Reuters

--Agencies

Disclaimer: All the comments will be moderated by the AD editorial. Abstain from posting comments that are obscene, defamatory or slanderous. Please avoid outside hyperlinks inside the comment and avoid typing all capitalized comments. Help us delete comments that do not follow these guidelines by flagging them(mouse over a comment and click the flag icon on the right side). Do use these forums to voice your opinions and create healthy discourse.

Most Viewed Video Stories

Ada Derana Prime Time News Bulletin

Ada Derana Prime Time News Bulletin

🔴LIVE | Ada Derana Midday Prime News Bulletin

Ex-Presidents, politicians and diplomats attend Siri Samanthabhadra Thero's birthday celebrations (English)

National Housing Operational Committee to be appointed to provide guidelines for housing program (English)

Contract killer arrested over plot to kill informant; More roadblocks to curb underworld activities (English)

“Coal procurement followed proper procedure” One shipment failed to meet standard -Cabinet Spokesman (English)

🔴LIVE | Ada Derana Prime Time News Bulletin

🔴LIVE | Ada Derana Midday Prime News Bulletin - 2026.02.24