Exclusive: Breaking down Beijing’s “Digital Mercenaries”

In February 2024, a batch of unidentified documents quietly appeared on GitHub, causing a stir in the cybersecurity community and shocking Western media and even the intelligence community. The latest research by The Epoch Times sheds light on a whole new perspective.

The owner of the documents is “i-Soon Information Technology Co., Ltd.”— a privately-owned company based in Shanghai that appears to be engaged in cybersecurity business. The leaked information includes internal contracts, client lists, target lists for attacks, and clear pricing: infiltrating a Southeast Asian government’s email system is priced at approximately 140,000 to 200,000 RMB; penetrating a European telecommunications operator is subject to further negotiation; and continuous monitoring of an overseas dissident’s social media account is charged monthly.

The buyers are not international pirates but rather local branches of the Chinese Communist Party’s Ministry of Public Security and national security agencies.

The unexpected leak of the “hacker business pricing list” provides crucial evidence that has long been lacking: Beijing has commercialized and outsourced cyber attacks, integrating monitoring of overseas democratic movements and suppression of domestic dissidents into the same commercial chain. What is even more disturbing is that the core technology of this machinery partly comes from the West.

However, the i-Soon case is not just a routine data leak; it underscores an institutional operation model that interconnects Party-state security systems, AI monitoring, private contractors, and the global technology supply chain.

Western media tend to point fingers at the “National Security Bureau in Beijing” when reporting on Chinese cyber operations. However, The Epoch Times’ exclusive report, “Structural Research on Chinese Communist Security Agencies,” directly corrects this misunderstanding—the direct controllers of “hacker mercenaries” are not in Beijing.

The report’s in-depth research found that there are numerous versions of provincial security bureau designations in circulation, varying in terms of era, source, and credibility; however, these designations are merely functional indexes, and the real operational body is the provincial bureaus.

Citing studies by scholars like Joske, the report points out that provincial national security agencies have had their own origins, regional cadre networks, and specific priorities from the beginning and are particularly active in external intelligence operations, not merely serving as outposts of the Beijing headquarters.

The report references historical data from 1989: National security personnel in only Beijing, Guangdong, Shanghai, and Tianjin already exceed 10,000, estimated to constitute the majority within the national security system, meaning the central headquarters is relatively small compared to local branches. The buyer records from the i-Soon case corroborate this structural assessment.

Indictments by institutions like the U.S. Department of Justice reveal that the main actors behind recent major cyber operations are invariably local branches of the Chinese Communist Party’s security apparatus:

– Hainan Province National Security Department (APT40)

—Through the dual cover of Hainan Xianshield Technology and Hainan University, the targets include multiple naval forces, deep-sea research institutions, and defense industries from various countries;

– Tianjin City National Security Bureau (APT10)

—Through Tianjin Huayinghaitai Technology, from 2006 to 2018, their continuous infiltration reached 45 global enterprises and government agencies, with the primary targets being “Managed Service Providers (MSPs)” responsible for managing data for multiple clients, gaining access to one means obtaining the master key to a whole building;

– Hubei Province National Security Bureau (APT31)

—Through Wuhan Xiaorui Zhi Technology, they systematically target foreign parliamentarians, decision-making think tanks, and overseas dissident groups;

– Multiple instances of joint customers between public security and national security (APT41) in Anxun, Guangzhou Boyu Information Technology, and other contractors simultaneously serving public security and national security, infiltrate telecommunication giants, monitor overseas democratic movements, and partake in network game theft, offering a one-stop solution.

The design logic behind this outsourcing chain is highly calculated: provincial national security bureaus do not have to maintain a full-time team of permanent hackers; instead, they recruit suitable candidates from the technical talent market, utilize front companies to shield legal responsibility, and in case of incidents, deflect responsibility by claiming it was the actions of a private enterprise. This is a standard response from the Chinese Foreign Ministry in the face of any accusations.

The report points out that Beijing’s hacker empire, cheaper, more covert, and harder to trace than the KGB-style professional special agent system, is more resilient.

The i-Soon case reveals the output end of external hacker actions. What is more difficult to detect and more deeply impacts the daily lives of every Chinese person is the “interface regime” mechanism constructed domestically by the Chinese Communist Party.

In a single sentence, the exclusive report encapsulates the core of this concept: the public security agencies do not need to establish a comprehensive civilian database covering all of society since platforms like WeChat, Alipay, Meituan, Didi, and major telecommunications operators have been legally transformed into their external sensor network.

The legal authorization chain is transparent and traceable. The revised “Counter-Espionage Law” of 2023 authorizes national security agencies to take coercive measures such as inquiries, seizures, detention, and technical reconnaissance against suspected spies; the “National Intelligence Law” passed in 2017 requires relevant organizations and citizens to support, assist, and cooperate with national intelligence work; the “Cybersecurity Law” and “Data Security Law” demand platform companies to provide real-time user account relations, transaction records, and physical trajectories when instructed by public security. These three layers of law share the same executing body—”internal law enforcement” and “external intelligence,” which were not originally two separate machines but two missions of the same command chain in institutional design.

The report specifically points out a commonly overlooked logic of “transferability”: systems developed for combating serious criminal activities—such as fund interception, tracking, and real-name landing systems—can be repurposed with no barriers for tracking religious believers, rights defenders, or campus political dissidents within the endless frame of political security of the regime.

This is not a systemic loophole but a designed feature: administrative names like “anti-fraud,” “anti-terrorism and stability maintenance,” and “public security management” originally provide legal cover for broader political monitoring.

The advancement of big data and AI has led people to imagine a highly automated surveillance system. However, the Epoch Times report found that this imagination underestimates the most significant structural characteristic of the Chinese Communist Party’s social control system: regardless of how powerful algorithms are, they are only responsible for providing early warning signals; in the end, it is still the neighborhood committees, schools, and police stations that conduct the actual door-to-door questioning, placing people under control during sensitive periods.

Two sets of numbers presented in the report reveal the scale and logic of this nested structure. National security police directly responsible for political monitoring make up about 3% of the police force, totaling between 60,000 to 100,000 nationwide, which means there is one per every 10,000 to 20,000 people, significantly lower than the Stasi’s ratio of one full-time agent for every 165 citizens in East Germany. However, according to Poon Min-hyun’s “Sentinel State” research cited in the report, the Party-political system controls an information network of between 10 to 15 million, meaning every hundred people have one informant keeping an eye on them.

These numbers underscore that while algorithms provide mass perception, they ultimately need to be implemented on the front lines by grid workers, community leaders, university student counselors, and religious site managers. The majority of these individuals are not primarily involved in security-related work.

The key point is that when a certain belief, expression, or cross-border contact is defined as a political risk, these everyday nodes will seamlessly link up for identification and disposal: the algorithm flags the “abnormality,” and grassroots personnel carry out the final mile of “interrogation-visit-stabilize.”

The report finds that the intertwining of high technology and traditional “mass line” is the most robust structural logic of social control by the Chinese Communist Party: the former provides coverage, and the latter is responsible for “hands-on disposal.”

One detail often overlooked in i-Soon’s leaked documents is that a part of the algorithm training and computing infrastructure supporting its hacking capabilities relies on Western technology.

Entities like Hikvision, Dahua, and Megvii Technology that were sanctioned by the U.S. Department of Commerce rely heavily on advanced Western chips for optimizing their big data computation and video image recognition models. Despite export controls, Chinese technology units can still procure advanced chips through multi-layered shell proxy companies or by packaging purchases under the guise of civilian compliance projects such as “smart transportation” and “weather big data.” A more difficult channel to block is the open-source databases and deep learning frameworks used for facial recognition algorithm training, which, under the guise of academic exchanges and international cooperation, continue to supply technological nutrients to the Chinese technical reconnaissance department.

The report indicates that the core issue with this supply chain problem is a flaw in institutional design rather than a commercial loophole: technology systems developed solely for public security to combat criminal acts can easily be repurposed for political monitoring without any barriers. This means that export controls that only scrutinize the “final declared use” without examining the entire platform and system integration logic cannot prevent Western technology from being “weaponized” by the Chinese Communist Party.

In 2023, an investigation by a non-governmental organization documented a new reality in the streets of Belgrade, the capital of Serbia in Europe: hundreds of Hikvision intelligent cameras have integrated facial recognition and license plate tracking technology into the local police’s surveillance network. Serbia is the first country in Europe to adopt the full set of Chinese “Safe City” systems.

Similar deployments have occurred in countries like Pakistan, Iran, and Ethiopia. However, the output goes far beyond hardware. The Epoch Times report points out that the Chinese Communist Party is simultaneously exporting the regulatory standards on “how to mandatorily interface local telecom companies and network service providers through legislation,” emulating China’s “Cybersecurity Law” to replicate the low-cost, high-penetration logic of China’s distributed surveillance in recipient countries.

The report warns that this means the infrastructure of the Chinese authoritarian surveillance system is completing geopolitical expansion through commercial cooperation—it weakens the defense capabilities of democratic allies and reshapes the governance order of authoritarian recipient countries, resulting in the erosion of universal human rights on a global and systemic level.

Commentator Li Linyi stated that the leaked documents from i-Soon have exposed a tip of the iceberg of this machinery to the international community, but The Epoch Times’ exclusive report reminds us that i-Soon is just a visible node in this outsourcing ecosystem. As long as the “bureau-front company-university-technical contractor” chain led by provincial bureaus continues to operate, replacing an i-Soon only takes a few months. The report cautions that the true resilience of this system does not lie in any single contractor but in the institutional framework that seamlessly transforms political definitions into daily monitoring commands and the business ecosystem that continuously supplies it with blood from the global semiconductor and cloud supply chain.

(Purchase “Structural Research on Chinese Communist Security Agencies”)