Exclusive: Classified Documents Leak Reveals the Truth about Chinese Communist Party’s Cybersecurity

Beijing’s aggressive promotion in the fields of AI and big data has constructed what appears to be a formidable digital authoritarian regime. However, exclusive secret files obtained by Epoch Times reveal that beneath this grand narrative lies a surveillance tower that is as fragile as a glass castle.

Late at night, a disturbance flickered through the monitoring log of the e-government website in Qinghai Province. An “intruder” targeted a routine document reading component on the government service portal, exploited its vulnerability, gained server privileges, and within 22 minutes, the entire electronic license management system of the province collapsed: the “three elements” data of 7.8 million citizens including names, ID numbers, and phone numbers, over 2 million marriage registration records, and 8.8 million license collection information all exposed to the invading terminal.

Investigations by reporters revealed that the figure of 7.8 million exceeded Qinghai Province’s current approximately 5.92 million resident population—this difference not being a mistake, but including personal information collected by various departments over the years, reflecting the all-encompassing, large-scale data aggregation without any privacy blind spots under the “digital authoritarianism”.

This is not a fictional scenario or a sudden attack by top-notch foreign hacker groups; rather, it was a routine “network security” exercise carried out by the Party and the government on October 21, 2025—intended to test the security of government websites.

The true records from the action report of Qinghai Province’s “network security” are only the tip of the iceberg of hundreds of internal documents exclusively obtained by Epoch Times. These files cover technical testing reports of the Qinghai Province Information Center, monthly network security monitoring reports, early warning notifications from the provincial CCP committee’s cyberspace affairs office and the National Computer Network Emergency Response Technical Team/Coordination Center of China (CNCERT), as well as internal training documents from China Mobile and Inspur Star.

These files paint a complete picture of the reality behind the construction of the “digital government”: highly centralized big data and government powers, mismatched basic security capabilities, and a closed loop of political-business interests through layers of sub-contracting.

Before interpreting these files, it is necessary to examine the institutional characteristics of the source unit. The Qinghai Province Information Center, under the Provincial Development and Reform Commission, is the key technical unit for the implementation of the local “Digital China” strategy: overseeing compliance pressure from the provincial cyberspace affairs office and the provincial development and reform commission, horizontally controlling the data lifeblood of departments such as public security, human resources, civil affairs, and housing provident fund. In other words, the provincial information center is the guardian of local big data, managing the main channels through which citizen data, forcibly collected by departments like public security and human resources, flows.

However, this centralized data hub has evolved in reality into a primary source of centralized leaks. Exclusive files obtained by Epoch Times show that these vulnerabilities are often not due to sophisticated attack methods, but rather due to basic management oversights: widespread use of weak passwords like admin/123456, and storing database passwords in plain text within public code.

In official propaganda, the “government network” and “government cloud” rely on layers of firewalls and security gateways to build an impregnable “security isolation zone”. But the leaked technical documents present a reality that is quite the opposite: physical isolation is meaningless in the absence of basic security awareness, and the entire system is like a warehouse with its doors wide open.

During an in-depth examination of the Qinghai Province Information Center, testing personnel only used a publicly known vulnerability on a small external website to gain access. Once inside, they found no effective partitioning of the internal network, smoothly advancing to the “central control console” that governs the operation of the province’s government systems.

This central control console directly connects to 704 core application components that control government services across the province. Testing personnel bluntly stated in their report: by simply clicking “clear” or “delete” on the console, all digital government functions such as administrative approvals, housing provident fund withdrawals, and social security settlements in the entire province could be paralyzed within seconds.

More alarming is that the collapse of defenses often begins from the most inconspicuous aspects. After a backdoor was implanted on an edge server belonging to the Qinghai Province Department of Culture and News Publishing, testing personnel used it as a springboard to penetrate the supposedly “completely isolated” security gateway, entering the internal office systems of the provincial government and even infiltrating the internal networks of the Provincial People’s Congress and the Provincial Department of Commerce.

If penetration testing reveals simulated risks, the red-flag early warning notifications from the provincial CCP committee’s cyberspace affairs office and CNCERT confirm actual incidents of intrusion.

An alert report numbered [2026] No. 323 disclosed that a core computer of the Qinghai Province Development and Reform Commission—an essential power center for macroeconomic approval and disbursement in the whole province—was implanted with a trojan by a black-hat syndicate, turning it into a “zombie” controlled by overseas hackers. For nearly a week (from July 27, 2026, to August 2, 2026), this computer transmitted data to an overseas control server every day until the superior cyberspace affairs office and the national emergency center issued rectification orders, prompting the Development and Reform Commission to initiate an investigation.

The leaked documents also reveal the inadequacy of the authorities’ digital defenses: the 51st edition of the monthly analysis report showed that in June 2026, the Qinghai Province Government Cloud and the external network monitoring platform collectively recorded over 40.83 million alarm events, with 2.89 million high-risk alarms. In the list of reported incidents, the emergency management server of the provincial emergency hall was compromised for crypto-mining, a remote control trojan was implanted in the monitoring server of the provincial traffic police corps, and computers of the provincial justice department and the provincial fire rescue corps continued to send abnormal requests to overseas addresses in Singapore, Switzerland, the United States, and others.

Considering the fragile defenses, how is the network security system that local governments invest substantial funds in constructing each year procured, deployed, and accepted? Internal training documents obtained exclusively by Epoch Times from China Mobile and Inspur Star expose the schemes involved.

In January 2024, China Mobile invested 4.143 billion yuan to acquire a controlling stake in the top network security company, Inspur Star, which was subsequently incorporated into the ranks of central state-owned enterprises.

The internal review document of Inspur Star titled “OBG Heilongjiang Work Sharing” revealed the “321 mechanism” employed in cracking government clients: first, establish technical trust through policy jargon such as “guaranteed security” and “confidential assessment”; then, have senior executives of central SOEs conduct “high-level visits”, packaging the procurement as a policy-compliant achievement, bypassing technical arguments and directly targeting procurement intentions; finally, demonstrate “successful defense” in the acceptance phase following a preset script. The document bluntly states that the essence of the project lies in “studying policy orientation, seizing market opportunities in the security sector under political advantages”, and relying on administrative channels of central SOEs to pre-determine bidding terms and exclude competitors.

Internal settling discounts go as low as 37% to 40% off list prices, security products are packaged into “guaranteed security packages” and “confidential assessment packages”, and local finances are charged rent annually. In just the first half of 2026, the orders for mobile-related business in Heilongjiang Province alone amounted to millions of yuan for Inspur Star.

In simple terms, the business of the Party and the government’s network security does not consider technical effectiveness but only focuses on “political compliance”. Central SOEs secure contracts through connections and then stably cut a share from the fiscal budget together with the vendors.

Renowned commentator Li Lin mentioned that while the Beijing authorities have erected a digital firewall to safeguard their digital authoritarianism, including the forcibly collected big data of citizens, the institutional collusion between the government and state-owned enterprises can only give up a paper-thin defense line that collapses at the slightest touch. The “digital authoritarianism” touted in propaganda is actually “digitally naked” in reality. Ultimately, the ones harmed are the common people, including those whose personal information, forcibly collected by the authorities, is exposed to high risks from black-hat syndicates.