Chinese Hackers Hit 996 Devices: What They Stole Will Shock You

·
Listen to this article~3 min

A Chinese-speaking threat actor exploited ZyXEL GS1900 switches and WordPress flaws to steal data from 996 devices and over 18,500 records. Learn how to protect your network.

### The Attack That Slipped Past Everyone Imagine finding out that nearly a thousand devices were quietly compromised, and over 18,500 records were stolen right from under everyone's nose. That's exactly what happened when a Chinese-speaking threat actor exploited vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress sites. The goal? Steal sensitive government data. And they got away with it for who knows how long. This isn't just another breach. It's a reminder that the tools we use every day—routers, switches, content management systems—can become open doors if we're not careful. The attackers didn't need to be geniuses. They just needed patience and a few unpatched flaws. ### How They Did It (And Why It Worked) First, they targeted ZyXEL GS1900 switches. These are common in small to mid-sized networks, often sitting in closets without much oversight. A vulnerability in the firmware let them in. From there, they moved to WordPress sites—probably because so many are outdated or poorly configured. Once inside, they planted backdoors and scraped databases. In total, they hit 996 devices and walked away with more than 18,500 records. That's not a small haul. It's a treasure trove for anyone looking to sell data or launch further attacks. > "The scariest part isn't the number of records. It's how long they went unnoticed. Most organizations don't even know they're breached until it's too late." ### What You Can Do Right Now You might be thinking, "I'm not a government target." But here's the thing: attackers don't discriminate. They scan for weaknesses everywhere. If your network has a ZyXEL switch or a WordPress site, you're in the crosshairs. - **Patch immediately.** Check for firmware updates for your switches and plugins for WordPress. Don't wait. - **Monitor your traffic.** Unusual outbound connections could mean someone's exfiltrating data. - **Use a reputable antidetect browser.** Tools like the best antidetect browser can help you manage multiple profiles securely, especially if you're handling sensitive accounts. They add a layer of privacy that standard browsers don't. - **Educate your team.** Phishing and social engineering often accompany these attacks. A little training goes a long way. ### The Bigger Picture This incident is part of a growing trend: nation-state actors and cybercriminals are blurring lines. They're using the same tactics, and they're getting better at hiding. The only way to stay ahead is to be proactive. Assume you're a target, even if you're small. And remember, it's not just about government data. Your business, your clients, your reputation—all of it is on the line. So take this as a wake-up call. Check your systems, update your defenses, and don't become the next statistic. Stay safe out there.