Drooid Logo
Back to story perspectives

Full Breakdown

Google Disrupts Chinese-Linked Hacking Group Targeting Global Organizations

2/25/2026, 10:10:44 PM

Overview of the Disruption

On February 25, 2026, Google announced the disruption of a Chinese-linked hacking group known as UNC2814, or “Gallium,” which had breached at least 53 organizations across 42 countries. This group has a nearly decade-long history of infiltrating government entities and telecommunications companies, according to findings shared by Google. John Hultquist, chief analyst with Google Threat Intelligence Group, described the operation as a "vast surveillance apparatus" aimed at spying on individuals and organizations worldwide.

Actions Taken by Google

Google, in collaboration with unnamed partners, terminated Google Cloud projects controlled by the hacking group, disabled internet infrastructure utilized by the group, and disabled accounts that accessed Google Sheets for data theft operations. The use of Google Sheets allowed UNC2814 to blend its activities into normal network traffic, avoiding detection. Charley Snyder, senior manager of Google Threat Intelligence Group, noted that the group had confirmed access to 53 entities, with potential access to at least 22 additional organizations at the time of the disruption.

Nature of the Breach

The hacking group reportedly installed a backdoor known as “GRIDTIDE” on systems containing sensitive personal information, including full names, phone numbers, dates of birth, and identification numbers. The targeting methods employed by UNC2814 align with previous campaigns aimed at exfiltrating call data records and monitoring SMS messages, indicating a sophisticated approach to surveillance.

Official Responses

In response to the disruption, Liu Pengyu, spokesperson for the Chinese Embassy, stated that "cyber security is a common challenge faced by all countries and should be addressed through dialogue and cooperation." He emphasized that China opposes hacking activities and rejects attempts to use cybersecurity issues to discredit the nation. Google clarified that the activities of UNC2814 are distinct from another Chinese hacking campaign known as “Salt Typhoon,” which has been linked to attacks on hundreds of U.S. organizations and political figures.

Criticism & Opposition

Critics of the Chinese government's cybersecurity practices argue that such hacking activities undermine international trust and security. The Chinese government’s denial of involvement in hacking activities has been met with skepticism, particularly given the increasing number of reported breaches attributed to Chinese-linked groups.

Conclusion

The disruption of UNC2814 by Google highlights ongoing cybersecurity challenges and the complexities of international relations in the digital age. As cyber threats continue to evolve, the responses from both technology companies and governments will play a crucial role in shaping the future of global cybersecurity efforts.