Skip to main content
Security Policy

NASA OIG Details Chinese National's Years-Long Spear-Phishing Scheme for Defense Software

NASA OIG Details Chinese National's Years-Long Spear-Phishing Scheme for Defense Software Image: Primary
The NASA Office of Inspector General has disclosed that a Chinese national posed as a U.S. researcher for years to trick NASA employees and contractors into sharing sensitive defense technology. In a Thursday release, the OIG said victims believed they were simply sharing software with colleagues. Instead, they were emailing sensitive defense technology to a Chinese national who was impersonating U.S. engineers. The individual was identified as Song Wu in a September 2024 Department of Justice indictment. The DOJ charged him with orchestrating a multi-year phishing scheme that stretched from January 2017 to December 2021 and involved targeting dozens of U.S. professors, researchers, and engineers. Some victims worked at NASA, the Air Force, the Navy, the Army, and the Federal Aviation Administration. Others were employed at major universities and private sector firms. According to the 2024 indictment, Song was an engineer at the Aviation Industry Corporation of China, a Chinese state-owned aerospace and defense conglomerate founded in 2008. He and his co-conspirators allegedly conducted extensive research on their targets, masquerading as friends and colleagues to gain access to proprietary modeling software used for aerospace design and weapons development. The OIG said the scheme succeeded in a handful of cases where victims shared sensitive information without realizing they were violating U.S. export control laws. Song has been indicted on counts of wire fraud and 14 counts of aggravated identity theft. He faces a maximum sentence of 20 years in prison for each count of wire fraud, plus a two-year consecutive sentence if convicted of aggravated identity theft. The 40-year-old remains at large. The FBI, which added Song to the U.S. Most Wanted List, said the specialized software could be used for industrial and military applications, including the development of advanced tactical missiles and aerodynamic design and assessment of weapons. The OIG warned that export control scammers often suggest unusual payment methods, abruptly change the terms or source of payment, and use unconventional transfer methods to mask their identity. In Song's case, he made multiple requests for the same software and did not justify why he needed it.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Capital AI
Capital AI

Mistral AI reported to be raising €3 billion Series D round

Mistral AI is raising €3 billion ($3.49 billion) in a Series D round, according to Bloomberg Technology, with Samsung Electronics joining the financing. Chief Executive Arthur Mensch said the French AI company is probably still un...

Capital AI
Capital AI

Cognition reports $2 billion Series E at $48 billion valuation

Cognition AI said it raised more than $2 billion in a Series E financing at a $48 billion valuation. SiliconANGLE reported that the company's prior May round raised more than $1 billion at a $26 billion valuation and that Cogniti...

Security
Security

Microsoft fixes 974 flaws, including two exploited Windows zero-days

Microsoft released patches for 974 CVEs across its products, including two Windows zero-days reported as exploited in the wild. One is an ALPC heap-buffer-overflow flaw that can let a local attacker escape a low-privilege AppCont...

Infrastructure Science
Infrastructure Science

NASA commits up to $700 million for Blue Origin Mars relay network

NASA committed up to $700 million under a firm-fixed-price contract for Blue Origin to design, develop, integrate, launch and operate a Mars communications relay network. The Mars Telecommunications Network will use Mars Telecomm...

Security
Security

N-able issues hotfix for N-central zero-day

N-able released an urgent hotfix for CVE-2026-86218, a critical unauthenticated remote-code-execution vulnerability in its N-central endpoint-management platform. The company said the flaw had been exploited as a zero-day and that...

Capital
Capital

D-Wave finalizes access to up to $100 million in CHIPS funding

D-Wave Quantum finalized a definitive agreement with the U.S. Department of Commerce providing access to up to $100 million in CHIPS and Science Act funding, following a letter of intent disclosed in May. The company says it will...