기사 메일전송
[Focus] A Chronicle of Chinese Espionage Cases… “Why Is South Korea the Only One Remaining Silent?”
  • Kim Young
  • August 28, 2025 at 2:53 PM
기사수정
  • The West has revealed its stance through indictments and rulings.

  • South Korea has never officially acknowledged a 'Chinese spy' case.

  • Dandong Gate, A Critical Vulnerability in Election Security
본 기사는 2000년대 이후 서방 각국에서 적발·기소된 중국 간첩단 사건과 한국 사례를 비교한 연대기적 분석입니다. 미국과 영국, 독일, 호주 등은 해킹·포섭·정보 절취 사건을 정부가 직접 발표하고 사법적으로 처리했지만, 한국에서는 단 한 건도 ‘중국 간첩 사건’으로 공식 규정되지 않았습니다. 특히 단둥을 거점으로 한 전자개표기 침투 정황은 선거 안보의 심각한 허점을 드러내지만 정부는 여전히 “확인된 바 없다”는 입장에 머물러 있습니다. 본지는 이러한 침묵의 구조적 의미를 묻고자 합니다. <편집자 주>

"The Expansion of China's Global Espionage Network." The black lines extending across the map symbolize the covert operational network radiating from China. Graphic by Hanmi IlboCases of Chinese espionage rings are being exposed one after another across the globe. Western nations, including the United States, the United Kingdom, Germany, and Australia, have publicly identified, prosecuted, and brought to trial Chinese activities involving hacking, recruitment, and intelligence theft. They have systematically raised their level of response by defining these organized Chinese espionage activities as a "state-level threat." South Korea, however, has been different. Despite numerous suspicions being raised, the government has not officially acknowledged a single case as a "Chinese espionage incident."

 

Until the early 2000s, China’s activities were primarily focused on cyberattacks.


Chronology of Chinese Espionage Ring Cases. Hanmi Ilbo

From 2003 to 2006, "Titan Rain" was a large-scale hacking campaign targeting U.S. and British defense contractors and government agencies. At the time, Western intelligence agencies warned of possible Chinese involvement, but formal attribution remained limited. In 2009, Canadian researchers exposed "GhostNet," which had infected diplomatic missions and the Dalai Lama’s office worldwide, but no official government announcement followed. The "Aurora attacks," disclosed by global IT firms like Google that same year, also left behind only suspicions of Chinese hacker involvement.

 

Entering the 2010s, China’s intervention became much more direct.


The case of Glenn Shriver, who attempted to be recruited under the guise of being a CIA applicant, was announced and prosecuted directly by the U.S. Department of Justice, ending in a conviction. When the U.S. Office of Personnel Management (OPM) database was hacked in 2015, leaking the personal information of 21 million government employees, the U.S. government took the unusual step of officially announcing that China was responsible. Su Bin, who participated in the theft of aircraft technology, was also convicted by a court. In 2018, the APT10 group, linked to China's Ministry of State Security, infiltrated global cloud companies to steal technical information, leading the U.S. Department of Justice to define it as the work of "Chinese government agencies." While 500 million Marriott hotel customer records were also leaked that year, the matter ended with a company-only announcement.

 

In the 2020s, China’s activities expanded into political and public opinion manipulation, as well as extraterritorial police operations.


In 2020, the FBI revealed through "Operation Fox Hunt" that the Chinese government was tracking and forcibly repatriating overseas dissidents. In 2022, the UK’s MI5 and the FBI issued a joint statement warning against China’s political infiltration. In 2023, a "secret police station" linked to the Chinese Ministry of Public Security was uncovered in New York’s Manhattan Chinatown, leading to indictments. The arrest of a UK parliamentary researcher followed the same context. In 2024, the UK Electoral Commission officially announced an attack by the Chinese hacking group APT31 and, together with the U.S., imposed sanctions. Subsequently, prosecutors in Germany and the UK indicted Chinese espionage rings, and Australia handed down its first conviction for foreign interference. Through official announcements and judicial processes, Western nations have firmly elevated the issue of Chinese espionage rings to a institutional security agenda.

 

In contrast, South Korea has displayed the exact opposite behavior.


Between 2022 and 2023, although international human rights groups raised suspicions about the operation of a Chinese secret police station in Myeong-dong, Seoul, the government repeatedly stated that it could not confirm the allegations and did not define the incident as "Chinese espionage." Even though Chinese individuals were spotted in militarily sensitive areas such as Jeju Airport and Yanggu, there was no official government announcement. The same was true for the National Election Commission (NEC) training center incident on December 3, 2024. Despite strong suspicions of Chinese involvement immediately following the incident, the government ultimately never announced it as a "Chinese espionage case."

 

Notably, the fact that the controversy over electronic vote-counting machine irregularities originated in Dandong, China, is a point of significant interest.


Multiple private security reports pointed out that traces of access to vote-counting machines were directly linked to IP addresses in Dandong. In fact, security experts analyzing the situation found that many of the abnormal connection logs detected in the election vote-counting machines and the NEC network originated from communication networks in Dandong, Liaoning Province, China. Dandong, a border city where North Korean IT personnel operate and where Chinese telecommunications companies are concentrated, has long been identified as a major hub for North Korean cyber operations.

 

Furthermore, between 2021 and 2023, international security conferences repeatedly reported evidence of North Korean hacking groups Kimsuky and Lazarus routing their activities through servers in northeastern China. Some reports even revealed traces of Kimsuky’s internal documents using the same infrastructure as a hosting provider in Dandong, China. This strongly suggests the possibility of North Korea-China cooperation or, at the very least, shared infrastructure, rather than North Korea acting alone.

 

Financial tracking reports also point to the shadow of Dandong. It has been confirmed that payment channels and cryptocurrency laundering routes discovered in activities related to the access of vote-counting machines passed through Chinese banks and the financial network in the Dandong region. Dandong has long been known as a hub for North Korean foreign currency earning, illegal currency exchange, and money laundering.


Despite these circumstances, the government has maintained its stance of "nothing confirmed," avoiding the attribution of the events. Although the "Dandong Gate" revealed a fatal vulnerability in South Korea's electoral security, it remains buried without ever being properly brought to public discourse.

 

International reports tracing internal materials from the North Korean hacking group Kimsuky have also confirmed evidence of shared servers and infrastructure in northeastern China. Analyses have also been raised that money-laundering paths passed through Chinese financial networks. These were signals indicating the possibility of cooperation between China and North Korea. However, the South Korean government has largely attributed these incidents to "North Korean actions," demonstrating an attitude of avoiding foreign policy burdens.

 

Unlike Western countries, which have institutionally defined Chinese espionage cases through official government announcements, indictments, and court rulings, South Korea has not had a single case that the government has recognized as a "Chinese espionage incident" to date. The events existed, but the government has consistently refused to label them.

 

Ultimately, the question boils down to one: "Why is only South Korea silent?"


This silence is not merely a diplomatic avoidance. It risks leaving a security vacuum and weakening the credibility of South Korean democracy in the international community. While the West names espionage ring cases through trials and verdicts, South Korea's silence is becoming a risk in itself.

 

#ChineseEspionageRing #DandongGate #ElectionSecurity #NorthKoreaChinaCollaboration #CyberWarfare #SouthKoreanGovernmentSilence #HackingIncident #InternationalSecurity #NEC #DemocracyCrisis



관련기사
What do you think of this article?
recommend
0
great
0
moved
0

This article has 5comments.

  • Profile
    guest2025-09-03 22:33:05

    소금먹은  좌파들

  • Profile
    hmj2025-08-29 11:01:45

    왜 한국만 침묵하냐고?
    한국은 중국의 속국이기 때문에..

  • Profile
    jigtk2025-08-29 10:40:00

    침묵하는 자가 범인이다

  • Profile
    kingyc712025-08-28 22:01:57

    우린 미국이 안나서면 허당입니다

  • Profile
    guest2025-08-28 20:22:12

    하이브리드 전쟁은 윤통이 대한민국에서 공식적으로 처음 국가적 이슈로 거론되었으나 좌파진영 ㅡ 정당, 언론, 노조, 입법, 사법, 각종 사회단체 등등 ㅡ 모두 일체의 언급을 하지않고 있다. 특히 "부정선거"라는 단어에 대해서는 멍청한 우파 개돼지들 조차 인정하지 않는다. 왜냐면 무식하고 멍청하니까. 이 단어는 우파인지 아닌지를 즉 애국인지 아닌지를 판별하는 리트머스 시험지와도 같다. 윤통의 계몽령이 정답이었다.

정기구독배너
Go to Mobile Site