China

Country

Japanese High-performance Automotive Suspension Manufacturer Force to Halt Production in Japan and China

October 31, 2025

TEIN, Inc. suffered a ransomware attack on October 31, 2025. The attack hit the main server, affecting all group companies. Japan HQ factory halted production for one day.
The subsidiary factory in China (TEIN Shock Absorber Manufacturing (Jiangsu) Co., Ltd.) was forced to shut down for one week (from November 3). The company is compensating for the lost time by operating on weekends and expects the final impact to be minimal. Their order/shipping system runs on a separate server and was NOT hit by the incident.

The company has not yet confirmed a data leak, internally or externally.

read more

Ransomware Attack at Circuit Board Maker Unimicron

January 30, 2025

Unimicron Technology ransomware attack impacted its China-based subsidiary. Unimicron did not confirm a data breach, stating the impact of the attack is limited. The manufacturer engaged an external cyber forensic team to conduct incident analysis. Sarcoma ransomware group has claimed the attack and listed the attack on its Tor-based leak website on February 11.

The cybercriminals are threatening to make the stolen data public in less than a week unless a ransom is paid. The samples leaked on its extortion portal appear authentic.

read more

Chinese AI platform DeepSeek Disabled Registrations after Cyberattack

January 27, 2025

Chinese AI platform DeepSeek has disabled registrations on its DeepSeek-V3 chat platform due to an ongoing “large-scale” cyberattack targeting its services.

Just as the DeepSeek AI Assistant app overtook ChatGPT as the top downloaded app on the Apple App Store, the company was forced to turn off new registrations after suffering a cyberattack. “Due to large-scale malicious attacks on DeepSeek’s services, we are temporarily limiting registrations to ensure continued service,” reads a message on the DeepSeek status page. “Existing users can log in as usual. Thanks for your understanding and support.”

While no details about the attack were shared, it is believed that the company is facing a distributed denial-of-service (DDoS) attack against its API and Web Chat platform. While the attack is impacting their registration process, you can now log in with your Google account to gain access.

BleepingComputer reached out to DeepSeek to learn more about the attack but did not receive a response.

read more

Wafer Equipment Maker Hit In Cyberattack

April 11, 2023

Mattson Technology Inc. suffered a cyberattack in 2023 and is now letting folks know about the incident.
“Between April 11, 2023 and April 29, 2023, an unauthorized individual accessed our network and accessed and/or removed certain files from it”. Mattson did not elaborate on the extent of the information stolen. Upon learning about the event, Mattson moved quickly to respond and investigate the incident, assess the security of its systems, and notified potentially impacted individuals.

read more

Wuhan Earthquake Monitoring Center Suspects Cyberattack comes from US.

July 26, 2023

Wuhan Earthquake Monitoring Center suffered a cyberattack. The Wuhan public security bureau Jianghan sub-bureau confirmed the discovery of a Trojan horse program originating from abroad at the Wuhan Earthquake Monitoring Center. According to the public security bureau, this Trojan horse program can illegally control and steal seismic intensity data collected by the front-end stations. This act poses a serious threat to national security. The center has immediately sealed off the equipment that was affected and reported the attack to the public security authorities, in order to investigate the case and handle the hacker organization and criminals according to law, said the statement.

read more

Ransomware Attack Affects Worldwide Operations of Italian Eyewear Giant Luxottica

September 18, 2020

Italy-based eyewear and eyecare giant Luxottica has reportedly suffered a ransomware attack that has led to the shutdown of operations in Italy and China and data leaked on the dark web. .

Union sources confirmed to Italian media Ansa that the employees were sent home due to “serious IT problems.” The ransomware attack affected the company worldwide, and for days offices were not fully operational.

Security official Nicola Vanin stated in a LinkedIn post “Once the event was analysed, the clues were collected in less than 24 hours and the procedure for cleaning up the affected servers began. Work activities are gradually returning to normal in the #Milano plants and headquarters.”

He also stated that “There is currently no access or theft of information from users and consumers.” However a month later the Windows Nefilim ransomware group leaked financial and human resources operations data on the dark web.

read more

Ransomware Attack at Major Tesla Competitor, NIO

December 20, 2022

Chinese electric vehicle manufacturer Nio revealed a major data breach. The hack exposed certain confidential customer and vehicle sales-related information before August 2021. It is believed the hackers demanded $2.25 million worth of Bitcoin in exchange for not leaking their internal data.

read more

Cyberattack at the Chinese Subsidiary of a German Furniture Manufacturer

August 15, 2022

A Chinese production site of the Hettich Group has involuntarily been the victim of a cyber attack. As yet unknown attackers have hacked the internal networks and deposited malware there. The company’s website states: ” It is not yet possible to say when the Chinese subsidiary will be able to fully access all IT systems again. Local production in China is continuing. As far as we know at present, other companies in the Hettich Group are not affected. From today’s point of view, the ability to deliver to our customers outside China is not limited.”

read more