01 / Executive brief
Executive summary
The hackers in Su Bin's conspiracy could penetrate networks, but they needed an aerospace insider to tell them what mattered. Su, an aviation businessman with industry knowledge, helped two China-based People's Liberation Army officers identify U.S. defense targets, interpret directory listings, select valuable files, and translate stolen material. S1S2
From 2008 through 2014, the group targeted defense-contractor systems, including Boeing computers, and stole sensitive and export-controlled information concerning the C-17 and fighter aircraft. Su admitted helping draft reports for the PLA General Staff Headquarters Second Department describing the acquired technology and its value. He pleaded guilty and received 46 months in federal prison. S1S2
Su Bin at a U.S. border crossing in 2011. The FBI image was later published by U.S. Air Force OSI in its account of the defense-contractor hacking conspiracy.
Federal Bureau of Investigation, via U.S. Air Force OSI · Public domain (U.S. federal government photograph) ↗
The conspiracy targeted sensitive technical information about U.S. military aircraft, including the C-17 transport. Contextual U.S. Air Force image; not evidence recovered in the case.
Staff Sgt. Jacob N. Bailey, U.S. Air Force · Public domain02 / The vignette
What happened
Technical context made hacking selective
Su's role was not primarily to break into computers. His aerospace experience helped the military officers decide which companies, programs, people, and files were worth the effort. When hackers sent him stolen directory listings, he prioritized targets and explained why particular documents would be useful—a human intelligence layer applied to cyber access. S1S2
Contractor files became military reports
The co-conspirators penetrated protected contractor systems, stole military aircraft data, and moved it to China. Su translated selected contents and helped turn raw collections into reports for the PLA Second Department. His plea describes a complete exploitation chain: intrusion, technical triage, cross-border movement, interpretation, and delivery to a state military beneficiary. S1S2
A signed plea fixed the state nexus
Canadian authorities arrested Su in 2014, and he later waived extradition to the United States. In March 2016 he admitted conspiring with the PLA officers to gain unauthorized access and violate export controls; the court sentenced him to 46 months. The public record identifies C-17 and fighter data but does not publish a complete inventory or prove every downstream military use. S1S2
03 / Anatomy
How access became transfer
This chain reconstructs the sequence supported by the cited record. It does not imply that every legitimate relationship follows the same path.
- 01
- 02
- 03
- 04
- 05
- 06
04 / Evidence boundary
What is established—and what is not
Established in the record
- Su admitted conspiring with PLA Air Force hackers to penetrate U.S. defense-contractor systems and steal military technical data. S1S2
- He supplied the industrial context: recommending targets, prioritizing files, explaining value, and translating selected stolen material. S1S2
- The conspirators reported their acquisitions and assessments to the PLA General Staff Headquarters Second Department. S1S2
Uncertain, limited, or unresolved
- The cited plea and sentencing record identify C-17 and fighter-aircraft data but do not publish a complete inventory of every contractor, file, or downstream military use. S1S2
- Su also admitted seeking financial gain; state benefit and personal profit can coexist and should not be treated as mutually exclusive explanations. S1S2
05 / Sequence
Timeline
06 / People and institutions
Who appears in the public record
Su Bin
China-based aviation businessman and admitted conspiracy participant
Outcome: Pleaded guilty and sentenced to 46 months in federal prison
Two People's Liberation Army Air Force officers
China-based hackers with whom Su admitted conspiring
PLA General Staff Headquarters Second Department
Addressee of reports assessing the stolen information and technology
Originator / affected institution
The Boeing Company
Defense contractor whose network and C-17 information were targeted
Originator / affected institution
Additional U.S. defense contractors
Companies whose systems held targeted military aircraft information
07 / Consequences
Documented and attributed harm
The conspiracy removed sensitive and export-controlled information about U.S. military aircraft from defense-contractor systems and delivered it to China. S1S2
Public sources reviewed do not provide a court-found dollar loss or a complete assessment of how the PLA used the stolen technical data. S1
08 / Hindsight analysis
Where leadership could have seen risk
These are our analytic judgments based on the public record, not court findings. They are framed to improve controls without treating nationality as a risk factor.
The scout was outside the network
A knowledgeable industry intermediary made stolen directory listings operationally useful without needing direct contractor employment or credentials.
File names exposed mission value
Even directory structures, program names, and personnel context helped the conspirators choose what to steal before opening every file.
The transfer chain was modular
Intrusion, selection, translation, assessment, and reporting were divided among participants, complicating detection focused on one actor or technique.
09 / Apply the lesson
Actions leaders can take
- companies
Protect metadata and directories
Limit unnecessary directory visibility, monitor reconnaissance patterns, and treat program names, staffing maps, and export classifications as sensitive context.
- companies
Threat-model knowledgeable intermediaries
Include brokers, consultants, suppliers, recruiters, and former personnel who can translate raw access into target priorities when modeling crown-jewel threats.
- both
Join cyber and export controls
Connect intrusion telemetry, data classification, export jurisdiction, incident response, and disclosure obligations before an event occurs.
10 / Source record
Sources
Links point to the public record reviewed for this file. Government releases can summarize court proceedings but remain government-authored sources; the source note identifies those limits.
- S1 government release
Chinese National Who Conspired to Hack into U.S. Defense Contractors' Systems Sentenced to 46 Months ↗
U.S. Department of Justice · Published Jul 13, 2016 · Retrieved Aug 23, 2026
Current sentencing account of the admitted conspiracy, military participants, targets, transfer, reporting, and sentence.
- S2 court record
Plea Agreement for Defendant Su Bin ↗
U.S. District Court for the Central District of California via U.S. Department of Justice · Published Mar 23, 2016 · Retrieved Aug 23, 2026
Signed plea and agreed factual basis detailing targeting, file selection, translation, financial motive, and PLA reporting.