← All case files CS-014 / Last reviewed Aug 23, 2026 Jump to sources ↓

Aerospace & defense / 2008–2016

An aviation businessman guided PLA hackers toward U.S. military aircraft data

Su Bin used his aerospace knowledge to identify targets, select files, translate stolen material, and help turn intrusions into reports for a People's Liberation Army department.

Finding

Su admitted conspiring with two China-based military officers to hack U.S. defense contractors, steal export-controlled military information, send it to China, and report the acquired technology to the PLA's Second Department.

01 / Executive brief

Executive summary

The hackers in Su Bin's conspiracy could penetrate networks, but they needed an aerospace insider to tell them what mattered. Su, an aviation businessman with industry knowledge, helped two China-based People's Liberation Army officers identify U.S. defense targets, interpret directory listings, select valuable files, and translate stolen material. S1S2

From 2008 through 2014, the group targeted defense-contractor systems, including Boeing computers, and stole sensitive and export-controlled information concerning the C-17 and fighter aircraft. Su admitted helping draft reports for the PLA General Staff Headquarters Second Department describing the acquired technology and its value. He pleaded guilty and received 46 months in federal prison. S1S2

FBI image of Su Bin looking toward a border-crossing camera in 2011
photograph

Su Bin at a U.S. border crossing in 2011. The FBI image was later published by U.S. Air Force OSI in its account of the defense-contractor hacking conspiracy.

Federal Bureau of Investigation, via U.S. Air Force OSI · Public domain (U.S. federal government photograph) ↗
United States Air Force C-17 transport aircraft flying above the Blue Ridge Mountains
technology

The conspiracy targeted sensitive technical information about U.S. military aircraft, including the C-17 transport. Contextual U.S. Air Force image; not evidence recovered in the case.

Staff Sgt. Jacob N. Bailey, U.S. Air Force · Public domain

02 / The vignette

What happened

Technical context made hacking selective

Su's role was not primarily to break into computers. His aerospace experience helped the military officers decide which companies, programs, people, and files were worth the effort. When hackers sent him stolen directory listings, he prioritized targets and explained why particular documents would be useful—a human intelligence layer applied to cyber access. S1S2

Contractor files became military reports

The co-conspirators penetrated protected contractor systems, stole military aircraft data, and moved it to China. Su translated selected contents and helped turn raw collections into reports for the PLA Second Department. His plea describes a complete exploitation chain: intrusion, technical triage, cross-border movement, interpretation, and delivery to a state military beneficiary. S1S2

A signed plea fixed the state nexus

Canadian authorities arrested Su in 2014, and he later waived extradition to the United States. In March 2016 he admitted conspiring with the PLA officers to gain unauthorized access and violate export controls; the court sentenced him to 46 months. The public record identifies C-17 and fighter data but does not publish a complete inventory or prove every downstream military use. S1S2

03 / Anatomy

How access became transfer

This chain reconstructs the sequence supported by the cited record. It does not imply that every legitimate relationship follows the same path.

  1. 01

    Relationship established

    Industry expert joined hackers

    Su's aviation and aerospace background gave military hackers context about valuable companies, people, platforms, and files. S1S2

  2. 02

    Sensitive access gained

    Contractor networks penetrated

    His co-conspirators gained unauthorized access to protected U.S. defense-contractor systems, including Boeing computers. S1S2

  3. 03

    Information acquired

    Directories triaged

    Hackers sent Su directory listings, and he told them which files to steal and why the information mattered. S1S2

  4. 04

    Assets moved

    Military data sent to China

    The conspirators stole sensitive and export-controlled files, moved them to China, and had Su translate selected contents. S1S2

  5. 05

    Technology put to use

    Reports prepared for PLA

    Su and his co-conspirators drafted reports to the PLA Second Department describing the acquired technology and its value to the beneficiaries. S1S2

  6. 06

    Competitive harm

    Extradition, plea, sentence

    Su was arrested in Canada, transferred to the United States, admitted the conspiracy, and received 46 months in prison. S1S2

04 / Evidence boundary

What is established—and what is not

Established in the record

  • Su admitted conspiring with PLA Air Force hackers to penetrate U.S. defense-contractor systems and steal military technical data. S1S2
  • He supplied the industrial context: recommending targets, prioritizing files, explaining value, and translating selected stolen material. S1S2
  • The conspirators reported their acquisitions and assessments to the PLA General Staff Headquarters Second Department. S1S2

Uncertain, limited, or unresolved

  • The cited plea and sentencing record identify C-17 and fighter-aircraft data but do not publish a complete inventory of every contractor, file, or downstream military use. S1S2
  • Su also admitted seeking financial gain; state benefit and personal profit can coexist and should not be treated as mutually exclusive explanations. S1S2

Subject response / procedural context

  • Su signed a plea agreement, agreed not to contest its factual basis, and admitted the targeting, translation, reporting, and export conduct summarized here. S1S2

05 / Sequence

Timeline

  1. Intrusion conspiracy

    Su admitted working with two China-based military officers to target and steal U.S. military aircraft information. S1S2

  2. Arrest in Canada

    Canadian authorities arrested Su on a U.S. warrant arising from the hacking conspiracy. S1

  3. Transfer to United States

    Su waived extradition and consented to transfer to face the federal case. S1

  4. Guilty plea

    Su admitted the conspiracy and its detailed factual basis in a signed plea agreement. S1S2

  5. Sentence imposed

    A federal judge sentenced Su to 46 months in prison. S1

06 / People and institutions

Who appears in the public record

Su Bin

China-based aviation businessman and admitted conspiracy participant

Outcome: Pleaded guilty and sentenced to 46 months in federal prison

Two People's Liberation Army Air Force officers

China-based hackers with whom Su admitted conspiring

PLA General Staff Headquarters Second Department

Addressee of reports assessing the stolen information and technology

Originator / affected institution

The Boeing Company

Defense contractor whose network and C-17 information were targeted

Originator / affected institution

Additional U.S. defense contractors

Companies whose systems held targeted military aircraft information

07 / Consequences

Documented and attributed harm

Documented record

The conspiracy removed sensitive and export-controlled information about U.S. military aircraft from defense-contractor systems and delivered it to China. S1S2

Unknown

Public sources reviewed do not provide a court-found dollar loss or a complete assessment of how the PLA used the stolen technical data. S1

08 / Hindsight analysis

Where leadership could have seen risk

These are our analytic judgments based on the public record, not court findings. They are framed to improve controls without treating nationality as a risk factor.

The scout was outside the network

A knowledgeable industry intermediary made stolen directory listings operationally useful without needing direct contractor employment or credentials.

File names exposed mission value

Even directory structures, program names, and personnel context helped the conspirators choose what to steal before opening every file.

The transfer chain was modular

Intrusion, selection, translation, assessment, and reporting were divided among participants, complicating detection focused on one actor or technique.

09 / Apply the lesson

Actions leaders can take

  1. companies

    Protect metadata and directories

    Limit unnecessary directory visibility, monitor reconnaissance patterns, and treat program names, staffing maps, and export classifications as sensitive context.

  2. companies

    Threat-model knowledgeable intermediaries

    Include brokers, consultants, suppliers, recruiters, and former personnel who can translate raw access into target priorities when modeling crown-jewel threats.

  3. both

    Join cyber and export controls

    Connect intrusion telemetry, data classification, export jurisdiction, incident response, and disclosure obligations before an event occurs.

10 / Source record

Sources

Links point to the public record reviewed for this file. Government releases can summarize court proceedings but remain government-authored sources; the source note identifies those limits.

  1. S1

    Chinese National Who Conspired to Hack into U.S. Defense Contractors' Systems Sentenced to 46 Months ↗

    U.S. Department of Justice · Published Jul 13, 2016 · Retrieved Aug 23, 2026

    Current sentencing account of the admitted conspiracy, military participants, targets, transfer, reporting, and sentence.

    government release
  2. S2

    Plea Agreement for Defendant Su Bin ↗

    U.S. District Court for the Central District of California via U.S. Department of Justice · Published Mar 23, 2016 · Retrieved Aug 23, 2026

    Signed plea and agreed factual basis detailing targeting, file selection, translation, financial motive, and PLA reporting.

    court record