Su Bin
Attribution profile
- Type
- Spy
- Location
- China
- Known incidents
- 2 incidents
- Sources
- 1 source
- First seen
- 2009-01-01
- Last seen
- 2009-01-01
- Updated
- 2026-07-31 04:15
- Aliases
- 2 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Su Bin, also known as Stephen Su, is a Chinese businessman who served as an executive for a Chinese aerospace company that maintained offices in Canada. He was identified by US authorities as the individual charged with facilitating cyber intrusions against major American defense contractors. Public records indicate his known location is China, although he was apprehended in British Columbia by the Royal Canadian Mounted Police in cooperation with the FBI.
The alleged activity focused on the aerospace and defense sector, specifically targeting companies such as Boeing, Lockheed Martin and other cleared defense contractors located in the United States. According to the Department of Justice, Su Bin worked with unidentified hackers based in China to identify and exfiltrate sensitive military aircraft data, including details on the F‑22, F‑35 fighter programs and the C‑17 cargo plane initiative. The intrusions began in 2009 and continued through 2013, with the actors gaining remote access from China to information residing on the compromised networks. The stated purpose of the data collection, as expressed in an email by Su Bin, was to enable Chinese aircraft designers to “stand easily on the giant’s shoulders” and to rapidly catch up with United States defense technology levels.
The operation resulted in the theft of proprietary designs and technical specifications that could advance Chinese aviation capabilities by building upon existing US technology. Following an international law enforcement effort, Su Bin was arrested on June 28, 2014, and subsequently charged with conspiracy to commit unauthorized access to protected computers and theft of trade secrets. The case highlighted the use of coordinated efforts between US and Canadian authorities to apprehend an individual accused of acting as a conduit for China‑based hackers. No public disclosures have linked the activity to specific malware families or particular intrusion tools, as the available sources describe the scheme in terms of network access and data identification rather than technical tooling. The prosecution underscored the strategic motive of acquiring military aerospace information to support national aviation development.
Incidents
Attributed incidents are available to members.
2 incidentsSources
Sources available to members: 1 source.