Key facts
- Finnish police are investigating suspected intrusions at the homes of members of parliament.
- The incidents were reported to the Speaker of Parliament last week.
- Nothing was stolen or broken, but signs of intrusion were found.
- Finnish authorities confirmed APT31, a group linked to China's Ministry of State Security, was responsible for a 2021 parliament breach.
- The 2021 breach involved access to several parliament email accounts.
- The U.S. Treasury and Justice Department have sanctioned and charged individuals linked to APT31.
Finnish police have initiated a preliminary investigation into a series of suspected intrusions at the homes of members of parliament, the police said on Thursday.
The inquiry is in its early stages, with Helsinki police collaborating with the National Bureau of Investigation. Reports of the suspected intrusions were made to the Speaker of Parliament, Jussi Halla-aho, last week. Halla-aho stated that while nothing was stolen or broken, signs of intrusion were evident in the homes, and the number of suspected cases is significant.
This investigation into potential home intrusions follows the official confirmation by Finnish authorities that the APT31 hacking group, which has ties to China's Ministry of State Security (MSS), was responsible for a breach of the Finnish parliament in March 2021. That incident, described as a state cyber-espionage operation, allowed attackers to access several parliament email accounts, including those belonging to Members of Parliament.
A collaborative criminal investigation involving the Finnish Security and Intelligence Service and international partners has been probing the 2021 parliament breach for offenses including aggravated espionage and unauthorized access to information systems. Detective Chief Inspector Aku Limnéll of the National Bureau of Investigation described the ongoing investigation as revealing a "complex criminal infrastructure."
In parallel actions, the U.S. Treasury Department's Office of Foreign Assets Control (OFAC) imposed sanctions on two individuals, Zhao Guangzong and Ni Gaobin, associated with APT31. The U.S. Justice Department also filed charges against these individuals and five others implicated in operations linked to APT31's front company, Wuhan XRZ, for at least 14 years. The U.S. State Department has offered rewards for information on these hackers.
