Natto Thoughts

Natto Thoughts

i-SOON Leak: Unanswered Questions and What Now?

Chinese hackers’ lax operations security; why Chinese officials have to rely on contractors; why i-SOON might not fear blowback from the leak; and how the name-and-shame strategy seems to be failing.

Natto Team's avatar
Natto Team
Mar 27, 2024
∙ Paid

It has been over a month after the massive leak of i-SOON, a Chinese information security company, revealed the operations of China’s hacker-for-hire industry. We have seen many insightful reports about the i-SOON leak, analyzing i-SOON’s commercial offering; diving deeply into i-SOON’s company culture, “fueled by influence, alcohol and sex”; and utilizing analysis of competing hypothesis (ACH) to assess who was responsible for the i-SOON leak. However, there are still many unanswered questions related to the leak and what it all means in terms of understanding Chinese threat groups, conducting threat analysis and preventing or mitigating future attacks. While the Natto Team has received many inquiries from the media and discussed the leak with experts from the industry, we would like to present these unanswered questions and our think-out-loud Natto Thoughts for the community to explore further.

text
Photo by Tim Mossholder on Unsplash

Operations Security

Why do i-SOON and similar companies …

User's avatar

Continue reading this post for free, courtesy of Natto Team.

Or purchase a paid subscription.
© 2026 Natto Thoughts · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture