threatintel
actor tracker
All actors

PLA Unit 54466

pla-54466 · primary source: Other · first observed 2017 · last observed 2017
CN · ChinaState-sponsoredHigh confidence

PLA 54th Research Institute (Strategic Support Force Unit 54466) members indicted by the U.S. DOJ on 10 February 2020 for the Equifax data breach of May–July 2017. Four military personnel — Wu Zhiyong, Wang Qian, Xu Ke, and Liu Lei — exploited a known Apache Struts vulnerability (CVE-2017-5638) to exfiltrate personal data on 145.5 million Americans from Equifax's servers. The operation routed traffic through approximately 20 countries to obscure its origin and used 34 servers in nearly a dozen nations. The breach also targeted Equifax employees in the UK and Canada.

Aliases

54th Research InstituteOther

Motivations

espionage

Target sectors

financialtechnology

Target countries

USGBCA

Diamond Model

Caltagirone / Pendergast / Betz 2013 — four-vertex attribution framework.

Adversary
  • PLA Unit 54466
  • China
  • espionage
Infrastructure
Victim
  • financial
  • technology
  • US
  • GB
  • CA

MITRE ATT&CK techniques

Timeline

0 events
No timeline events recorded yet.

Indicators of compromise

0 indicators
No indicators of compromise have been cataloged for this actor yet.

Related actors

shared ATT&CK techniques

References

cite this page

Threat Intel Tracker. (2026-05-19). PLA Unit 54466 — actor profile. Retrieved from https://threatintel.local/actors/pla-54466

no cited activity