in ~2005 whilst I was the IT manager at Lckheed Martin's RFID division - we were implementing TLS on Exchange for all email... among other security measures...
We had a compromised machine (linux) and had to un-plug it...
BUT
On the security calls was an interesting conversation about the Chinese infiltration of Lockheed.
Lockheed, had at the time, only (3) three egress connects to the internet.
The chinese did the following:
1. They did phishing attacks on those who worked at Lockheed + plus their orbit who attended various conferences and events... giving them seemingly valid contact info (business cards and such) of their agents who also attended said events.
2. Would email the Lockheed Targets and in the emails contain links to military phishing links which would install malware on said target's machine...
3. Would trickle out data so as not to be exposed...
4. Would attack known international suppliers of Lockheed's sub-components through air-gap measures (meaning that Lockheed epoxied USB ports in machines and suppliers were (ironically) then required to transfer data via USB sticks... and China was infecting the machine which the supplier was loading the USB sticks with such to infect Lockheed employees once they received and connected said sticks...
How this was discovered:
Lockheed employees bitches about machine being slow. Investigation ensues and the trickle malware is discovered;
The chinese know they have been discovered and they open the floodgates on all their bots within Lockheed...
HUGE firehose...
Lockheed had to shut down all three egress until resolution...
Yeah, china is in EVERYTHING.