Interesting bits from the Google/China fiasco
Why only subject lines? If the attackers could get access to subject lines, why couldn't they access entire e-mails? Apparently because the hackers infiltrated automated systems set up to provide such information to law enforcement in the US and elsewhere. (Getting access to the contents of e-mail messages is harder under US law than getting access to addresses, subject lines, etc, which are considered to be on the "outside of the envelope" and subject to pen register searches).
According to a Macworld source, "Right before Christmas, it was, 'Holy s—, this malware is accessing the internal intercept [systems].'" Later, Google cofounder Larry Page supervised a Christmas Eve meeting on the security breach.
Fun fact: Google's security team managed to penetrate one of the servers being used by the attackers, which was how the full extent of the attack—more than 30 companies—was revealed.