Abstract
This study draws on a synergy of Corpus Linguistics and Critical Discourse Studies to scrutinize the portrayal of hackers in China Daily and The New York Times in the 21st century (2001–2020), primarily revolving around the main social actors and targets in hacking. This study demonstrates that both media share a positive transformation of the image-building of hackers in the 21st century. Besides, countries are salient social actors in hacker media discourse and the two media differ in their ways of constructing them. The New York Times tends to have a negative other-representation and categorical otherness of specific countries through such discursive strategies as negative other-representation and group categorization, whereas China Daily is prone to insist on opposing the US hacking allegations in a defensive manner. Regarding major targets, China Daily highlights government websites whereas The New York Times emphasizes government websites, officials’ emails, large technology companies, and election infrastructure. The analysis shows that the two media’s different ways of framing hackers are underpinned by the ideologies behind them and the Chinese and US socio-political landscapes. This study can provide insights into how hacker discourse in media is represented in the 21st century and how national identities are constructed in the media representations of hackers.
Keywords
Introduction
Given the growing importance of cyberspace to virtually every aspect of human life, hackers, as a crucial community impacting cybersecurity, have been subject to increasing scrutiny in the last two decades. Generally, hacking is a dual-use skill that can be employed for both beneficial and harmful purposes: on the one hand, it can be used to identify loopholes and weaknesses in the computer systems and ensure the security of personal data; on the other hand, it can be misused for revenge, sabotage, extortion, blackmail, and financial gain (Holt and Schell, 2013: xvii). Despite classifying hackers by their intentions into white hat hackers, black hat hackers and gray hat hackers, there has been little consensus among scholars or specialists on what constitutes a hacker.
The term hacker, in lack of an officially agreed definition, takes on different connotations in different periods and for different communities. The modern meaning of the term hacker originated at the Massachusetts Institute of Technology in the 1960s. At that time, hackers, considered as ‘an appellation of honor rather than a pejorative’, referred to ‘computer programmers and designers who regard computing as the most important thing in the world’ (Levy, 2010: ix). The 1980s was a watershed decade in the historical trajectory of hackers, since it marked the emergence of cyberspace and the introduction of personal computers to the public (Power, 2016). Since the 1980s, hackers have been widely portrayed as computer criminals or intruders in the mainstream media, owing largely to the 1983 release of the hacker-thriller movie WarGames (Thomas, 2002). Since the 1990s, the profile of the hackers has been constantly constructed as an outsider, a threat and a danger (Levy, 2010). In consequence, the term hacker has changed over the past five decades, ranging from technical experts and heroes of the computer revolution to cybercriminals who break into computer systems with malicious intent.
Not only has the meaning of hacker evolved over time, but it varies as interpreted by different discourse communities. Hackers often deem themselves something of elites and attribute expertise and enthusiasm to themselves. For instance, Turgeman-Goldschmidt’s (2008) study of face-to-face interviews with 54 Israeli hackers shows that all hackers perceive themselves positively as technological wizards and breakers of boundaries. Hacker Raymond (1996: 234–235) defines a hacker as ‘an expert or enthusiast of any kind’ and ‘a person who is good at programming quickly’, exhibiting a positive and complimentary connotation. However, as noted by Thomas (2002), hackers in the media and popular imagination are often portrayed as malicious criminals, as is also the case in judicial discourse that centers on hackers’ criminality.
As aforementioned, news media serve as a significant contextual setting in which the image of hackers is constructed and further consolidated. National newspapers, as a crucial social and linguistic site, play a particularly significant role in creating national identities and ideologies (Li, 2009). In recent years, the US and China have emerged as the world’s two leading cyber powers, but with a rapidly deteriorating US-Chinese relation in cyberspace (Levite and Lyu, 2019). On 19 July 2021, the US, in collaboration with its allies and partners, accused China of ‘malicious cyber activities’ including hacking (The White House, 2021). Earlier studies have focused mainly on the representation of hackers or hacking in western media, notably the US media (e.g. Kubitschko, 2015; Ooi and D’Arcangelis, 2017; Taylor, 1999; Thomas, 2002; Vegh, 2005). China in the US news rhetoric is framed as a potential enemy other such as a cyber threat (Ooi and D’Arcangelis, 2017; Zhang and Liu, 2015). However, whether the media portrayal of hackers in the Chinese media or that from a comparative cross-country perspective, has been rarely touched upon, except in the work by Zhang and Liu (2015) who compare American and Chinese attitudes toward Internet hacking before and after Snowden Event, based on 32 news coverage from major US and Chinese newspapers from February to December 2013. The present study therefore chooses the US and Chinese newspapers as the research objects to examine whether countries, as crucial social actors involved in hacking, are salient in the hacker discourse in national news media, and if yes, how they are constructed.
Apart from the countries involved in hacking, prior studies also focus on the identity construction of hackers themselves and the socio-political motivations behind it. Halbert (1997), for example, contends that even though the self-representations of hackers tend to be positive, the mainstream media often portray hackers in a negative light. Likewise, by analyzing five major US newspapers in 1 year with 11 September 2001 in the middle, Vegh (2005) states that the hacker discourse framed by media becomes increasingly negative after 11 September 2001, with a shift from hackers as criminals toward hackers as cyberterrorists. The negative media representation of hackers is also demonstrated in other works (e.g. Holt and Schell, 2013; Taylor, 1999). The construction of technological risks may have little to do with the real danger and much to do with the social, political and cultural factors (Douglas and Wildavsky, 1982), especially in the context of social media (Jarvis et al., 2017). Prior studies indicate that media discourse about hackers is not a mere reflection of hackers or hacking incidents, but rather is socially and politically constructed. Vegh (2005), for instance, observes that media framing of hacking has become part of the political and corporate elite’s hegemony. Taylor (1999) highlights that hacking lends itself particularly well to media hyperbole and misinterpretation, which is due primarily to its aura of anonymity. Additionally, the emphasis on the dark side of hacking or hackers in the media might be put down to the news values lying behind journalistic news selections, since that type of news sells (Holt and Schell, 2013). It is thus significant to probe into the socio-political motivations behind the media’s preferred way of constructing hackers.
Overall, it is observed that previous studies on the media representation of hackers focus extensively on ‘who they are’, such as hackers themselves (e.g. Holt and Schell, 2013; Taylor, 1999; Vegh, 2005) and countries (e.g. Ooi and D’Arcangelis, 2017; Zhang and Liu, 2015), whereas less attention is paid to ‘what they do’ which also functions as a critical aspect shaping hacker discourse (Kubitschko, 2015). Besides, a quantitative corpus linguistic analysis of hackers in the news media, particularly in the 21st century, is still sparse. In this respect, one motivation for this study is to examine how hacker discourse in news media is presented in the 21st century. So, this study contributes to the literature by looking at both the social actors involved in hacking and the prime targets for hackers in the 21st century. In view of the preceding background, the objectives of the present study are inherently two-fold: (1) to examine in what way the Chinese and US media converge and diverge in their representations of the social actors and main targets in hacking in the 21st century; (2) to illustrate the socio-political motivations for their respective modes of representations. To this end, this study seeks to employ the corpus approach to compare the news media texts related to hackers in the 21st century, in China Daily (hereafter as CD), a Chinese national newspaper and The New York Times (hereafter as NYT), a US national newspaper.
Theoretical framework: Corpus-based critical discourse analysis
The present study is situated within a corpus-based critical discourse analysis, combining Corpus Linguistics (hereafter as CL) (Baker, 2006) and Critical Discourse Studies (hereafter as CDS) (Flowerdew and Richardson, 2018; Van Dijk, 2008). CL is a useful methodology dealing with linguistic data quantitatively, with a particular emphasis on the frequency lists, keywords, clusters, collocations, concordance lines, etc. CDS is a ‘critical perspective, position or attitude within the discipline of multidisciplinary Discourse Studies’ (Van Dijk, 2016: 62), focusing on various forms of power abuse and the complex relations between social structures and discourse structures (Van Dijk, 2008, 2016, 2018). The integration of CL and CDS can be traced back to the 1990s (Subtirelu and Baker, 2018). CL is beneficial to CDS by unraveling the non-obvious meaning since much of what carries meaning in texts is not accessible to naked-eye and direct observation (Partington et al., 2013: 11). Additionally, CL can help render analysts’ interpretations more trustworthy (Subtirelu and Baker, 2018) and guard against subjectivity and overgeneralization (Hart and Cap, 2014). In turn, CDS, which takes into account the social-political and cultural context of data, enables researchers to counteract the limitation of CL on explaining or interpreting the reasons for the occurrence of certain linguistic patterns (Baker et al., 2008). Such integration has been extensively utilized to approach security or risk discourse in the media, especially the discursive practices of certain social groups or security events, such as antiracism (Van Dijk, 2021), refugees and asylum seeks (Gabrielatos and Baker, 2008), terrorism (Qian, 2010), the Iraq conflict (Morley and Bayley, 2009), global financial crisis (Lischinsky, 2011), environmental issues (Wang, 2018), and so forth.
This study draws upon Van Dijk’s (2016, 2018) socio-cognitive approach to discourse, linking discourse structures to social structures through a complex socio-cognitive interface. From a cognitive perspective, CDS aims not only to describe the structural properties of text and talk, but also to account for how the cognitive, social and political contexts of language use and communication influence the structures, strategies and functions of text or talk (Van Dijk, 2016). Besides, Van Dijk’s (1998) ideological square framework, as a component of his socio-cognitive approach to discourse, outlines the main discursive strategies for self-other representations and thus can contribute to interpreting the social actors and their identity construction in hacker media discourse. Therefore, this study, theoretically guided by Van Dijk’s socio-cognitive approach, starts with an analysis of the discourse structures representing specific topics of hacker discourse and then investigates the discursive strategies adopted to achieve a particular cognitive, social and political objective in the media texts about hackers.
The methodology followed in this study is corpus-based since it uses a corpus as a database to be searched for pre-defined linguistic categories, namely lexical items related to the social actors and targets in hacking. This differs from the corpus-driven approach claiming that the corpus should be the only source of information to be accessed with no prior assumptions and expectations (Tognini-Bonelli, 2001). In doing so, this study, combining CL and CDS, seeks to describe, interpret and explain the discursive construction of hackers in CD and NYT. Utilizing the corpus approach, the study is carried out by computing frequencies and keyness and interrogating their collocational environments around particular words in news texts. It attends to not only an investigation of textual data, but also a critical look at the underlying ideological configurations behind the use of narratives concerning hackers or hacking.
Data and methodology
The data for this study consist of two purpose-built corpora: one of articles in CD and the other of articles from NYT. CD is chosen because it serves as China’s first and largest national English-language newspaper, China’s most influential English-language web portal, 1 and a significant news agenda-setter in the Chinese media system (Duan and Takahashi, 2017). The reason for selecting NYT is due to its top rank, large circulation and wide readership in the US (Samaie and Malmir, 2017). Concerning the state-media relationship, CD, in contrast with other Chinese newspapers, is typical in conveying the government’s attitudes and positions (Liu, 2009), and NYT, which is not independent of the US government, often reveals capitalist and anti-communist values (Duan and Takahashi, 2017). Consequently, the two national newspapers play a critical role in creating national identities and are thus inevitably embedded with national ideologies and values (Duan and Takahashi, 2017; Li, 2009).
CD includes all news texts whose headlines contain the variants of the word hack from its official website, whereas NYT contains news texts retrieved from Nexis Lexis with hack* as a searching word in the news headline. An asterisk at the end of a word acts as a wildcard, so hack* refers to hacker, hacking, hacked, etc. The time frame set for data collection is from 1 January 2001 to 31 December 2020. The year 2001 is selected as the starting point for data collection because this study sets out to investigate the media portrayal of hackers since the 21st century, and the year 2020 was when corpus compilation was finished. A total of 330 CD news texts and 1771 NYT news texts were generated through the online collection. Then, each news text was read through carefully to remove the duplicate and irrelevant articles (e.g. hackett, hacksaw, etc.). Finally, 315 news texts totaling 124,539 tokens were yielded for CD and 1226 news texts totaling 1,002,761 tokens for NYT. The greater levels of media coverage and the higher average article length in NYT account for the size variation between the two corpora.
WordSmith Tools Version 7.0 (Scott, 2018), as one commonly used software package for corpus linguistics, was employed to interrogate the two corpora via two principal functions – KeyWords and Concord. The present study begins with a keyword analysis because keywords provide insights not only into the ‘aboutness’ of a corpus (Scott and Tribble, 2006), but specify the salient lexical items which are fundamentally linked to the description of hackers. The ‘keyness’ of words was calculated by comparing the study corpora (CD and NYT) and the reference corpus British National Corpus (hereafter as BNC). The BNC World Edition (100 million words) was used in this study and retrieved from the WordSmith Tools website. The reason for choosing BNC is that it is well balanced and thoroughly documented with texts from a wide range of genres and subject fields (Kennedy, 1998).
Keywords were identified by combining the log likelihood and log ratio statistics. A high threshold was set for the keyword analysis. To be a keyword, a word must occur in a minimum of 10% of the texts in each corpus, thus with a minimum frequency of 32 occurrences in CD and 123 occurrences in NYT. The log likelihood test was conducted with p-value set at 0.000001 to give 99.9999% confidence that an identified keyword does not occur on the list by chance. The log ratio (Hardie, 2014), as an effect-size measure, was used to refine the keyword calculation and to identify the words where the difference in frequency is greatest. To make CD and NYT comparable in terms of their strength, we compared keywords with a log ratio score of at least 4, meaning that the word is 16 times more common in CD and NYT than in the reference corpus (Hardie, 2014).
The study was carried out in the following stages. Firstly, we carried out a keyword analysis of the two corpora, through which a preliminary overview of the representation of hackers in each corpus was conducted. Secondly, to further examine the social actors and main targets in hacking, we conducted a collocation and concordance analysis of keywords obtained from the first stage from two aspects: one with keywords hack* (e.g. hacker* and hacking) directly denoting hackers, the other with keywords specifically revealing the social actors and main targets (e.g. USA, Russia, Chinese, website*, email*, infrastructure, Google, Facebook, and Twitter). The space restrictions preclude a discussion of all variants of hack (e.g., hacking, hacked, hack), so hacker* and hacking, with the highest log ratio among the variants (See Table 1 below), were selected for further investigation. The keywords USA in CD and Russia* and Chinese in NYT were chosen since they were salient and unexpected social actors in both corpora. Likewise, the choice of keywords website*, email*, infrastructure, Google, Facebook, and Twitter was attributed to their roles as salient targets. The Collocation and Concord functions can aid in providing a broader picture of the immediate textual surroundings of a word. As such, this study aims to elaborate on the construction of hackers by displaying, interpreting and explaining the quantitative profile of hackers respectively in the two corpora by means of the collocate lists and concordance lines of the keywords. It bears mentioning that due to space constraints, the collocate and concordance analysis primarily focused on highly frequent collocates. Moreover, function words were eliminated from all the subsequent collocation analyses to incorporate more meaningful lexical patterns.
The keywords identified in the two corpora ordered by log ratio.
Results and discussion
This section, based on the analytical methodology explained above, focuses on an analysis of the keywords reflecting each corpus’ particular preferences for the framing of hackers. Using the criteria set in the previous section, this study identified 39 keywords for CD and 75 keywords for NYT, as shown in Table 1. 2 Each keyword was ranked by log ratio.
As displayed in Table 1, as expected, a high proportion of basic search terms frequently occur in CD (hackers, hacker, hacking, hacked, and hack) and in NYT (hackers, hacking, hacker, hacked, hack, and hacks). The cyber-related terms in both corpora, such as cyber, Internet, online, web, computers, and network in CD and malware, Internet, online, web, servers, networks, digital, and computers in NYT reinforce the significant role of cyberspace or Internet as a virtual venue for hacking activities. Both corpora embrace several keywords referring to the dangerous nature of hackers, such as cybersecurity, attacks, scandal, allegations, victims, arrested, and attack in CD, and cybersecurity, WikiLeaks, cyberattacks, vulnerabilities, prosecutors, defense, attackers, espionage, malicious, breaches, intrusion, breached, leaked, attacks, steal, stolen, theft and attack in NYT. This suggests that hackers are inextricably linked to the discourse of danger and crime, carrying a negative connotation, a finding supported by Halbert (1997) who argues that hackers, by and large, have long been represented negatively in news media.
The keywords denoting social actors and main targets in hacking were displayed in Table 2. For social actors, as is the nature of keywords, it is expected to find many keywords that are unique to one national context (Mockler and Groundwater-Smith, 2018: 127), such as Beijing, China’s, China and Chinese in CD and Obama, Trump, Hillary, Clinton, and Francisco in NYT. The appearance of several technology-related words, such as experts in CD and experts and researchers in NYT manifests the typically technical facet of hackers. One noticeable difference is the representations of the foreign state actors occurring in each corpus: it is the US 3 in CD (reflected by keyword USA 4 ) whereas it is Russia and China in NYT (reflected by keywords Russian, Russia, and Chinese). The emphasis of the US in CD and Russia in NYT can also be reinforced by the keywords FBI and Putin. For main targets, Table 2 shows that websites serve as the shared targets presented in both corpora, but with a wider variety of targets presented in NYT.
Keywords denoting social actors and main targets in hacking.
It is noted that the keyword analysis conducted above is merely a preliminary overview of keywords representing hackers in the two corpora. In order to have a better understanding of the media representations of social actors and main targets, a closer collocate and concordance analysis of the keywords is required. Therefore, the following two subsections present a closer analysis of these two sets of keywords: one set mainly denotes the social actors in hacking, including hacker* in CD and NYT, USA in CD, and Russia* and Chinese in NYT; and the other set primarily represents the main targets of hackers, including hacking in CD and NYT, website* in CD, as well as email*, website* infrastructure, Google, Facebook, and Twitter in NYT. The rationale for selecting these keywords was discussed in the previous section.
The social actors in hacking
Hacker*
The word hackers has 463 (0.37%) occurrences in CD and 3327 (0.33%) occurrences in NYT, and the word hacker has 235 (0.19%) occurrences in CD and 784 (0.08%) occurrences in NYT. In seeking to investigate how hackers are described in the two corpora, the adjectival and noun collocates with typical descriptive and evaluative meanings, which tend to occur immediately before the words hackers and hacker as modifiers, were examined. The top 10 collocates at L1 position (the first position to the left) of the search word hacker* were then identified in Table 3.
The top 10 evaluative adjectival and noun collocates of hacker*.
Table 3 suggests that the positive connotation of hackers begins to receive extensive attention in the two media. In CD, hat is the most frequent collocate of hackers, and a further scrutiny of its concordance lines shows that all the instances of hat hacker* refer to white-hat hackers. A closer look at the concordance lines of white hat hacker* in CD (Figure 1) and ethical hacker* in NYT (Figure 2) shows the positive portrayal of hackers in the two corpora, as evidenced by the positive phrases used to describe them in CD (lines 1, 2, 6, 7, 8, 9, and 10) and NYT (lines 2, 3, 4, 5, 6, 7, 9, and 10). Therefore, different from the traditional negative media construction of hackers as criminals and terrorists (e.g. Thomas, 2002; Vegh, 2005), positive changes to hackers are on the rise in the 21st century with the emergence of white-hat hackers in CD and ethical hackers in NYT. The overall attitude to hackers in either corpus is not extremely negative.

The sample concordance lines of white hat hacker* in CD.

The sample concordance lines of ethical hacker* in NYT.
As represented in Table 3, both corpora are noted for their preferences for modifying hackers. In NYT, the highly frequent collocates Russian, Chinese, Iranian, Korean, state, and government show that NYT tends to nationalize hackers, constructing countries as the main source of hacking activities. Of the 37 instances of Korean hacker*, 36 concordance lines refer to North Korean hacker* and one denotes South Korean hacker*. This indicates that Russia, China, Iran, and North Korea are discursively constructed as the origins of hackers in NYT. Regarding the self-representation, the collocate lists of hacker* were further investigated and only three instances of American hackers were identified. Although hacking has become a worldwide event and the US itself was also claimed to hack other countries according to Edward Snowden’s revelations (Helm et al., 2013) and WikiLeaks releases (Shane et al., 2017), only Russian, Chinese, Iranian, and North Korean hackers are prominently featured in NYT. The distinct contrast in the frequency of occurrences of negatively represented hackers between self (American hackers) and others (Russian hacker*, Chinese hacker*, Iranian hacker*, and North Korean hacker*) reinforces NYT’s negative other-presentation of hackers.
This to some extent is an emphasis on the foreignness of the hackers, accomplished by the use of negative other-representation strategy (Van Dijk, 1998). A vast literature shows that it functions as a widely used strategy in the discursive construction of exclusion (Erdogan-Ozturk and Isik-Guler, 2020; Reisigl and Wodak, 2001; Van Dijk, 2008, 2021). News is not a value-free reflection of facts (Fowler, 1991) but a portrayal of reality based on certain criteria and values to maintain particular interests (Kim, 2014). Representing hackers as invasively foreign reflects the US’ geopolitical hostility toward these countries who have a history of conflict to a lesser or greater degree with the US. It’s not the first time that the countries like China (Ooi and D’Arcangelis, 2017), Russia (Bolshakova, 2016), and North Korea (Kim, 2014) are negatively constructed as foreign others in western media. This is also consistent with the ingrained anti-communist ideology characterizing the dominant Anglo-American English media (Herman and Chomsky, 1988; Stone and Xiao, 2007). Given the nature of ideologies as basic systems of group-based beliefs (Van Dijk, 1998), hacker discourse in NYT may be ideologically underpinned by the preferences or interests the media represent.
In CD, it can be seen that hacker* seldom collocates with nationality-related words except for Chinese. Actually, it is striking to see Chinese, rather than other countries, is frequently associated with hacker*, since hackers are commonly constructed in a negative sense in both corpora. In general, it is expected that out-groups are depicted in neutral or negative terms, and in-groups in neutral or positive words (Van Dijk, 1998). Hence, the concordance lines of Chinese hacker* as a search cluster were further investigated. It is noticed that CD, except for China, seldom uses specific countries to modify hacker*. The concordance lines of Chinese hacker* in CD were then surveyed. The following four extracts extracted from CD are examples showing the concordance analysis: Extract 1: China rejected accusations from USA officials that (CD, 15 June 2015) Extract 2: A Foreign Ministry spokesman on Tuesday said allegations of (CD, 19 February 2013) Extract 3: The remarks came after a top USA intelligence official claimed that (CD, 12 September 2015) Extract 4: www.mcdonalds.com.cn, the official website for fast food giant McDonald’s China operations, was attacked by a person or persons calling themselves ‘ (CD, 28 December 2004)
It is observed that the Chinese hacker* is primarily used in the following two contexts: first, to describe the hacking allegations from the US (see Extracts 1 and 2); and second, to quote others’ words directly or indirectly (see Extracts 3 and 4). Moreover, the frequent use of collocates overseas and global in Table 3 reveals that CD tends to use broader macro terms to modify hackers instead of specific countries. As a result, NYT and CD diverge in naming or labeling hackers. Naming or labeling is a crucial step in creating an enemy (Aho, 1994: 28). The widely used ‘other countries + hackers’ narratives in NYT imply that the US is a body facing external threats from other countries. Different from NYT that presents other countries in negative terms, CD seldom uses specific countries to modify the term hacker*.
In a sense, this is in line with the inherent Chinese ideology concerning ‘self-other relations which draws on the prevailing philosophy of harmony (not making enemy) in the social and political life of contemporary China’ (Li and Zhu, 2020: 168). Harmony seeking is profoundly rooted in traditional Chinese philosophies such as Confucianism or Daoism. As noted by Van Dijk (1998: 314), ideologies are grounded in the general beliefs of entire societies or cultures. The cultural ideology thus accounts for CD’s more neutral way of articulating the relationship between hackers and other countries. In addition, the attribution of hacking behaviors has been a persistently unsettled problem in the international arena. It is extremely challenging to decisively name a perpetrator of hacking on the grounds that hackers may employ a multitude of technical tools to cover their digital tracks (Newman, 2016).
USA, Russia*, and Chinese
In Table 2, the keywords USA in CD and Russia* and Chinese in NYT indicate the influential role of the US in CD and Russia and China in NYT. The five most frequent lexical collocates of USA within a −5 to +5 span in CD are China (36), hacking (35), said (34), government (31), and intelligence (28). In NYT, the top five frequent collocates of Russia* within a −5 to +5 span are intelligence (333), hackers (328), have (244), hacking (195), and government (179). A preliminary observation of these collocates reveals that both corpora use hack-related terms to modify specific countries. In order to probe into how these countries relate to hacking in each corpus, the concordance lines of relevant collocates were examined. A close examination of the concordance lines of USA in CD suggests that 14 out of the 35 occurrences (USA-hacking) refer to China’s response to the US hacking allegations, as outlined in Figure 3.

The sample concordance lines of USA-hacking in CD.
In NYT, the concordance lines show that 238 out of 328 occurrences for hackers and 99 out of 195 occurrences for hacking occur at the R1 position of Russia*, indicating the extremely frequent use of Russian hackers (235) and Russian hacking (92). Besides, the top five lexical collocates of Chinese within a −5 to +5 span in NYT are hackers (118), government (83), officials (45), military (45), and said (33). Ninety-one of 118 occurrences for hackers occur at the R1 position of Chinese, denoting the widespread use of the label Chinese hackers in NYT. By comparison, the two corpora differ in their ways of constructing other countries concerning hacking activities. CD tends to adopt a defensive posture, merely centering around the rejection or denial of the US hacking allegations. However, NYT is noted for directly casting Russia and China hackers. The collocates of Russia (1139) within a −5 to +5 span were examined to understand better how Russia as one main social actor was constructed in NYT. The result shows that China (68) is identified to be the most frequent one. The concordance lines of Russia and its collocate China were further investigated, as laid out in Figure 4.

The sample concordance lines of Russia-China in NYT.
Figure 4 shows that NYT tends to feature countries like Russia, China, Iran and North Korea together. Moreover, these countries co-occur with negative narratives such as ‘daily attack by’ (line 16), ‘. . . and other adversarial countries’ (line 17), ‘a hacking attack that originated in’ (line 18), ‘cyberattacks daily, not only from’ (line 22), and ‘countries like . . . have implanted malicious’ (line 24). According to the Gallup poll (Younis, 2021), these four countries have long been perceived as the US’ greatest enemies in the 2000s. Therefore, it can be seen that being the US’ enemies or adversaries might determine which countries are constructed together as hackers in NYT. The results further corroborate the aforementioned negative other-presentation in NYT, especially the othering of those countries deemed as the US’ rivals.
This rhetorical strategy othering is a reflection of the use of group categorization strategy to lump countries like Russia, China, Iran, and North Korea into the category ‘them’. Furthermore, the frequent co-occurrence of these countries indicates that the category ‘them’ seems to be a relatively fixed collection in NYT. This group categorization in in-groups and out-groups offers a method for analyzing the fundamental properties of ideological groups and their interests (Van Dijk, 1998, 2021). This finding appears to be unsurprising since Russia, China, Iran, and North Korea have geopolitically long been perceived as the anti-US nexus (Ahrari, 2001). The US news media have a propensity to classify the world into several groups of countries grounded on their ‘pro- or anti- political leanings’ toward the US (Kim, 2014: 240). The countries having unfavorable relations with the US tend to be categorized as out-groups, which fits with the US’ geopolitical hostility toward those countries. In the sense that the identity construction and presentation in media are subject to a particular contextual environment (Seargeant and Tagg, 2014), the categorical otherness is motivated by the fact that these countries are frequently characterized as the US primarily geopolitical adversaries. Furthermore, it is worth noting that the membership category ‘them’ is not always a closed or static collection (Leudar et al., 2004). To put it another way, the incumbency of the category ‘them’ in NYT may be extended or narrowed depending on the changing social and political conditions.
Major targets of hackers
Hacking
A collocation analysis of hacking was undertaken to further identify the key targets of hackers in the two corpora. In CD, the 10 most frequent collocates of hacking within a −5 to +5 span include phone (117), scandal (42), China (36), news (33), USA (30), said (28), Chinese (24), allegations (21), British (20), and computer (18). In NYT, the 10 most frequent collocates of hacking within a −5 to +5 span are phone (287), Russian (96), scandal (81), computer (79), group (78), news (67), attacks (60), investigation (57), London (56), and tools (55). The 10 most frequent collocates of hacking in the two corpora disclose both similarities and differences in the news reporting of hacking. The collocates phone, scandal, and British in CD and phone, scandal, investigation, and London in NYT suggest that the British phone hacking scandal is one primary hacking incident reported in both corpora. Aside from this event, the concordance lines of hacking and its third most frequent collocate China in Figure 5 (lines 1, 3, 5, 7, and 9) show that CD is more concerned with China’s denouncement of the US hacking allegations, which aligns well with the finding described in the previous subsection.

The sample concordance lines of hacking-China in CD.
A concordance analysis of hacking and its second most frequent collocate Russian in NYT shows that NYT gives more weight to the US’ claim of Russian meddling in the presidential election, which appears to be suggestive of the central role of election as a target for hackers, as shown by the concordance lines of hacking-Russian in Figure 6 (lines 1, 2, 3, 4, 5, 7, and 8).

The sample concordance lines of hacking-Russian in NYT.
Website*, email*, infrastructure, Google, Facebook and Twitter
The 10 most frequent lexical collocates of website* within a −5 to +5 span in CD are hacked (29), government (26), attacks (23), official (21), hackers (17), Chinese (16), hacker (11), public (11), hackers (11), and social (11). These collocates show that CD focuses on the hacking of government websites. As shown by the concordance lines of website*-government in Figure 7, hacking into government websites is constructed as a severe problem and a major concern of China.

The sample concordance lines of website*-government in CD.
In NYT, the 10 most frequent lexical collocates of website* within a −5 to +5 span are said (28), hackers (24), fake (19), posted (14), including (14), government (13), called (12), news (12), campaign (11), and attack (11). An investigation of the concordance lines of website* and its collocate government in Figure 8 shows that government websites are also particularly framed as targets for hackers in NYT.

The sample concordance lines of website*-government in NYT.
In NYT, the top 10 frequent lexical collocates of email* within a −5 to +5 span are accounts (135), said (98), account (78), Democratic (77), addresses (76), personal (76), hacked (74), hackers (57), phishing (55), and stolen (51). A closer inspection of the concordance lines of email* and its most frequent collocate accounts (Figure 9) manifests NYT’s emphasis on the hacking of officials’ email accounts.

The sample concordance lines of email*-accounts in NYT.
The top 10 lexical collocates of infrastructure in NYT within a −5 to +5 span are critical (73), Security (38), Infrastructure (35), Agency (23), Cybersecurity (27), election (19), Homeland (11), systems (13), security (11), and attacks (8). Sixty-seven out of 73 occurrences of critical occur at the L1 position of infrastructure. Besides, the concordance lines of infrastructure-election in Figure 10 show the emphasis on election infrastructure as a target, which primarily arises from the alleged Russian interference in the US presidential election (lines 7 and 10). Therefore, critical infrastructure is sketched as one major target of hackers in NYT, with particular attention to the election infrastructure. The concordance lines of the collocates Security, Infrastructure, Agency, Cybersecurity, and Homeland show that these collocates refer to Homeland Security’s Cybersecurity and Infrastructure Security Agency, a US body leading the national effort to understand, manage and reduce risk to the cyber and physical infrastructure. 5

The sample concordance lines of infrastructure-election in NYT.
A further collocation analysis of Google, Facebook and Twitter in NYT indicates that they are frequently collocated with the word-form hack, such as Twitter-hacked (22), Google-hackers (11), and Facebook-hacked (5), thereby representing technology companies as main targets for hackers. Taking a look back at the main targets identified by a detailed collocate and concordance analysis of the aforementioned keywords, this study summarizes that government websites seem to be the main targets of hackers in CD whereas government websites, officials’ emails, large technology companies and election infrastructure appear to be the main targets in NYT. It can thus be noted that the meaning of hacker as a semiotic term may be subject to temporal and spatial variation. At the temporal scale, it needs to be interpreted in specific temporal contexts. This study provides evidence for a shift of hackers’ image in the media from cyberterrorists after 11 September 2001 (Vegh, 2005) to malicious actors hacking into government websites, officials’ email accounts and technology companies nowadays. At the spatial scale, the targeted objects differ in part between CD and NYT. From the standpoint of CDS, textual analysis should not primarily focus on a text and its structural properties, but on the social and political context in which the text is situated and produced (Van Dijk, 2008, 2018). Such an overserved discrepancy in media portrayal of main targets of hackers may be in part attributable to the different social and political circumstances of China and the US, principally shaped by the challenges they are faced with and the great concerns they have for security issues.
Government websites with symbolic significance and large companies with high degree of digitalization of values have always been hot targets for hackers (Kshetri, 2010). It is therefore expected that government websites in both media and prominent US technology companies (Google, Twitter, and Facebook) in NYT are constructed as main targets for hackers. According to the official annual cybersecurity reports 6 released by the National Computer Network Emergency Response Technical Team of China since 2004, government websites have always been perceived as one of China’s most urgent cybersecurity concerns. In the wake of Russian interference in the 2016 US election, since August 2016 when the US announced that certain state election jurisdictions became the victims of cyberattacks, election infrastructure has assumed critical importance to national security with the designation of election systems as critical infrastructure in January 2017 (Humphreys, 2019). A significant election security legislation, namely Election Security Act of 2019, was also introduced in the US to protect its election systems.
In addition, NYT’s construction of election as one main target for hackers also indicates the passage of hackers into the political arena. The politicization of hackers is further supported by the frequently co-occurring political actors such as Russia, China, Iran, and North Korea in NYT, as shown in Figure 4. In light of Felstiner et al.’s (1980) framework for analyzing the politicization of issues, the politicization of hackers in NYT is primarily realized through the following two actions: the naming action, bringing hackers or hacking to the political field and allowing political agents to position themselves as legitimate players in the problem-solving process; and the blaming action, blaming and othering other actors who were against their interests, by using the discursive strategy of negative other-representation and group categorization.
Concluding remarks
The study, combining both qualitative and quantitative approaches, showcases the media representations of hackers in CD and NYT through the lens of corpus-based critical discourse analysis. It reveals not only the media attitude toward hackers in the 21st century, but also how salient social actors (particularly countries) and major targets in hacking are framed in the two media and why they are framed in such ways. More specifically, although both media, on the whole, put emphasis on the negative connotation of hackers, the positive transformation of image-building hackers begins to receive extensive attention in the 21st century. The keywords denoting social actors suggest that foreign countries are salient actors in media discourse on hackers, particularly the US in CD and Russia and China in NYT. Therefore, national identity, as one aspect of the self-identity of hackers, is highlighted in the media representations of hackers. Nevertheless, the two media have divergent ways of other-representations, as evidenced by their distinct approaches of naming or labeling hackers. NYT tends to use nationality-related words to modify hackers and categorically other countries (Russia, China, Iran, and North Korea) that have unfavorable relations with the US as the primary origins of hacking. By contrast, CD prefers to use broader macro-geographical terms to describe hackers, simply reiterating its denouncement of the US hacking allegations in a defensive stance. With respect to major targeted objects for hackers, CD concentrates more on the government websites, whereas NYT is more concerned with government websites, officials’ emails, large technology companies and election infrastructure.
The interpretation of their particular ways of framing hackers or hacking cannot be achieved without situating it within the socio-political and ideological contexts. In the case of the main social actors in hacking activities, NYT is inclined to use negative-other representation and group categorization to delineate countries like Russia, China, North Korea and Iran as the source of hackers and threats. The negative other-representation, which is considered as ‘a fundamental property of ideologies’ (Van Dijk, 1998: 69), expresses the US’ geopolitical ideology. It is assumed that the currently fixed othering of these four countries may vary in response to the US ideology and interests. However, this is in sharp contrast to CD in which the ‘other countries + hackers’ narratives are seldom used, which may be attributed to the harmony-seeking philosophy in contemporary Chinese politics (Li and Zhu, 2020). The varying salient targets for hackers in the 21st century displayed in CD and NYT are embedded in the socio-political contexts of China and the US as well as in specific historical contexts. In consequence, the meaning of hackers, which is typically technical in nature, is context-dependent in media discourse, which drives its understanding to take into account the broader socio-political and historical contexts within which the news texts are located.
The combination of CL and CDS is conducive to providing a descriptive, interpretive, and explanatory analysis of hacker discourse in CD and NYT, focusing not merely on the news texts themselves but also on the socio-political and ideological contexts in which they are interwoven. The findings also offer useful implications for national image construction and global cooperation in the cyber domain. As ideologies may turn into common sense through the act of legitimation (Van Dijk, 1998) and the power of the symbolic elites of the mass media (Van Dijk, 1993, 2018), of particular note is that if the public comes to believe through repetitive exposure to such discursive representations, people may take them for granted. This ideological manipulation may bring about the reproduction of negative stereotypes, stigmatization, prejudices, and exclusion worldwide. The application of othering strategy and the underlying ideologies behind it may lead to ‘deep divides and hostility between nations’ (Bolshakova, 2016: 448) and impinge on the promotion of mutual trust and cooperation between governments in the cyber domain. Moreover, the politicization of hackers may conceal the real nature of hackers and cause great difficulties in attributing the source of hacking activities.
Footnotes
Acknowledgements
We would like to thank the reviewers for the thoughtful reviews and valuable comments which help us improve the quality of the manuscript.
Declaration of conflicting interests
The author(s) declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
Funding
The author(s) disclosed receipt of the following financial support for the research, authorship, and/or publication of this article: The work was supported by the National Social Science Foundation of China (Grant 20ZDA062); and the Zhejiang Provincial Philosophy and Social Science Planning Project (Grant 22NDQN249YB).
