Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Sophos firewall breach: 81,000 devices compromised by Chinese national

The vulnerability, classified as CVE-2020-12271 and rated with a high CVSS score of 9.8, allowed unauthorized access through SQL injection flaws on Sophos firewall devices

byEditorial Team
December 11, 2024
in News, Cybersecurity
Home News

A federal indictment has charged Chinese national Guan Tianfeng with exploiting a zero-day vulnerability in Sophos firewalls, affecting approximately 81,000 devices worldwide in 2020. The U.S. Department of Justice (DoJ) alleges that Guan conspired to deploy malware that compromised sensitive data and infiltrated critical infrastructure.

Chinese national indicted for exploiting Sophos firewall vulnerabilities

The vulnerability, classified as CVE-2020-12271 and rated with a high CVSS score of 9.8, allowed unauthorized access through SQL injection flaws on Sophos firewall devices. Notably, more than 23,000 of the compromised firewalls were located in the United States, with 36 serving U.S. critical infrastructure systems. Guan, also known by aliases gbigmao and gxiaomao, was employed by Sichuan Silence Information Technology Co., Ltd, a company believed to have ties to the Chinese government.

According to the indictment, Guan and his co-conspirators designed malware to exfiltrate data and disrupt firewall functionality. The DoJ stated, “Guan Tianfeng is wanted for his alleged role in conspiring to access Sophos firewalls without authorization, cause damage to them, and retrieve and exfiltrate data.” Investigations are ongoing, and the FBI has sought public assistance in identifying others involved in the attacks.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

Guan’s activities reportedly included exploiting vulnerabilities to steal information and subsequently deploying a ransomware variant, the Ragnarok malware, aimed at encrypting files of victims attempting to remediate the infections. The intent to hide their activities involved registering domains that mimicked Sophos, such as sophosfirewallupdate.com.

In 2021, Sophos had already highlighted the sophistication of the cyber threats they faced, indicating that numerous incidents were perpetrated by advanced persistent threat (APT) groups with significant knowledge of Sophos devices. Following the incidents, Sophos had implemented rapid countermeasures that helped mitigate further exploits. “If any of these victims had failed to patch their systems… the potential impact… could have resulted in serious injury or the loss of human life,” stated the U.S. Treasury Department.

In responding to these cyber threats, the U.S. government has imposed sanctions against both Guan and Sichuan Silence, emphasizing that such cyber activities pose significant risks to both national security and public safety. The indictment reflects a broader effort to confront challenges posed by foreign state-sponsored cyber actors, particularly those based in China.

The U.S. Department of State has also offered rewards of up to $10 million for information leading to identifying individuals engaged in malicious cyber activities against U.S. critical infrastructure. As investigations continue, officials emphasize the need for collaborative efforts in cybersecurity to combat the persistent threat from foreign actors.


Featured image credit: Compare Fibre/Unsplash

Tags: CybersecurityFeatured

Related Posts

Psychopathia Machinalis and the path to “Artificial Sanity”

Psychopathia Machinalis and the path to “Artificial Sanity”

September 1, 2025
GPT-4o Mini is fooled by psychology tactics

GPT-4o Mini is fooled by psychology tactics

September 1, 2025
AI reveals what doctors cannot see in coma patients

AI reveals what doctors cannot see in coma patients

September 1, 2025
Asian banks fight fraud with AI, ISO 20022

Asian banks fight fraud with AI, ISO 20022

September 1, 2025
Android 16 Pixel bug silences notifications

Android 16 Pixel bug silences notifications

September 1, 2025
Azure Integrated HSM hits every Microsoft server

Azure Integrated HSM hits every Microsoft server

September 1, 2025

LATEST NEWS

Psychopathia Machinalis and the path to “Artificial Sanity”

GPT-4o Mini is fooled by psychology tactics

AI reveals what doctors cannot see in coma patients

Asian banks fight fraud with AI, ISO 20022

Android 16 Pixel bug silences notifications

Azure Integrated HSM hits every Microsoft server

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy.