Current Wave Data

Thousands of firewalls infected in Northwest Indiana

By Michael Howie Michael.Howie

Thousands of firewalls infected in Northwest Indiana

Michael Howie

HAMMOND -- A hacker from China faces federal accusations of attempting to hack into firewall devices worldwide, including in Northwest Indiana.

A grand jury indictment, filed Sept. 19 and unsealed Tuesday, charges Guan Tianfeng, 30, with conspiring to commit computer fraud and conspiracy to commit wire fraud.

According to the indictment, Tianfeng worked for a China-based private company, Sichuan Silence Information Technology Co. Ltd., that sold hacking services to Chinese government agencies from July 2018 to May 2020.

Tianfeng and other unnamed co-conspirators allegedly infected approximately 81,000 firewall devices sold by Sophos Ltd., an IT company based in the United Kingdom that sells cybersecurity products.

More than 23,000 of the infected firewalls were located in the United States. Many were in the Northern District of Indiana.

People are also reading...

The primary purpose of a firewall is to secure a network from cyberattacks.

"Guan Tianfeng and his co-conspirators placed thousands of computer networks, including a network in the Northern District of Indiana, at risk by conducting this attack," U.S. Attorney Clifford Johnson said.

Tianfeng and others allegedly "obtained internet domains, servers and firewalls to test malicious computer code for exploiting a zero-day vulnerability in an identified, widely used firewall, testing such code, and ultimately using that code to conduct mass, indiscriminate intrusions targeting such firewalls worldwide," the indictment states.

A zero-day exploit is a previously unknown vulnerability in a computer software or hardware product that can be used in a cyberattack.

Over three days in April of 2020, Tianfeng allegedly used the zero-day exploit to deploy malware on 81,000 firewalls owned by thousands of businesses across the world.

Feds believe Tianfeng intentionally accessed computers in the United States without authorization. In doing so, he allegedly obtained information from a U.S. government entity.

His actions caused software damage to at least one computer used by the U.S. government, the indictment alleges.

The code Tianfeng installed stole victims' usernames and passwords. If the victim tried to reboot their device, the code would attack every Windows-based computer on the victim's network with ransomware -- a type of malicious software that prevents a user from accessing data stored on their device.

The U.S. State Department on Tuesday announced it is offering a reward of up to $10 million to anyone who has information about Tianfeng or his tech company.

Feds believe Tianfeng is currently living in Sichuan Province, China. He also has ties to or may visit Bangkok, Thailand, they say.

The U.S. Department of the Treasury has issued sanctions against Tianfeng and Sichuan Silence, it said.

Gallery: Recent arrests booked into Lake County Jail Edward Zurawski Lynn Wilson Theodore Waggner Jeremy Wienke Cory Williams Kevin Urbina Stephen Rucker Abreya Taylor Gabriel Taylor Kevin Newkirk Dontrell Henderson Jr. Nathaniel Burnett III Ashley Conner Maurice Baker Kaleb Beres Andre Boyer Luis Guarenas Garcia Alexander Taylor James Anderson Tyler Cazy Rishard Watson Luis Vasquez Jr. Kerry Kirk Christina Garza Dekoven Bradley Michael Callicutt Jr. Edwin Diaz-Peralta Andrew Stover Kendrick Walker Miguel Malave Carlos Merced De Jesus Rodrigo Perez Jaylyn Jarrett Zachary Jimerson Aaron Johnstone Jarvis Green Jr. Jose Cervantes Kyle Chakos Juan Cruz Diaz Damen Brown Dejanae Askew Frederick Benner Love 0 Funny 0 Wow 0 Sad 0 Angry 0 * I understand and agree that registration on or use of this site constitutes agreement to its user agreement and privacy policy. Michael Howie

Public safety reporter

Author facebook Author linkedin Author twitter Author email Follow Michael Howie Close Get email notifications on {{subject}} daily! Your notification has been saved. There was a problem saving your notification.

{{description}}

Email notifications are only sent once a day, and only if there are new matching items.

Close Followed notifications Please log in to use this feature Don't have an account? Sign Up Today

Previous articleNext article

POPULAR CATEGORY

corporate

4517

tech

4744

entertainment

5630

research

2532

misc

5895

wellness

4495

athletics

5892