CrimeOwl AI logoCrimeOwl AI
CasesBlogPricingAboutLaw Enforcement
  1. Home
  2. /
  3. Cases
  4. /
  5. APT 41 GROUP
Back to CasesMore Cases
Multiple international victims including high-technology companies, video gaming firms, telecommunications providers, government agencies, and defense contractors

The person at the center of this case

Multiple international victims including high-technology companies, video gaming firms, telecommunications providers, government agencies, and defense contractors

Case
#532
SourceFBI WantedUpdated Mar 15, 2026
International (targeting victims in United States, Australia, Brazil, Germany, India, Japan, Sweden, and telecommunications providers across Asia-Pacific and beyond)
Federal Bureau of Investigation (FBI) and U.S. District Court for the District of Columbia
Cold Case · Open
6 years waiting · since 2019

APT 41 GROUP

Justice for Multiple international victims including high-technology companies, video gaming firms, telecommunications providers, government agencies, and defense contractors — the trail went cold in 2019, but the truth hasn't.

Start here

Key leads to think about

🎯
suspect
Lead #1

What is the current location and status of the five indicted Chinese nationals, and have any been apprehended?

🔍
evidence
Lead #2

What specific supply chain attack methods did APT 41 employ to compromise hundreds of companies globally?

📍
location
Lead #3

How did the group's alleged connection to Chengdu 404 Network Technology Company facilitate their international cyber operations?

APT 41, a Chinese hacking group also known as BARIUM, conducted sophisticated cyber attacks targeting high-technology, video gaming, telecommunications, and government sectors across multiple continents from 2019 onward. Five Chinese nationals—ZHANG Haoran, TAN Dailin, QIAN Chuan, FU Qiang, and JIANG Lizhi—were indicted on charges including unauthorized computer access, identity theft, money laundering, wire fraud, and racketeering, with victims in over a dozen countries. The case remains active as authorities work to locate and apprehend the defendants and continue investigating the full scope of their global supply chain attacks and ransomware operations.

Case
#532
SourceFBI WantedUpdated Mar 15, 2026
International (targeting victims in United States, Australia, Brazil, Germany, India, Japan, Sweden, and telecommunications providers across Asia-Pacific and beyond)
Federal Bureau of Investigation (FBI) and U.S. District Court for the District of Columbia

Try asking

Claim this imported case

A one-time $10 claim transfers this imported case workspace to your account. You get 10 uploads for this case, 25 daily AI questions for this case, and public tips with files route to you.

10 uploads25 AI questions/day

This does not start a subscription. When the included limits are reached, the Personal plan unlocks more workspace capacity.

More leads to consider

Beyond the top three above — each detail below could be the thread that pulls this case open.

💡
clue
Lead #4

What ransomware variants were deployed by the group, and what payment demands were made to victims?

👁️
witness
Lead #5

Which telecommunications providers and defense contractors were targeted, and what sensitive data or systems were compromised?

Have information about any of these leads?

Even the smallest detail could be the key to solving this case.

Official wording

Source Narrative

Caution: ZHANG Haoran , TAN Dailin , QIAN Chuan , FU Qiang , and JIANG Lizhi are all part of a Chinese hacking group known as APT 41 and BARIUM. On August 15, 2019, a Grand Jury in the District of Columbia returned an indictment against Chinese nationals ZHANG Haoran and TAN Dailin on charges including Unauthorized Access to Protected Computers, Aggravated Identity Theft, Money Laundering, and Wire Fraud.

These charges primarily stemmed from alleged activity targeting high technology and video gaming companies, and a United Kingdom citizen. On August 11, 2020, a Grand Jury in the District of Columbia returned an indictment against Chinese nationals QIAN Chuan , FU Qiang , and JIANG Lizhi on charges including Racketeering, Money Laundering, Fraud, Identity Theft, and Access Device Fraud.

These charges stem from their alleged unauthorized computer intrusions while employed by Chengdu 404 Network Technology Company. The defendants allegedly conducted supply chain attacks to gain unauthorized access to networks throughout the world, targeting hundreds of companies representing a broad array of industries to include: social media, telecommunications, government, defense, education, and manufacturing.

These victims included companies in Australia, Brazil, Germany, India, Japan and Sweden. The defendants allegedly targeted telecommunications providers in the United States, Australia, China (Tibet), Chile, India, Indonesia, Malaysia, Pakistan, Singapore, South Korea, Taiwan, and Thailand.

The defendants allegedly deployed ransomware attacks and demanded payments from victims.

Timeline of Events

🕵️
2019-08-15

First indictment returned

Grand Jury in District of Columbia indicted ZHANG Haoran and TAN Dailin on charges of unauthorized computer access, aggravated identity theft, money laundering, and wire fraud targeting technology and gaming companies

🕵️
2020-08-11

Second indictment returned

Grand Jury in District of Columbia indicted QIAN Chuan, FU Qiang, and JIANG Lizhi on charges of racketeering, money laundering, fraud, identity theft, and access device fraud related to supply chain attacks

Case Information

Incident:August 15, 2019
Last Updated:July 12, 2026

Leave a comment

Comments

Case Information

Incident:August 15, 2019
Last Updated:July 12, 2026