
The person at the center of this case
Companies and Government Entities (Edge Devices and Networks)
Justice for Companies and Government Entities (Edge Devices and Networks) — the trail went cold in 2020, but the truth hasn't.
Start here
What is the specific nature of the sensitive data exfiltrated from compromised firewalls and which sectors were most heavily targeted?
Which Advanced Persistent Threat group is responsible, and what are their known tactics, techniques, and procedures?
How was the CVE-2020-12271 vulnerability initially discovered and exploited, and were there earlier indicators of compromise?
On April 22, 2020, an Advanced Persistent Threat group deployed malware exploiting CVE-2020-12271 to compromise edge devices and networks at companies and government entities worldwide, exfiltrating sensitive data from firewalls. The FBI continues to seek the identities of individuals responsible for this ongoing series of indiscriminate cyber intrusions. Public assistance is critical to identifying the threat actors behind these attacks that have persisted since 2020.
Try asking
A one-time $10 claim transfers this imported case workspace to your account. You get 10 uploads for this case, 25 daily AI questions for this case, and public tips with files route to you.
This does not start a subscription. When the included limits are reached, the Personal plan unlocks more workspace capacity.
Beyond the top three above — each detail below could be the thread that pulls this case open.
Have any victims come forward with information about the intrusions, and what technical indicators can help identify compromised systems?
Even the smallest detail could be the key to solving this case.
Official wording
Cyber Intrusions into Companies and Government Entities April 2020 to Present The Federal Bureau of Investigation (FBI) is asking the public for assistance in an investigation involving the compromise of edge devices and computer networks belonging to companies and government entities. As described by Sophos Ltd.
in a recently released cyber security report, on April 22, 2020, an Advanced Persistent Threat group allegedly created and deployed malware exploiting the vulnerability CVE-2020-12271 as part of a widespread series of indiscriminate computer intrusions designed to exfiltrate sensitive data from firewalls worldwide. The FBI is seeking information regarding the identities of the individuals responsible for these cyber intrusions.
Advanced Persistent Threat group created and deployed malware exploiting CVE-2020-12271 vulnerability targeting firewalls worldwide to exfiltrate sensitive data