The person at the center of this case
Sophos firewall users and affected organizations
Justice for Sophos firewall users and affected organizations โ the trail went cold in 2026, but the truth hasn't.
Start here
What specific technical expertise and resources did Guan Tianfeng utilize to develop the zero-day vulnerability?
How many organizations and individuals were affected by the data exfiltration from the compromised firewalls?
What is the significance of his ties to Bangkok, Thailand, and does he maintain active networks there?
Guan Tianfeng is wanted for his alleged role in developing and testing a zero-day vulnerability that compromised approximately 81,000 Sophos firewalls, enabling unauthorized access and data theft. Federal charges include conspiracy to commit computer fraud and wire fraud, with an arrest warrant issued by the U.S. District Court, Northern District of Indiana. He is believed to be residing in Sichuan Province, China, with known ties to Bangkok, Thailand.
Try asking
A one-time $10 claim transfers this imported case workspace to your account. You get 10 uploads for this case, 25 daily AI questions for this case, and public tips with files route to you.
This does not start a subscription. When the included limits are reached, the Personal plan unlocks more workspace capacity.
Beyond the top three above โ each detail below could be the thread that pulls this case open.
Who were the co-conspirators in this operation, and what were their specific roles?
Even the smallest detail could be the key to solving this case.
Official wording
Conspiracy to Commit Computer Fraud; Conspiracy to Commit Wire Fraud Caution: Guan Tianfeng is wanted for his alleged role in conspiring to access Sophos firewalls without authorization, cause damage to them, and retrieve and exfiltrate data from both the firewalls themselves and the computers behind these firewalls. The exploit was used to infiltrate approximately 81,000 firewalls.
It is alleged that Guan Tianfeng's role in the conspiracy was to develop and test the zero-day vulnerability used to conduct the attack. A federal arrest warrant was issued for Guan Tianfeng in the United States District Court, Northern District of Indiana, Hammond Division, after he was charged with conspiracy to commit computer fraud and conspiracy to commit wire fraud.
Remarks: It is believed that Guan Tianfeng is currently residing in Sichuan Province, China. He also has ties to or may visit Bangkok, Thailand.
Guan Tianfeng allegedly developed and tested a zero-day vulnerability used to compromise approximately 81,000 Sophos firewalls
Warrant issued by U.S. District Court, Northern District of Indiana, Hammond Division for conspiracy to commit computer fraud and wire fraud
For information leading to the resolution of this case
For information leading to the resolution of this case