Guan Tianfeng, 30, is believed to be living in China's Sichuan province, according to the State Department.
An indictment charging Guan with conspiracy to commit computer fraud and conspiracy to commit wire fraud was unsealed on Tuesday.
The Treasury Department said it had imposed sanctions on the company Guan worked for, Sichuan Silence Information Technology Co Ltd.
Beijing swiftly hit back, accusing the US of "exploiting cybersecurity issues to smear and discredit China".
"We firmly oppose the excessive application of illegal unilateral sanctions... against Chinese entities and individuals," foreign ministry spokeswoman Mao Ning said at a Wednesday press briefing.
"China will take necessary measures to safeguard the just legal rights and interests of its companies and citizens," she said.
Guan and co-conspirators at Sichuan Silence allegedly took advantage of a vulnerability in firewalls sold by UK-based cybersecurity company Sophos Ltd, according to the indictment.
"The defendant and his co-conspirators exploited a vulnerability in tens of thousands of network security devices, infecting them with malware designed to steal information from victims around the world," Deputy Attorney General Lisa Monaco said in a statement.
Some 81,000 firewall devices were simultaneously attacked worldwide in April 2020, the indictment said, with the aim of stealing data, including usernames and passwords, while also attempting to infect the computers with ransomware.
More than 23,000 firewalls were in the United States, of which 36 were protecting "critical infrastructure companies' systems," the Treasury said.
"The zero-day vulnerability Guan Tianfeng and his co-conspirators found and exploited affected firewalls owned by businesses across the United States," FBI agent Herbert Stapleton said.
"If Sophos had not rapidly identified the vulnerability and deployed a comprehensive response, the damage could have been far more severe."
According to the indictment, Sichuan Silence sold its services and the data it obtained through hacking to Chinese businesses and to government entities, including the Ministry of Public Security.
A man who answered a call to a phone number registered with Sichuan Silence on Wednesday said the company "did not accept interviews" and declined to comment on the sanctions.
The man, who did not identify himself when asked by AFP, also said Guan was "uncontactable."
US sanctions Chinese cybersecurity firm for 'malicious' activities
Washington (AFP) Dec 10, 2024 -
The US slapped sanctions on a Chinese cybersecurity company and one of its employees Tuesday, accusing it of compromising more than 80,000 firewalls in a 2020 attack.
The US Treasury Department said in a statement that it had sanctioned Sichuan Silence Information Technology Company and an employee named Guan Tianfeng over the April 2020 attack, which targeted firewalls around the world, including US critical infrastructure.
Over a three-day period, Guan had exploited a vulnerability in a firewall product, and proceeded to deploy malware against around 81,000 businesses around the world with the aim of stealing data, including usernames and passwords, while also attempting to infect the computers with ransomware, according to the Treasury Department.
More than 23,000 firewalls were in the United States, of which 36 were protecting "critical infrastructure companies' systems," the Treasury said.
"Today's action underscores our commitment to exposing these malicious cyber activities... and to holding the actors behind them accountable for their schemes," Bradley Smith, Treasury acting under secretary for terrorism and financial intelligence, said in a statement.
The Treasury, he added, "will continue to leverage our tools to disrupt attempts by malicious cyber actors to undermine our critical infrastructure."
Alongside the sanctions, the Department of Justice has also unsealed an indictment against Guan, and announced a reward of up to $10 million for information about the employee or company, according to the Treasury Department.
Related Links
Cyberwar - Internet Security News - Systems and Policy Issues
Subscribe Free To Our Daily Newsletters |
Subscribe Free To Our Daily Newsletters |