China Information and Communication Design Institute Co., Ltd

China Information and Communication Design Institute Co., Ltd

In September 2025, over 500GB (later estimated at 600GB) of internal data from China’s Great Firewall (GFW) infrastructure was leaked, exposing technical blueprints, operational logs, internal communications, and human networks behind the censorship system. The breach attributed to either an insider or a highly coordinated external adversary revealed 100,000+ files, including RPM packaging servers, Jira/Confluence exports, PCAP/IP logs from state-run telecoms (China Telecom, China Mobile), VPN/proxy fingerprints, DNS queries, SSL certificates, and behavioral detection heuristics. Visio diagrams detailed firewall architectures, VLAN zoning, and edge-control logic, while OCR’d dashboards exposed management interfaces, session logs, and real-time alerts. Critically, metadata linked usernames, organizational roles, and edit trails to engineers and state contractors, unmasking the human infrastructure. The leak also exposed operational failures, accidental blacklist disclosures, and foreign probing via honeypots, undermining GFW’s distributed enforcement. The implications include empowering circumvention communities, revealing surveillance vulnerabilities, and exposing China’s digital authoritarian framework to global scrutiny.

Source: https://cyberpress.org/china-great-firewall-breach/

TPRM report: https://www.rankiteo.com/company/jiangsu-posts-&-telecommunications-planning-and-designing-institute-co.-ltd

"id": "jia2132521103125",
"linkid": "jiangsu-posts-&-telecommunications-planning-and-designing-institute-co.-ltd",
"type": "Breach",
"date": "9/2025",
"severity": "100",
"impact": "6",
"explanation": "Attack threatening the economy of geographical region"
{'affected_entities': [{'industry': ['telecommunications',
                                     'cybersecurity',
                                     'government services'],
                        'location': 'China',
                        'name': 'China Information and Communication Design '
                                'Institute Co., Ltd',
                        'type': ['government-linked infrastructure firm',
                                 'censorship technology operator']},
                       {'industry': 'telecommunications',
                        'location': 'China',
                        'name': 'China Telecom',
                        'type': 'state-run telecom'},
                       {'industry': 'telecommunications',
                        'location': 'China',
                        'name': 'China Mobile',
                        'type': 'state-run telecom'},
                       {'industry': 'public administration',
                        'location': ['China (multiple provinces)',
                                     'Myanmar',
                                     'Kazakhstan',
                                     'Ethiopia'],
                        'name': 'Unnamed provincial GFW operators',
                        'type': ['government agencies',
                                 'regional censorship nodes']}],
 'attack_vector': ['privileged insider',
                   'highly coordinated external adversary'],
 'data_breach': {'data_exfiltration': True,
                 'file_types_exposed': ['PDFs',
                                        'Visio diagrams',
                                        'PCAPs',
                                        'logs',
                                        'spreadsheets',
                                        'configuration files',
                                        'emails',
                                        'Jira/Confluence exports',
                                        'RPM packages',
                                        "screenshots (OCR'd)",
                                        'metadata'],
                 'number_of_records_exposed': '100000+ files (~600GB)',
                 'personally_identifiable_information': ['usernames',
                                                         'organizational '
                                                         'affiliations',
                                                         'edit trails linking '
                                                         'to individuals'],
                 'sensitivity_of_data': 'high (includes state censorship '
                                        'mechanisms, engineer attribution, '
                                        'surveillance tactics)',
                 'type_of_data_compromised': ['technical documentation',
                                              'operational data',
                                              'internal communications',
                                              'network logs',
                                              'censorship heuristics',
                                              'organizational metadata',
                                              'system monitoring data',
                                              'network topology diagrams']},
 'date_detected': '2025-09',
 'date_publicly_disclosed': '2025-09',
 'description': 'In September 2025, over 500GB (estimated 600GB) of internal '
                'data was leaked from Chinese infrastructure firms operating '
                'the Great Firewall (GFW). The breach exposed technical '
                'blueprints, operational logs, internal communications, and '
                "human networks behind China's censorship architecture. The "
                'leaked archive contains ~100,000 files, including project '
                'management data, emails, technical manuals, configuration '
                'files, operational runbooks, RPM packaging server data, '
                'Jira/Confluence exports, PCAPs, IP logs, VPN/proxy '
                'fingerprints, DNS queries, SSL certificates, behavioral '
                'patterns, Visio diagrams, and system-level monitoring logs. '
                "The data reveals vulnerabilities in China's censorship "
                'mechanisms, operational shortcomings, and attribution vectors '
                'linking engineers and contractors to the infrastructure. The '
                'implications include empowered circumvention efforts and '
                'exposure of technical/human weak points in the GFW.',
 'impact': {'brand_reputation_impact': ['severe damage to perceived '
                                        'infallibility of GFW',
                                        "global scrutiny of China's digital "
                                        'authoritarianism',
                                        'loss of credibility in exported '
                                        'censorship technologies'],
            'data_compromised': ['technical blueprints',
                                 'operational logs',
                                 'internal communications',
                                 'RPM packaging server data',
                                 'Jira/Confluence exports',
                                 'PCAPs and IP logs',
                                 'VPN/proxy fingerprints',
                                 'DNS queries',
                                 'SSL certificates',
                                 'behavioral patterns',
                                 'Visio diagrams',
                                 'system-level monitoring logs',
                                 'organizational metadata (usernames, '
                                 'affiliations)',
                                 'edit trails',
                                 'network topology diagrams',
                                 'censorship management interfaces',
                                 'session logs',
                                 'thread/CPU usage data',
                                 'real-time alerts'],
            'identity_theft_risk': ['exposure of usernames and organizational '
                                    'affiliations of engineers/contractors'],
            'operational_impact': ['exposure of censorship and surveillance '
                                   'mechanisms',
                                   'compromised VPN/VPN detection heuristics',
                                   'weakened deep packet inspection (DPI) '
                                   'efficacy',
                                   'disruption of rule propagation across '
                                   'provincial nodes',
                                   'potential exploitation of operational weak '
                                   'points by adversaries',
                                   "loss of trust in GFW's robustness"],
            'systems_affected': ['Great Firewall (GFW) infrastructure',
                                 'provincial-level firewall deployments',
                                 'RPM packaging servers',
                                 'Jira/Confluence systems',
                                 'state-run telecom networks (China Telecom, '
                                 'China Mobile)',
                                 'censorship management interfaces',
                                 'honeypots',
                                 'distributed enforcement nodes']},
 'initial_access_broker': {'entry_point': ['privileged insider access',
                                           'coordinated external intrusion'],
                           'high_value_targets': ['RPM packaging servers',
                                                  'Jira/Confluence instances',
                                                  'state telecom logs',
                                                  'provincial firewall '
                                                  'configurations']},
 'investigation_status': 'ongoing (as of 2025-09)',
 'lessons_learned': ['Distributed censorship architectures are vulnerable to '
                     'centralized data exposure.',
                     'Metadata retention in operational files can enable '
                     'attribution of state actors.',
                     'Operational lapses (e.g., rule propagation failures) '
                     'create systemic weaknesses.',
                     'Exported censorship technologies carry reputational and '
                     'technical risks for the originating state.',
                     'Real-time monitoring logs can reveal tactical '
                     'surveillance methods to adversaries.'],
 'motivation': ['exposure of censorship mechanisms',
                'empowering circumvention communities',
                'geopolitical or ideological',
                'potential adversarial exploitation'],
 'post_incident_analysis': {'root_causes': ['Insufficient metadata '
                                            'sanitization in operational '
                                            'files.',
                                            'Over-reliance on periodic '
                                            'synchronization for distributed '
                                            'enforcement.',
                                            'Lack of granular access controls '
                                            'for high-sensitivity censorship '
                                            'infrastructure.',
                                            'Failure to detect/exfiltration of '
                                            'large-scale data archives.',
                                            'Brittle error handling in rule '
                                            'propagation systems.']},
 'recommendations': ['Implement stricter metadata scrubbing for internal '
                     'documents.',
                     'Enhance segmentation between provincial censorship nodes '
                     'to limit breach scope.',
                     'Adopt zero-trust principles for access to censorship '
                     'infrastructure.',
                     'Conduct regular red-team exercises to test resilience '
                     'against insider threats.',
                     'Reevaluate the export of surveillance technologies to '
                     'high-risk regions.',
                     'Improve synchronization protocols for rule propagation '
                     'across distributed systems.'],
 'references': [{'source': 'Original article (hypothetical)'}],
 'title': 'Massive Data Leak from Chinese Infrastructure Firms Operating the '
          'Great Firewall (GFW)',
 'type': ['data breach',
          'insider threat',
          'cyber espionage',
          'unauthorized disclosure'],
 'vulnerability_exploited': ['operational lapses in rule propagation',
                             'accidental exposure of regional blacklist data',
                             'weaknesses in distributed enforcement '
                             'synchronization',
                             'metadata retention in files']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.