In an unprecedented cybersecurity incident that occurred in September 2025, more than 500 gigabytes of internal data from China's Great Firewall infrastructure. Security experts are calling it one of the most significant breaches in the history of digital surveillance.

The massive leak includes over 100,000 documents, including internal source code, work logs, configuration files, emails, technical manuals, and operational manuals from Chinese companies related to the censorship mechanism.
The leaked material reveals the technical structure behind China's digital surveillance regime, including raw IP access logs from state-owned telecommunications providers such as China Telecom, China Unicom and China Mobile.
See also: Russian Ransomware Groups Abuse AdaptixC2 for Attacks
The dataset provides unprecedented visibility into real-time traffic monitoring and endpoint interaction protocols , giving researchers a good look at the functional anatomy of the Great Firewall.
Great Firewall Breach
The exposed file shows that the attacker was operating over an extended period of time, meaning that it was either a trusted insider with full access or it was a methodical external data extraction.
The breach reveals critical vulnerabilities in China's distributed enforcement model, exposing moments where the censorship mechanism failed.

DomainTools analysts noted that multiple leak incidents allowed foreign IP addresses to establish unfiltered sessions for extended periods, indicating delays in rule promotion, temporary policy gaps, or failures in detection systems.
Among the most sensitive exposed elements are packet captures (PCAPs) and routing tables, combined with blackhole sinkhole exports, which describe how traffic is silently intercepted, redirected, or dropped.
The Excel spreadsheets list known IP addresses VPN, DNS query patterns, SSL certificate fingerprints , and behavioral signatures of proxy services, providing information for identification and blocking heuristics.
See also: Ribbon Communications: Cyberattack by state hackers
The dataset also includes Visio diagrams that map the internal architecture of the firewall, from hardware deployments to logical enforcement chains spanning across ministries and provinces.
Metadata report and performance
The most valuable element of the leak, strategically speaking, lies in the metadata randomly embedded in thousands of files. These offer unprecedented visibility into the human and organizational machinery behind China's censorship apparatus.
The leak reveals dozens of unique usernames that follow consistent naming conventions, indicative of internal department hierarchies, including system account names and author tags in Office documents that allow association with individual operators.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Authorship data and revision histories link technical documents to specific personnel in government agencies, telecommunications subsidiaries, and third-party contractors.

Cross-referencing these metadata fields with well-known Chinese companies and research institutions (linked to the state) has allowed the construction of preliminary performance clusters that show clear ties to China's major telecommunications providers and academic partners, including digital forensics labs and infrastructure vendors.
See also: Proton Data Breach Observatory: Notifies you when your personal data appears on the Dark Web
Many files maintain internal reports of IP addresses and hostnames corresponding to sandbox and testbed environments used to evaluate censorship circumvention tools, including systems specifically marked for analysis of the Psiphon, V2Ray, and Shadowsocks protocols.
This breach radically shifts the asymmetry between censor and censored, providing detailed insight into China's digital surveillance infrastructure for the first time in history.
