Great Firewall Export shortlisted for IJ4EU Impact Awards 2026
A leak, a coalition of eight organizations, and China’s censorship and surveillance model being sold abroad.
The Great Firewall Export has been named among the ten investigations shortlisted for the IJ4EU Impact Awards 2026, the European prize for cross-border collaborative journalism. The winners will be announced on 17 September in Budapest.
The recognition belongs to a collaboration of eight organizations, and to a single, unusual source: a leak of more than 100,000 internal documents and source code, roughly 600GB, from Geedge Networks, a Chinese company founded by Fang Binxing, known as the father of China’s Great Firewall. What the leak describes is a shift in how repression is delivered. China’s domestic model of internet control is being turned into a product, sold ready-made to governments abroad.
WHAT THE LEAK REVEALED
At the center of the leak is the Tiangou Secure Gateway, a carrier-grade national firewall built for deep packet inspection, VPN identification, traffic throttling, user reputation scoring, and malware injection. Its companion tool, Cyber Narrator, tracks individual subscribers’ locations via cell tower data and lets operators go back in time to identify users who visited websites later deemed illegal. The system can inject malicious JavaScript and code into web pages and downloaded files in real time, and through a capability Geedge calls DLL Active Defence, a DDoS-for-hire solution, it can recruit users’ own computers into botnet attacks against politically disfavored websites.
InterSecLab’s technical analysis, The Internet Coup, sets it out plainly: companies like Geedge are now openly marketing comprehensive suites of products that give any government cutting-edge tools for both mass and precision surveillance and censorship. The leak also shows that customer data does not stay only with the buyer. It appears to be accessible to Geedge’s own staff, and shared with Mesalab, a laboratory at the Chinese Academy of Sciences, where students use real user data to study how to defeat the tools people rely on to stay safe.
WHERE IT RUNS
The system is already running in five countries, four of them named in the leak and one that could not be identified, with internal job postings pointing to Malaysia, Bahrain, Algeria and India. Each partner traced a different part of that map.
In Kazakhstan, InterSecLab established from the leaked documents that the country was Geedge’s first client government, in 2019, and traced the company’s ties to Mesalab at the Chinese Academy of Sciences. Amnesty International added commercial trade records showing shipments from China to a Kazakh contractor in late 2024, and The Globe and Mail brought the findings to an international audience. In Ethiopia, Follow the Money found a support ticket showing Geedge’s engineers were called in over the blocking of YouTube and Twitter during the February 2023 unrest, matching InterSecLab’s own record of the system being switched to in-line mode at Safaricom data centres in the run-up. In Pakistan, Amnesty International, in Shadows of Control, documented the wider surveillance infrastructure into which Geedge’s system was integrated: the LIMS interception platform and its European and Emirati suppliers, court filings showing the scale of interception, and a decade of commercial trade records covering operators, integrators and vendors. In Myanmar, Justice for Myanmar, in Silk Road of Surveillance, identified the thirteen telecommunications companies whose data centres host the system, mapped their ownership and their development finance backers, and documented the arrests that followed.
The investigation also followed the supply chain. InterSecLab found that Geedge licenses its gateway software through Sentinel HASP, a licensing product now owned by France’s Thales Group, and that one of Geedge’s domains resolved to a server in an Alibaba Cloud data centre in Germany. Der Standard and Follow the Money reported the Western corporate exposure and put the findings to Thales, which confirmed Geedge as a customer. The Tor Project received the leak as a consortium partner, reviewed the report’s Tor section and took coordinated disclosure of the Tor related findings, among them InterSecLab’s discovery that Mesalab researchers had begun studying how to detect and block WebTunnel, one of Tor’s circumvention tools. Independent network level corroboration came from OONI measurements and public Tor relay metrics, which show Tor effectively blocked in Myanmar since May 2024.
HOW THE INVESTIGATION WORKED
The subject demanded cross-border collaboration, and the leak demanded shared technical capacity. InterSecLab hosted the secure research infrastructure and built the methodology that turned 600GB of leaked files, most of them in Chinese, into a dataset every partner could search: an OpenSearch cluster, a Datashare index, and OCR and machine translation across tens of thousands of screenshots and documents. On that foundation, it ran the forensic analysis of how the system works and how it was deployed across five countries and in provincial regions of China.
From there, each partner led on the terrain it knew best. Paper Trail Media coordinated the consortium, and four newsrooms carried the reporting across Germany, Austria, the Netherlands and Canada: Paper Trail Media, Der Standard, Follow the Money and The Globe and Mail. Follow the Money surfaced the Geedge support ticket behind the Ethiopian social media blocking, and, with Der Standard, traced the Western corporate exposure in the supply chain.
Amnesty International ran its own technical investigation of the Pakistan deployment, extracting Geedge’s P19 project from the leaked ticketing and documentation systems and setting it against the wider interception apparatus it documented independently: the LIMS platform and its European and Emirati suppliers, a decade of commercial trade records covering operators, integrators and vendors, court filings on the scale of lawful interception, and biometric SIM registration. Justice for Myanmar identified the thirteen telecommunications companies whose data centres host the system in Myanmar, mapped their ownership and their development finance backers, and documented the arrests and executions that followed.
CREDITS
The Great Firewall Export was the work of eight organizations, and their published research:
InterSecLab |The Internet Coup: A Technical Analysis on How a Chinese Company is Exporting The Great Firewall to Autocratic Regimes.
Amnesty International | Shadows of Control: Censorship and Mass Surveillance in Pakistan.
Follow the Money | China exports censorship tech to authoritarian regimes.
Der Standard | Wie China seine Totalüberwachung des Internets ins Ausland exportiert.
READ THE FULL INVESTIGATION
The complete investigation, together with the reporting from across the consortium, is gathered at interseclab.org/research/the-internet-coup.
Our thanks to IJ4EU, and to every partner who made it possible.