# China supercomputer hack exposes 10 PB of military data
An intruder claims months of undetected access to defense data at the Tianjin NSCC. The method was not sophisticated, and that is the alarming part.

A hacker using the handle **FlamingChina** claims to have extracted roughly **10 petabytes** of sensitive data from the **National Supercomputing Center (NSCC) in Tianjin**, China. The haul reportedly includes missile schematics, defense documents marked "secret", and simulations of military equipment. The extraction is said to have run over **several months**, apparently without being detected. It is being offered on an anonymous Telegram channel, at prices reaching **hundreds of thousands of dollars in cryptocurrency**.

Cybersecurity specialists who examined the samples the attacker published say the files look authentic. Dakota Cary, a SentinelOne consultant who specializes in the Chinese market, confirmed as much: "They are exactly what I would expect to see from a supercomputing center."

## How the breach happened

According to accounts obtained by Marc Hofer, a security researcher and author of the NetAskari blog, the attacker said he got into the NSCC through a **compromised VPN domain**. Once inside the system, he deployed a **botnet**: a network of automated programs that pulled data out to multiple servers in parallel, over roughly six months.

Spreading the extraction across several destinations at once lowered the odds of tripping an alert. "You can think of it as having several different servers that you have access to and are extracting data through that gap," Cary explained. The method worked, he said, but was **not particularly sophisticated**. That detail is exactly what makes the case worrying.

The Tianjin NSCC, opened in 2009 as the first of its kind in the country, serves more than **6,000 customers** nationwide, including advanced science and defense agencies.

## What the experts say

Cary noted that the variety in the samples the attacker published "demonstrates the wide range of clients this institution had". Most of them would have no reason to run supercomputing infrastructure of their own.

For Hofer, the size of the leak is what makes it attractive to **state intelligence services**: "Probably only they have the capacity to process all this data and get something useful out of it."

On security posture, Cary was blunt: "They have had poor cybersecurity for a long time across many sectors and organizations. If you look at what policymakers themselves say, cybersecurity in China has not been good."

## A pattern that keeps repeating

The case is not isolated. In 2021, a database holding personal information on up to **one billion citizens** sat exposed and publicly accessible for more than a year. The leak only came to light when an anonymous user offered the data for sale on a hacker forum in 2022.

The government itself acknowledges the weakness. The 2025 National Security White Paper listed building "robust security barriers for the network, data and AI sectors" as a core priority. Meanwhile, the global race for dominance in artificial intelligence keeps raising the value of these assets and making the targets more attractive.

## What this means for technology leaders

The Tianjin NSCC incident goes well beyond geopolitics. It exposes failure patterns that repeat in any organization running shared high-performance infrastructure, cloud environments included:

1. **The perimeter is not a defense.** A compromised VPN domain was the way in. Access controls built on credentials alone, with no behavioral monitoring, are not enough.
2. **Slow exfiltration is invisible.** Without anomaly detection on traffic volume and destination (DLP, UEBA), gradual leaks go unnoticed for months.
3. **Shared infrastructure amplifies the risk.** When thousands of customers depend on the same processing center, the attack surface becomes the sum of every vulnerability. You do not get to work with averages here.
4. **Compliance without monitoring is fiction.** Security policies that exist only in documents do not survive the first real test.

At Uranus, we treat security as **architecture**, not as a checklist. Continuous monitoring, environment segregation, audit trails and incident response are part of the design from the start, because when the attack comes, you cannot improvise the structure. See our approach to [cloud transformation](/capabilities#cloud) and [software engineering](/capabilities#engineering).

---

**Read also:** [Claude Mythos Preview and the new bar for AI-assisted cybersecurity](/blog/claude-mythos-preview-ai-assisted-cybersecurity)

**Sources:** [Yahoo News](https://www.yahoo.com/news/articles/hacker-allegedly-steals-chinese-military-013000127.html) · [CNN Brasil](https://www.cnnbrasil.com.br/tecnologia/centro-de-dados-da-china-pode-ter-sido-alvo-de-ataque-hacker-entenda/)
