National Nuclear Security Administration
Incident posture
Linked entities
- Victim
- National Nuclear Security Administration
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
The National Nuclear Security Administration was among the organizations breached in a hack targeting Microsoft's SharePoint document management software, according to a Bloomberg News report citing a person with knowledge of the matter. The agency, which is responsible for maintaining and designing the nation's cache of nuclear weapons, was compromised as part of the broader SharePoint attack, though no sensitive or classified information is known to have been exposed. Reuters was unable to independently verify the report, and requests for comment from the U.S. Energy Department, the Cybersecurity and Infrastructure Security Agency, and Microsoft went unanswered at the time of publication.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
U.S. National Nuclear Security Administration was among the organizations breached by a hack of Microsoft's SharePoint document management software, according to a report from Bloomberg News on July 22, 2025. The agency, which is responsible for maintaining and designing the United States' cache of nuclear weapons, was identified as one of the victims of the SharePoint vulnerability exploitation, with Bloomberg citing a person with knowledge of the matter. The disclosure came as part of a broader reporting effort examining the scope of the Microsoft SharePoint incident, in which multiple federal entities and organizations were reportedly targeted through flaws in the widely-deployed collaboration platform. Reuters, which reported on the Bloomberg story, indicated that it could not immediately verify the report at the time of publication.
The incident specifically affected the National Nuclear Security Administration, a semi-autonomous agency within the U.S. Department of Energy that oversees the nation's nuclear weapons stockpile and related security programs. According to the Bloomberg reporting referenced by Reuters, no sensitive or classified information was known to have been compromised as a result of the breach. This detail was specifically attributed to a person with knowledge of the matter rather than to an official agency statement, and the absence of evidence of compromise of classified material was presented as a key finding in the initial reporting on the incident. The SharePoint software involved in the breach is a document management and collaboration platform developed by Microsoft that is widely used across federal agencies and private sector organizations for internal file sharing and content management.
At the time of the Reuters report on July 22, 2025, several relevant parties had not yet provided official statements or responses to inquiries about the incident. The U.S. Energy Department, which serves as the parent organization for the National Nuclear Security Administration, did not immediately respond to requests for comment from Reuters. Similarly, the U.S. Cybersecurity and Infrastructure Security Agency, the federal entity responsible for coordinating cyber defense efforts across civilian government networks, did not immediately respond to comment requests. Microsoft, the vendor whose SharePoint product was exploited in the attack, also did not immediately respond to Reuters's inquiries. The lack of immediate official responses from these organizations meant that the initial public understanding of the incident relied entirely on the anonymous sourcing provided to Bloomberg News, without corroboration from the affected agency, its parent department, the lead federal cybersecurity agency, or the software vendor involved.
Sources
Sources available to members: 1 source.