CSIDB logo
Incident

National Nuclear Security Administration

Incident posture

Attack window
Jul 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 10:37

Linked entities

Victim
National Nuclear Security Administration
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Jul 2025
Resolved
Pending

Summary

The National Nuclear Security Administration was among the organizations breached in a hack targeting Microsoft's SharePoint document management software, according to a Bloomberg News report citing a person with knowledge of the matter. The agency, which is responsible for maintaining and designing the nation's cache of nuclear weapons, was compromised as part of the broader SharePoint attack, though no sensitive or classified information is known to have been exposed. Reuters was unable to independently verify the report, and requests for comment from the U.S. Energy Department, the Cybersecurity and Infrastructure Security Agency, and Microsoft went unanswered at the time of publication.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

U.S. National Nuclear Security Administration was among the organizations breached by a hack of Microsoft's SharePoint document management software, according to a report from Bloomberg News on July 22, 2025. The agency, which is responsible for maintaining and designing the United States' cache of nuclear weapons, was identified as one of the victims of the SharePoint vulnerability exploitation, with Bloomberg citing a person with knowledge of the matter. The disclosure came as part of a broader reporting effort examining the scope of the Microsoft SharePoint incident, in which multiple federal entities and organizations were reportedly targeted through flaws in the widely-deployed collaboration platform. Reuters, which reported on the Bloomberg story, indicated that it could not immediately verify the report at the time of publication.

The incident specifically affected the National Nuclear Security Administration, a semi-autonomous agency within the U.S. Department of Energy that oversees the nation's nuclear weapons stockpile and related security programs. According to the Bloomberg reporting referenced by Reuters, no sensitive or classified information was known to have been compromised as a result of the breach. This detail was specifically attributed to a person with knowledge of the matter rather than to an official agency statement, and the absence of evidence of compromise of classified material was presented as a key finding in the initial reporting on the incident. The SharePoint software involved in the breach is a document management and collaboration platform developed by Microsoft that is widely used across federal agencies and private sector organizations for internal file sharing and content management.

At the time of the Reuters report on July 22, 2025, several relevant parties had not yet provided official statements or responses to inquiries about the incident. The U.S. Energy Department, which serves as the parent organization for the National Nuclear Security Administration, did not immediately respond to requests for comment from Reuters. Similarly, the U.S. Cybersecurity and Infrastructure Security Agency, the federal entity responsible for coordinating cyber defense efforts across civilian government networks, did not immediately respond to comment requests. Microsoft, the vendor whose SharePoint product was exploited in the attack, also did not immediately respond to Reuters's inquiries. The lack of immediate official responses from these organizations meant that the initial public understanding of the incident relied entirely on the anonymous sourcing provided to Bloomberg News, without corroboration from the affected agency, its parent department, the lead federal cybersecurity agency, or the software vendor involved.

Sources

Sources available to members: 1 source.

CSIDB