Menu
Browse

Cyber Incident Victim: National Supercomputing Center

Date

Feb 2026

Location

China

Status

Unknown

Updated

2026-08-17 08:50

Timeline
Occurred
Undetermined
Discovered
Undetermined
Disclosed
Feb 2026
Resolved
Pending
Summary

A hacker allegedly breached the National Supercomputing Center (NSCC) in Tianjin and exfiltrated over ten petabytes of sensitive data, including defense documents, missile schematics, and research from aerospace, military, bioinformatics and fusion fields. The group FlamingChina posted a sample of the data on Telegram and offered full access for hundreds of thousands of dollars in cryptocurrency, claiming the theft occurred over several months via a compromised VPN and a botnet that evaded detection.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

A report published on April 8 2026 by CNN described an alleged breach of the National Supercomputing Center in Tianjin, where a hacker using the moniker FlamingChina claimed to have stolen more than ten petabytes of sensitive data, including defense documents, missile schematics, aerospace engineering research, military research, bioinformatics and fusion simulation materials. The group posted a sample of the alleged dataset on an anonymous Telegram channel on February 6, asserting that the information was linked to top organizations such as the Aviation Industry Corporation of China, the Commercial Aircraft Corporation of China and the National University of Defense Technology. According to the account provided to cybersecurity researcher Marc Hofer, the attacker gained entry through a compromised VPN domain, deployed a botnet to extract data over approximately six months and stored the stolen information across multiple systems to avoid triggering alerts. The hacker offered a limited preview of the data for thousands of dollars and full access for hundreds of thousands of dollars, requesting payment in cryptocurrency. CNN noted that it could not independently verify the hacker’s claims or the origins of the dataset, though several experts who reviewed the leaked sample considered it genuine.

Cyber Incident Image

Experts consulted by CNN, including Dakota Cary of SentinelOne and Marc Hofer of the NetAskari blog, stated that the sheer volume of the stolen data would make it attractive to adversarial state intelligence services, though many governments interested in the material might already possess similar information. Cary observed that the NSCC functions as a centralized hub providing infrastructure services for over six thousand clients across China, including advanced science and defense agencies, and that the breach, if genuine, points to a potentially deeper vulnerability in the country’s technology infrastructure. Hofer emphasized that the size of the dataset would likely only be useful to state actors capable of processing such scale. CNN reported that it had reached out to China’s Ministry of Science and Technology and the Cyberspace Administration of China for comment, and noted that China’s National Security White Paper of 2025 had already identified building robust security barriers for the network, data and AI sectors as a key priority, acknowledging that cybersecurity had long been a known weakness across government and private sectors and was still improving.

The alleged breach highlights the NSCC’s role as a critical computational resource for numerous Chinese clients and underscores the potential impact of unauthorized data exfiltration on national security and scientific research. The described method—using a compromised VPN to install a botnet and siphoning data in small, distributed increments—was characterized by experts as relying more on architectural opportunity than on novel technical sophistication. The group’s pricing structure, with preview access priced in the low thousands of dollars and full access in the hundreds of thousands, reflects the perceived value of the stolen material. While the authenticity of the leak remains unverified by CNN, the statements from officials and experts indicate that Chinese authorities are aware of ongoing cybersecurity challenges and have outlined intentions to strengthen coordinated defenses for key information infrastructure.

Sources
Sources available to members
2 sources