← Back to list

10 PB of Military Data Stolen Through One VPN Flaw

The alleged NSCC Tianjin hack would be the largest data theft ever recorded — and it happened through a vulnerability class that’s been…

Before The Curve · 2026-04-10 05:50 · 0 claps · 3.8 min read
#cybersecurity #data-breach #cyber-espionage #supercomputing #nationstatehacking
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity ⚖️ · Law & Justice

10 PB of Military Data Stolen Through One VPN Flaw

The alleged NSCC Tianjin hack would be the largest data theft ever recorded — and it happened through a vulnerability class that’s been exploitable for years.

10 Petabytes: The Breach That Dwarfs Everything — Comparing data volumes in major breaches

10 Petabytes: The Breach That Dwarfs Everything — Comparing data volumes in major breaches

Someone claims to have stolen 10 petabytes of classified data from one of China’s most sensitive research facilities. If the claim holds up, it would be the largest single data exfiltration ever documented — eclipsing every known breach by orders of magnitude.

The target: China’s National Supercomputing Center (NSCC) in Tianjin, a centralized hub providing infrastructure for more than 6,000 clients across China’s defense, aerospace, and scientific sectors.

The method: a compromised VPN domain. The timeline: six months of undetected extraction.

What Was Stolen

An account identifying itself as “FlamingChina” posted a sample dataset to Telegram on February 6, 2026. The claimed contents span aerospace engineering simulations, military technology files, bioinformatics datasets, and nuclear fusion models.

Cybersecurity experts who reviewed the samples told CNN that the data appears authentic. The dataset includes documents marked “secret” in Chinese, technical schematics, and animated renderings of defense equipment including bombs and missiles.

The full dataset is being sold for cryptocurrency — thousands for previews, hundreds of thousands for full access.

Scale in Context

Ten petabytes is approximately 10,000 terabytes. To put that in perspective, the Colonial Pipeline attack in 2021 involved under 100 terabytes. The Mercor breach earlier in 2026 — which exposed 4 terabytes including 40,000+ Social Security numbers — is 2,500 times smaller.

Some researchers have noted the figure may be inflated for commercial leverage. Even a fraction of the claimed volume would still represent a historic breach of classified military research infrastructure.

The Attack Vector

The attacker entered through a compromised VPN domain — a vulnerability class that the cybersecurity industry has flagged repeatedly as the leading enterprise attack surface.

Once inside, FlamingChina deployed automated extraction tools that operated for approximately six months without triggering detection. This implies either inadequate network monitoring, insufficient data loss prevention controls, or both.

VPN vulnerabilities aren’t exotic. They’ve been the primary entry point in nation-state attacks for years. That a facility handling classified military simulations was breached through this vector points to a systemic gap between the sophistication of the data being protected and the maturity of the protection itself.

China-Nexus Cyber Operations: 150% Surge and Climbing

China-Nexus Cyber Operations: 150% Surge and Climbing

A Broader Escalation

This breach sits within a larger pattern. CrowdStrike’s 2025 Global Threat Report documented a 150% surge in Chinese-backed cyber espionage, with critical industries seeing up to 300% increases. The firm identified seven new China-nexus threat groups in a single year.

The roster of Chinese state-linked operations reads like an escalation ladder. Salt Typhoon compromised nine US telecom companies. Volt Typhoon pre-positioned inside US critical infrastructure for potential wartime disruption. And CISA’s China threat advisories now form one of the agency’s largest advisory categories.

Simultaneously, Russia’s APT28 just had its FrostArmada campaign disrupted — a global operation that hijacked 18,000+ routers across 120 countries to steal Microsoft 365 credentials. The two superpowers’ cyber operations are running in parallel, creating compound risk.

Global Context

The breach surfaces at a charged geopolitical moment. As US-Iran ceasefire talks continue in Islamabad and the world’s diplomatic attention is consumed by Middle East negotiations, the US-China technology confrontation is intensifying on a separate track. New Section 301 investigations targeting Chinese semiconductor dominance are underway, with public hearings scheduled for April 28 and a Trump-Xi summit expected in May.

The stolen data — covering aerospace, military simulations, and nuclear fusion — maps directly onto the categories of strategic competition driving trade tensions. Whether or not the US intelligence community had any role in the breach, its existence creates asymmetric leverage heading into negotiations.

Key Takeaways

VPN security remains the weakest link in classified infrastructure. The NSCC Tianjin breach allegedly occurred through a compromised VPN domain — a vulnerability class that enterprises of all sizes should be auditing immediately. If a Chinese military supercomputing hub can fall to this vector, no organization is exempt. Review your VPN configurations, patch firmware, and eliminate default credentials.

Shared computing infrastructure creates cascading risk. The NSCC served 6,000 clients including defense agencies. A single breach in centralized infrastructure compromises every client by association. Organizations running sensitive workloads on shared HPC or cloud environments should assess their segmentation posture.

The offense-defense gap is widening at the nation-state level. China has built one of the world’s most aggressive cyber espionage programs — 150% growth, 330+ blocked intrusions, nine compromised US telecoms. Yet its own premier research facility may have been vulnerable to a known VPN exploit for six months. The asymmetry between offensive investment and defensive hygiene is the defining cybersecurity story of 2026.

AI research infrastructure is the next target. With $242 billion pouring into AI in Q1 2026, the datasets and models being generated are among the most valuable intellectual property ever created. If supercomputer-grade research facilities can be breached, the security of rapid-growth AI labs and cloud research environments deserves urgent scrutiny.

Expect regulatory response within 90 days. China will almost certainly tighten cybersecurity mandates for national computing infrastructure. Separately, the US Section 301 hearings on April 28 may cite this breach as evidence of systemic vulnerability in Chinese technology infrastructure, adding fuel to the tariff and export control debate.

Follow Before the Curve on Medium and Substack for daily cutting-edge intelligence at the intersection of technology, security, and geopolitics.


메타데이터
post_id
31076debe28e
slug
10-pb-of-military-data-stolen-through-one-vpn-flaw-31076debe28e
url
https://medium.com/@beforethecurve/10-pb-of-military-data-stolen-through-one-vpn-flaw-31076debe28e
canonical_url
https://medium.com/@beforethecurve/10-pb-of-military-data-stolen-through-one-vpn-flaw-31076debe28e
author_url
https://medium.com/@beforethecurve
status
ok
fetched_at
2026-08-19 01:22:14