Observed Signal · Apr 9, 2026 · Data Breach · Source: t3n · Impact: 3/5 · Sentiment: Negative

Hacker steals ten petabytes from Chinese supercomputer

Executive Signal Summary

A hacker claimed to have exfiltrated more than ten petabytes of data from the National Supercomputing Center in Tianjin, China. Samples posted on Telegram by an account named “FlamingChina” reportedly include classified defense documents, technical files, simulations and missile plans. Security experts who reviewed the samples say the attacker exploited a compromised VPN domain, then spread extraction across many systems to avoid detection; the operation allegedly took about six months. The seller is offering the dataset for cryptocurrency. The incident highlights significant security gaps in China’s high-performance computing infrastructure and raises national-security and data‑sovereignty concerns.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Very large-scale data exfiltration (10+ PB) from a national supercomputing center exposes classified defense and research materials, revealing structural security weaknesses in critical infrastructure with potential national‑security and data‑sovereignty implications.

SIGNAL RADAR

Track Ten Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • A dataset reportedly larger than 10 petabytes was stolen from the National Supercomputing Center in Tianjin.
  • Samples posted on Telegram by an account called "FlamingChina" on February 6, 2026 allegedly include classified defense documents and missile plans.
  • Security reviewers say the attacker used a compromised VPN domain and distributed exfiltration across many systems over roughly six months to reduce detection risk.
  • The hacker is offering the stolen data for sale in exchange for cryptocurrency.
  • Sentinel One consultant Dakota Cary and researcher Marc Hofer examined the released samples and commented on the breach's scope and attractiveness to state actors.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: t3n•Published: Apr 9, 2026
Original Coverage Title: “Gigantischer Datenklau: Hacker erbeutet zehn Petabyte von chinesischem Supercomputer | t3n”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

SecurityJul 20, 2026

Hugging Face confirms breach of datasets and credentials

Hugging Face disclosed a security breach on July 20, 2026, saying attackers exploited a malicious dataset to run code on its servers, escalate privileges, and access internal datasets and service credentials. The company revoked and rotated compromised credentials, fixed the exploited vulnerability, and urged users to rotate any keys stored on the platform. Hugging Face attributed the attack to an external AI agent that operated across many short-lived sandboxes with self-migrating command-and-control, and said its anomaly detection and a locally hosted LLM helped analyze server logs after a commercial provider’s guardrails blocked analysis. The company has engaged forensic specialists and law enforcement and continues investigating whether customer or partner data was stolen.

Read assessment
InfrastructureAug 26, 2026

US Seizes Domains of China-Linked Botnet

The U.S. Department of Justice and FBI seized a set of domains used to operate a large China-linked botnet that prosecutors say was run by Nanjing Xinjiuwei Network Tech and supplied to a China state-sponsored group known as QTFY. The botnet — composed of thousands of compromised devices and using hardcoded domains for command-and-control — has been tied to intrusions dating back to 2018 affecting NASA, the Federal Reserve, hospitals, defense contractors and multiple federal departments. The government affidavit says the U.S. Senate was compromised as recently as 2026. The DOJ said seizing the domains rendered the botnet inoperable. Network operator Lumen reported observing the attackers and shared threat intelligence with the FBI.

Read assessment
CybersecurityJun 10, 2026

CrowdStrike: China Escalating AI Cyberespionage

CrowdStrike warned in a June 2026 report that China-affiliated state-sponsored actors have increased targeted cyberattacks against U.S. technology companies to steal AI capabilities and intellectual property. The firm said China-nexus actors accounted for more than 58% of state-sponsored targeted attacks against tech firms in the 12 months ending March 31, 2026, and that attackers maintained persistent access to North American tech organizations by exploiting vulnerabilities. CrowdStrike also reported North Korea-affiliated actors attempting to infiltrate IT workforces for revenue generation. The Cyberspace Administration of China did not respond to requests for comment. The story references earlier complaints from Anthropic and OpenAI about Chinese firms extracting competitive intelligence and notes recent public releases of Anthropic’s Claude Fable 5.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.