Observed Signal · Apr 9, 2026 · Data Breach · Source: t3n · Impact: 3/5 · Sentiment: Negative
Hacker steals ten petabytes from Chinese supercomputer
A hacker claimed to have exfiltrated more than ten petabytes of data from the National Supercomputing Center in Tianjin, China. Samples posted on Telegram by an account named “FlamingChina” reportedly include classified defense documents, technical files, simulations and missile plans. Security experts who reviewed the samples say the attacker exploited a compromised VPN domain, then spread extraction across many systems to avoid detection; the operation allegedly took about six months. The seller is offering the dataset for cryptocurrency. The incident highlights significant security gaps in China’s high-performance computing infrastructure and raises national-security and data‑sovereignty concerns.
Very large-scale data exfiltration (10+ PB) from a national supercomputing center exposes classified defense and research materials, revealing structural security weaknesses in critical infrastructure with potential national‑security and data‑sovereignty implications.
Track Ten Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- A dataset reportedly larger than 10 petabytes was stolen from the National Supercomputing Center in Tianjin.
- Samples posted on Telegram by an account called "FlamingChina" on February 6, 2026 allegedly include classified defense documents and missile plans.
- Security reviewers say the attacker used a compromised VPN domain and distributed exfiltration across many systems over roughly six months to reduce detection risk.
- The hacker is offering the stolen data for sale in exchange for cryptocurrency.
- Sentinel One consultant Dakota Cary and researcher Marc Hofer examined the released samples and commented on the breach's scope and attractiveness to state actors.
Connected Companies & Entities
2 Entities mappedRelated Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Hugging Face confirms breach of datasets and credentials
Hugging Face disclosed a security breach on July 20, 2026, saying attackers exploited a malicious dataset to run code on its servers, escalate privileges, and access internal datasets and service credentials. The company revoked and rotated compromised credentials, fixed the exploited vulnerability, and urged users to rotate any keys stored on the platform. Hugging Face attributed the attack to an external AI agent that operated across many short-lived sandboxes with self-migrating command-and-control, and said its anomaly detection and a locally hosted LLM helped analyze server logs after a commercial provider’s guardrails blocked analysis. The company has engaged forensic specialists and law enforcement and continues investigating whether customer or partner data was stolen.
US Seizes Domains of China-Linked Botnet
The U.S. Department of Justice and FBI seized a set of domains used to operate a large China-linked botnet that prosecutors say was run by Nanjing Xinjiuwei Network Tech and supplied to a China state-sponsored group known as QTFY. The botnet — composed of thousands of compromised devices and using hardcoded domains for command-and-control — has been tied to intrusions dating back to 2018 affecting NASA, the Federal Reserve, hospitals, defense contractors and multiple federal departments. The government affidavit says the U.S. Senate was compromised as recently as 2026. The DOJ said seizing the domains rendered the botnet inoperable. Network operator Lumen reported observing the attackers and shared threat intelligence with the FBI.
CrowdStrike: China Escalating AI Cyberespionage
CrowdStrike warned in a June 2026 report that China-affiliated state-sponsored actors have increased targeted cyberattacks against U.S. technology companies to steal AI capabilities and intellectual property. The firm said China-nexus actors accounted for more than 58% of state-sponsored targeted attacks against tech firms in the 12 months ending March 31, 2026, and that attackers maintained persistent access to North American tech organizations by exploiting vulnerabilities. CrowdStrike also reported North Korea-affiliated actors attempting to infiltrate IT workforces for revenue generation. The Cyberspace Administration of China did not respond to requests for comment. The story references earlier complaints from Anthropic and OpenAI about Chinese firms extracting competitive intelligence and notes recent public releases of Anthropic’s Claude Fable 5.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
