According to sources, hackers are believed to have stolen more than 10PB (approximately 107 billion gigabytes) of data from the Chinese Communist Party’s “National Supercomputing Center” (NSCC) research facilities. The stolen data reportedly involves aerospace, military, bioinformatics, nuclear fusion simulations, and is being offered for sale at a price of tens of thousands of US dollars, with payment requested in Monero (XMR), a type of cryptocurrency. The incident is said to be the largest known espionage event in China.
A user named “FlamingChina” posted information on an anonymous Telegram channel on February 6, claiming to have hacked into China’s NSCC. The stolen information reportedly includes data from key Chinese state-owned military enterprises such as the Aviation Industry Corporation of China (AVIC), Commercial Aircraft Corporation of China (COMAC), National University of Defense Technology (NUDT), Northwestern Polytechnical University (NWPU), and Huazhong University of Science and Technology (HUST), among others.
“FlamingChina” plans to sell the complete list, with the highest bidder obtaining all the data. The post included XMR address, email, and sample links.
The mentioned Chinese companies and universities are core institutions in the aerospace, defense technology fields of the Chinese Communist Party.
Leaked information circulating online reportedly includes content related to aircraft, submarines, hypersonic aircraft, missile designs, and more.
It is known that there are supercomputing centers in nine cities in China, including Guangzhou, Shenzhen, and Chengdu. The hack is said to have originated from the NSCC in Tianjin. Comments online suggest that the hack was relatively rudimentary. The Tianjin NSCC was established in 2009 and is one of China’s earliest supercomputing centers.
Cybersecurity experts suggest that the hackers easily breached the NSCC’s supercomputer and continuously stole vast amounts of data for months without being detected.
The comments indicate that the breach may have been due to vulnerabilities in Windows nodes or finding Remote Code Execution (RCE) where attackers could execute code directly on computers or servers.
This is considered one of the highest-level vulnerabilities, as gaining access means essentially controlling the host. Leakage could also be due to human error, such as if multiple supercomputing nodes share usernames and passwords, allowing a breach to compromise all.
Downloading such a large amount of data could take up to 56 days if transmitted at 5% bandwidth capacity, according to comments online. The latest timestamp on the screenshot data is December 3 of last year, with sales occurring on February 6 this year, allowing for a significant gap of about two months which is deemed sufficient.
The comments further suggest that the intrusion detection system failed to detect anomalies, and the traffic monitoring system’s malfunction was expected. In conclusion, the criticism is harsh, describing the situation as a total failure.
CNN’s report on the incident states that network security experts reviewing the data say hacker groups are currently offering partial data previews for thousands of dollars. Sample data appears to include Chinese documents marked as “confidential,” technical files, animated simulations, and renderings of defense equipment including bombs and missiles.
Dakota Cary, a consultant at the cybersecurity company SentinelOne focusing on China, expressed that the content found matches what one would expect to see in a supercomputing center. Supercomputer centers are typically used for large-scale computing tasks and the range of samples released reflects the diverse clientele of such centers. Cary notes that most customers have no reason to independently maintain supercomputing infrastructure.
Leaked data circulating online includes a report on a “Target Destruction Calculation Model and Tools Research Topic Contract Summary Report” dated December 2025. The research was conducted at the “National Supercomputing Center in Tianjin,” with the title page indicating it was produced by the Academy of Military Sciences National Defense Engineering Research Institute. The report details include ship multi-deck explosion simulations, land mobile vehicle models, concrete shelter finite element grids and professional damage calculations.
Cary, responding to CNN, indicates that data leaks exist within the Chinese network ecosystem as the leaked data is quickly purchased. He believes that several governments globally might be interested in NSCC data, with some governments possibly already having access to it.
Cybersecurity researcher and blogger Mark Hofer highlights the extensive scale of this data, which would be highly appealing to intelligence agencies of adversarial nations, stating that only these organizations would possess the capability to process such a large volume of data and extract valuable intelligence from it.
The Chinese Communist Party is currently striving to compete with the United States to become a leader in global technological innovation and artificial intelligence. However, if confirmed, this data breach incident indicates deeper systemic vulnerabilities within China’s technological infrastructure.
This is not the first time that sensitive information from Chinese institutions has been stolen by hackers. In 2021, a large database containing personal information of up to 1 billion Chinese citizens was publicly available for over a year until 2022, when hackers attempted to sell the data on underground forums, attracting widespread attention.
