10PiB breach in China

From CNN:

A [cyberthreat actor] has allegedly stolen a massive trove of sensitive data – including highly classified defense documents and missile schematics – from a state-run Chinese supercomputer in what could potentially constitute the largest known heist of data from China.

The dataset, which allegedly contains more than 10 petabytes of sensitive information, is believed by experts to have been obtained from the National Supercomputing Center (NSCC) in Tianjin – a centralized hub that provides infrastructure services for more than 6,000 clients across China, including advanced science and defense agencies.

Apparently data extraction took ~6 months. 10PiB of data. This is some serious stuff. Thoughts?

2 Likes

Sheer scale of the data exfiltrated makes me very doubtful.

2 Likes

Yeah. CNN claims that “experts” looked at the data and confirmed it seems plausible, but how do you even assess 10PiB of data based on some samples.

“Yep, those are Chinese characters. Checks out.”

2 Likes

Here is the Telegram channel in question. View at your own risk: FlamingChina – Telegram

What’s been shared is mostly images. The sample leak has been pulled from Mega.

2011 Mandiant, is that you?

This was my line of thinking.

Even a random sample seems implausible. Batch processing via LLM? But how would it know what is legit?

So this is a useful case study in bad journalism, and also a point I’m working through for IFIN. Here we have a single anonymous source making an unverifiable claim. Using the Admiralty Code, we would classify this as F4 or F5.

And broadly, this is how we should handle those ratings.

2 Likes