Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
state-sponsored-espionageunderground-data-leakremote-access-implantdata-exfiltration-method

Alleged Leak of Chinese Military-Linked Data and Knownsec Cyber Operations Documents

Updated 3mo agoFirst seen Mar 19, 20269 sources

A broad exposure of Chinese state-linked sensitive data resurfaced across underground and open reporting, combining claims of a massive leak from the National Super Computer Center in Tianjin with renewed circulation of previously stolen Knownsec corporate documents. One report described a threat actor using the name airborneshark1 and the alias Flaming China to advertise an alleged 10 PB dataset purportedly taken from the NSCC, a government-owned high-performance computing environment used by academic institutions, state-owned enterprises, and military-affiliated research partners. The available sample data was assessed by the source as likely genuine, although the full scale of the claimed exfiltration remains unverified and may imply prolonged access or insider assistance if authentic.

Separately, a partial re-release of the Knownsec leak revived reporting on more than 12,000 classified documents allegedly exposing the internal capabilities of a major Chinese cybersecurity firm tied to government and military work. The leaked material reportedly included multi-platform RATs, Android malware targeting chat data, hardware-based collection tools such as a malicious power bank, and spreadsheets identifying overseas targets in more than 20 countries, alongside evidence of large-scale data theft from India, South Korea, and Taiwan. The Kazakhstan Daryn Online and Tanzania BRELA breach reports describe unrelated criminal data-sale listings and do not match the China-focused state-linked leak activity covered in the relevant reporting.

Share:
Alleged Leak of Chinese Military-Linked Data and Knownsec Cyber Operations Documents
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Mar 25, 20263mo ago

Alleged NSCC thief claims six-month botnet exfiltration operation

In a March 25, 2026 update, a Telegram user calling themselves 'Flaming China' allegedly claimed responsibility for the NSCC Tianjin intrusion, saying initial access came via a compromised VPN domain controller and that roughly 10 petabytes were exfiltrated over six months using a botnet for transfer and distributed storage. The report said the dataset had not yet been sold and was still under negotiation, though the claims remained unverified.

NSCC hack : UPDATE ! - NetAskari
Mar 19, 20263mo ago

NSCC Tianjin sale post is re-listed to attract more interest

The sale post for the alleged NSCC Tianjin dataset was later re-listed in an apparent effort to increase buyer interest. Reporting noted that if the full claimed volume is genuine, the theft likely required prolonged access, lateral movement, and possibly insider help.

Alleged 10-petabyte NSCC Tianjin dataset advertised for sale

A dark web actor using the handle airborneshark1 advertised an alleged 10-petabyte dataset purportedly stolen from the National Super Computer Center of China in Tianjin. Sample data reportedly included internal directory screenshots, credentials, technical reports, radar-related data, and 2024-2025 weapons-effects modeling documents.

Mar 18, 20263mo ago

Partial Knownsec leak resurfaces on dark web

On March 18, 2026, a threat actor using the name Blastoize posted a free partial download of Knownsec documents. The material appeared to be a redistribution of the original November 2025 leak rather than a new breach.

Feb 1, 20265mo ago

Flaming China Telegram presence appears in early February

A group or alias calling itself Flaming China appears to have established a Telegram presence in early February 2026. Later sale posts attributed the alleged NSCC Tianjin data theft to this name.

Nov 1, 20258mo ago

Chinese government denies knowledge of Knownsec breach

Following reporting on the Knownsec leak, the Chinese government publicly denied knowledge of any breach and reiterated its opposition to cyberattacks. The statement was part of the official response to allegations tied to the leaked files.

Resecurity assesses Knownsec leak was likely caused by an insider

After the Knownsec leak emerged, Resecurity assessed that the exposure was likely the result of insider activity rather than an external intrusion. This attribution shaped understanding of how the data was obtained.

Knownsec breach first exposed with 12,000+ leaked files

In November 2025, the original Knownsec breach was first exposed, reportedly involving more than 12,000 classified files from the Chinese cybersecurity company. The leak was described as revealing offensive malware, hardware attack tools, surveillance target lists, and records of large-scale data theft.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Threat actors
2 linked
Organizations
4 linked
LG U PlusKnownsecResecurityGopher Security
SOURCE COVERAGE

Sources

9 references tracked. Mallory keeps watching after this page renders.

9 SOURCESView all
ScworldNews
Apr 10, 2026

China supercomputer breach: 10 petabytes of military data allegedly stolen by ‘FlamingChina’ | brief | SC Media

scworld.com

Open source
Toms HardwareNews
Apr 9, 2026

10 petabytes of sensitive data stolen from China's National Supercomputing Center, hackers claim - daring heist would be largest ever China hack, covering 6,000 clients across science, defense, and beyond | Tom's Hardware

tomshardware.com

Open source
Security AffairsNews
Apr 9, 2026

The alleged breach of China’s National Supercomputing Center can have serious geopolitical consequences

securityaffairs.com

Open source
Cyber Security NewsNews
Apr 9, 2026

Hackers Claim to Have Stolen 10 Petabytes of Data from China's Tianjin Supercomputer Center

cybersecuritynews.com

Open source
Data Breaches NetNews
Apr 9, 2026

A hacker has allegedly breached one of China’s supercomputers and is attempting to sell a trove of stolen data - DataBreaches.Net

databreaches.net

Open source
CnnNews
Apr 8, 2026

A hacker has allegedly breached one of China’s supercomputers and is attempting to sell a trove of stolen data | CNN

edition.cnn.com

Open source
Netaskari SubstackNews
Mar 25, 2026

NSCC hack : UPDATE ! - NetAskari

netaskari.substack.com

Open source
Netaskari SubstackNews
Mar 19, 2026

China's massive data leak of military secrets ?

netaskari.substack.com

Open source
DarkwebinformerNews
Mar 18, 2026

Partial Leak of Knownsec Corporate Documents Resurfaces With Espionage Tradecraft, Offensive Cyber Tools, and Global Targeting Evidence

darkwebinformer.com

Open source
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.