Hacker NewsInternational NewsNews

FlamingChina’s Tianjin Supercomputer Samples Are Still Being Sold While Beijing Has Not Confirmed the Theft

The Hacker Gets Hacked: China’s Secrets Unearthed, One Leak at a Time

The first receipt was not a Chinese ministry statement. It was a price list. On February 6, 2026, a Telegram account calling itself FlamingChina posted sample files and a claim that reads like a boast until the samples are opened: the operator had lived inside the National Supercomputing Center in Tianjin for about six months, pulled more than 10 petabytes, and would sell a preview for thousands of dollars or the stack for far more, payable in cryptocurrency. Around February 4 a BreachForums listing under the handle airborneshark1 carried the same pitch. Forum names change. The files in the sample folder are the only object anyone outside the building can test.

Ten petabytes is not a stolen inbox. A high-end laptop holds about a terabyte. Ten petabytes is on the order of ten thousand of those drives. If even a slice is real defense work, the damage is not the invoice. The damage is a map of who computes what on a shared national machine, and which login surface stayed open long enough for a patient thief to walk it. CNN could not verify that the full dataset came from Tianjin. Specialists who looked at the first samples told the network they looked genuine. That gap, experts saying the files match a tenant list, a state saying nothing, is still the public record. The early GhostStory label on this address was a sticker. The persona selling the data was FlamingChina. The AEGIS Alliance treats marketing names as stickers. Hashes and directories are the product.

A machine that rents cycles to everybody

NSCC-Tianjin is not a vault with one customer. It sells time. Research institutes, companies, and government shops rent cycles on a campus that became famous when Tianhe-1 sat at the top of the TOP500 list in 2010. Descriptions of the modern center put the client count in the thousands, with CNN’s reporting using a figure near 6,000. A mixed tenant list is why one intrusion can spit aircraft skins, fusion models, and biology papers out of the same tree. Dakota Cary, a SentinelOne consultant who focuses on China, told CNN the sample swath was “exactly what I would expect to see from the supercomputing center.” Most of those customers, he said, would have little reason to keep a machine of their own.

April reporting named organizations that showed up in the samples: the Aviation Industry Corporation of China, the Commercial Aircraft Corporation of China, the National University of Defense Technology, and Northwestern Polytechnical University. Some documents carried Chinese markings consistent with a secret classification, including files described as classified for ten years. Other files were technical renderings and animated simulations of bombs and missiles. Marc Hofer, who writes the NetAskari blog and said he spoke with the persona, described one sample as a damage study aimed at armored targets that included a HIMARS rocket system, a carrier, and hardened concrete. TechRadar and Security Affairs repeated the aerospace and weapons descriptions. None of them could put a government confirmation under the headline.

Cary did not describe an elegant zero-day ballet. He described a hole. In his read, and in the account Hofer said he heard, the operator used a compromised VPN domain, then a botnet that pulled data out to different servers over months in pieces small enough to look like ordinary scientific traffic. “You can think of it as having a bunch of different servers that you have access to and you’re pulling data through this hole in the security of the NSCC,” Cary said. If that account is true, the method is not genius. It is patience plus a shared login nobody watched. Jeff Wichman, an incident-response director at Semperis, called a military-secret theft on this scale shocking. Unimaginable is a press word. Unmonitored is the operational one.

The samples did not die with the first sales post

A 10-petabyte pile is not something a forum buyer parks on a consumer drive and decodes over a weekend. Hofer told CNN that only a state or a well-funded lab could work through it and come back with something useful. Criminal markets still matter at the edges, because a verified sliver of AVIC or COMAC design data is a gift to a rival aerospace program, and a verified sliver of National University of Defense Technology work is a gift to anyone mapping weapons research. The realistic buyers are governments, contractors, and a few brokers who already have cold storage and people who read Chinese technical documents. Intelligence services that already collect on Tianjin tenants do not need a shopping cart. The cart is for everyone else, and for the proof that the files are real enough to price.

The cart did not close in February. On September 14, 2026, threat-intelligence account S2W flagged a DarkForums listing by a persona calling itself The_BlackH4t, offering what it described as classified Chinese military and supercomputing data tied to NSCC-Tianjin plus AVIC, COMAC, NUDT, NWPU, and Huazhong University of Science and Technology. The pitch added employee identification scans and claimed sample directories were already circulating. That listing is not an independent forensic report, and it is not proof the new alias is FlamingChina. It is evidence that Tianjin-linked directories were still being sold as a product months after the first Telegram post, while Beijing had still not published an incident timeline. The Cyber Security Incident Database still carried the original event as unresolved. Silence from the Ministry of Science and Technology and the Cyberspace Administration of China, both of which CNN asked for comment in April, filled nothing. A sales pitch filled it first.

Shared compute is shared risk

A national supercomputing center is a hotel with a science budget. Tenants come and go. Accounts linger. VPN certificates get reused. Research groups share scratch disks because the alternative is a queue. Defense contractors sit two racks away from a university fusion team because the machine does not care who paid for the cycle. That architecture is efficient. It is also one compromised domain away from a catalog of other people’s secrets. Cary told CNN that weak cybersecurity has been a long-running condition across a wide set of Chinese industries. China’s own 2025 national security language listed stronger barriers for networks, data, and artificial intelligence as a priority. Listing a priority is not the same as closing a VPN hole.

Skepticism belongs in the file, not outside it. Some security writers, including coverage at PC Gamer, noted that researchers were not ready to bless a 10-petabyte claim on the strength of a Telegram channel. They are right that a sales channel is not a chain of custody. They are not a reason to ignore samples that specialists recognized as the kind of work Tianjin tenants actually run. The honest status is alleged, partially inspected, unconfirmed by the victim, and still on the market. A story that stops at “unverified” and a story that stops at “the biggest hack ever” are both lazy. The middle is a center that sells cycles to thousands of clients, a persona that priced the warehouse, and a government that has preferred quiet.

Related files in this archive sit on the hacker news desk, including the U.S. Treasury breach attributed to Chinese operators, the sanctions that followed, and the Google takedown of a phone-traffic shadow network. The international desk is the wider frame. The pattern on this page is older than any alias. Shared compute is shared risk. A VPN domain is a front door. Six months of quiet exfiltration is a failure of watching. National laboratories that rent cycles cannot pretend they are closed shops. The tenants who parked classified jobs on that floor already know what the bill looks like if the samples hold.

Jeffrey Childers
Journalist, editor, cybersecurity and computer science expert, social media management, roofing contractor.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button