A broad exposure of Chinese state-linked sensitive data resurfaced across underground and open reporting, combining claims of a massive leak from the National Super Computer Center in Tianjin with renewed circulation of previously stolen Knownsec corporate documents. One report described a threat actor using the name airborneshark1 and the alias Flaming China to advertise an alleged 10 PB dataset purportedly taken from the NSCC, a government-owned high-performance computing environment used by academic institutions, state-owned enterprises, and military-affiliated research partners. The available sample data was assessed by the source as likely genuine, although the full scale of the claimed exfiltration remains unverified and may imply prolonged access or insider assistance if authentic.
Separately, a partial re-release of the Knownsec leak revived reporting on more than 12,000 classified documents allegedly exposing the internal capabilities of a major Chinese cybersecurity firm tied to government and military work. The leaked material reportedly included multi-platform RATs, Android malware targeting chat data, hardware-based collection tools such as a malicious power bank, and spreadsheets identifying overseas targets in more than 20 countries, alongside evidence of large-scale data theft from India, South Korea, and Taiwan. The Kazakhstan Daryn Online and Tanzania BRELA breach reports describe unrelated criminal data-sale listings and do not match the China-focused state-linked leak activity covered in the relevant reporting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
In a March 25, 2026 update, a Telegram user calling themselves 'Flaming China' allegedly claimed responsibility for the NSCC Tianjin intrusion, saying initial access came via a compromised VPN domain controller and that roughly 10 petabytes were exfiltrated over six months using a botnet for transfer and distributed storage. The report said the dataset had not yet been sold and was still under negotiation, though the claims remained unverified.
The sale post for the alleged NSCC Tianjin dataset was later re-listed in an apparent effort to increase buyer interest. Reporting noted that if the full claimed volume is genuine, the theft likely required prolonged access, lateral movement, and possibly insider help.
A dark web actor using the handle airborneshark1 advertised an alleged 10-petabyte dataset purportedly stolen from the National Super Computer Center of China in Tianjin. Sample data reportedly included internal directory screenshots, credentials, technical reports, radar-related data, and 2024-2025 weapons-effects modeling documents.
On March 18, 2026, a threat actor using the name Blastoize posted a free partial download of Knownsec documents. The material appeared to be a redistribution of the original November 2025 leak rather than a new breach.
A group or alias calling itself Flaming China appears to have established a Telegram presence in early February 2026. Later sale posts attributed the alleged NSCC Tianjin data theft to this name.
Following reporting on the Knownsec leak, the Chinese government publicly denied knowledge of any breach and reiterated its opposition to cyberattacks. The statement was part of the official response to allegations tied to the leaked files.
After the Knownsec leak emerged, Resecurity assessed that the exposure was likely the result of insider activity rather than an external intrusion. This attribution shaped understanding of how the data was obtained.
In November 2025, the original Knownsec breach was first exposed, reportedly involving more than 12,000 classified files from the Chinese cybersecurity company. The leak was described as revealing offensive malware, hardware attack tools, surveillance target lists, and records of large-scale data theft.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetomshardware.com
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcedatabreaches.net
Open sourceedition.cnn.com
Open sourcenetaskari.substack.com
Open sourcenetaskari.substack.com
Open sourcedarkwebinformer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.