Cybercriminals exploited long-known vulnerabilities in ownCloud and WordPress to breach the Philippines' nuclear agency, stealing reactor databases and sensitive personnel records.
- Attackers utilized unpatched flaws in ownCloud and LiteSpeed Cache to infiltrate sensitive networks.
- Stolen data includes reactor core-component databases, fuel inventories, and radiation safety manuals.
- Evidence suggests a Chinese-speaking threat actor due to coding comments found on the staging server.
A major cybersecurity breach has compromised the Philippines Nuclear Agency and a key naval contractor, exposing highly sensitive technical and personal data. Researchers from the threat hunting platform Hunt.io revealed that attackers exploited commodity vulnerabilities that had been patched for years, highlighting a massive failure in digital hygiene among critical infrastructure providers.
The breach was traced back to an ownCloud server hosted in Amsterdam, which served as a central hub for the attackers. From this server, approximately 1.2 GB of data was identified, including files belonging to a marine engineering firm serving the Philippine Navy. More alarmingly, the exfiltrated data appears to include a massive 9 GB of information, including reactor-related technical blueprints and personnel files containing passports and financial disclosures.
Why This Matters
BozokMedia analysis shows that this incident is not merely a localized data theft but a significant geopolitical event. As tensions escalate in the South China Sea, cyber espionage has become a primary tool for regional influence. The fact that the breach targeted both nuclear assets and naval contractors suggests a coordinated effort to gather intelligence on Philippine defense and energy capabilities.
The exploitation of two-year-old bugs proves that even the most sophisticated targets are vulnerable to the most basic security lapses.
While the attackers did not appear to deploy tools for immediate destruction or disruption, the nature of the stolen data—specifically reactor core-component databases and fuel inventories—provides a technical roadmap that could be used for much more damaging operations in the future.
Historical Background
The vulnerabilities exploited, such as CVE-2023-49105 in ownCloud, were disclosed in late 2023. Despite the availability of patches, many organizations continue to run outdated software, leaving a 'window of opportunity' for threat actors. This pattern of exploiting 'old flaws' is a rising trend in state-sponsored cyber espionage.
| Vulnerability ID | Affected Software | Disclosed Date |
|---|---|---|
| CVE-2023-49105 | ownCloud | November 2023 |
| CVE-2024-2800 | LiteSpeed Cache (WordPress) | August 2024 |
Frequently Asked Questions
1. Was the nuclear reactor's physical safety compromised?
No. Reports indicate the attackers focused on data collection rather than disrupting the systems that run the reactor itself.
2. Who is suspected of the attack?
While no official attribution was made, coding comments in Chinese suggest a Chinese-speaking threat actor.