ua en ru

US nuclear agency targeted in cyberattack

US nuclear agency targeted in cyberattack Illustrative photo: cyberattack (Getty Images)
Author: Oleh Velhan

The United States National Nuclear Security Administration fell victim to a cyberattack due to a vulnerability in Microsoft SharePoint. According to Microsoft, the breach was carried out by hackers linked to the Chinese government, according to Bloomberg.

It has been revealed that hackers attacked the United States National Nuclear Security Administration (NNSA). As a result of a large-scale cyberattack exploiting a vulnerability in Microsoft SharePoint software, the agency responsible for designing, maintaining, and transporting the U.S. nuclear arsenal was breached.

Although no highly sensitive information was compromised, the very fact of the intrusion has raised concerns within the US national security community.

According to a spokesperson for the US Department of Energy, exploitation of the SharePoint vulnerability began on July 18. Nevertheless, the impact on the department's infrastructure was limited due to a broad transition to Microsoft 365 cloud services and a strengthened cybersecurity framework.

"A very small number of systems were impacted. All impacted systems are being restored," the department representative noted.

Who may be behind attack

According to Microsoft, the attack was carried out by China-linked hacker groups, including Linen Typhoon, Violet Typhoon, and Storm-2603. These groups exploited SharePoint vulnerabilities as part of a global cyberespionage campaign that targeted:

  • Government agencies in Europe and the Middle East,

  • The US Department of Education,

  • The Florida Department of Revenue,

  • The Rhode Island General Assembly,

  • As well as other organizations worldwide.

In several cases, hackers gained access to login credentials, including usernames, passwords, hash codes, and authentication tokens.

About NNSA

The US National Nuclear Security Administration (NNSA) is a semi-autonomous agency within the Department of Energy that:

  • Provides nuclear reactors for the US Navy’s submarine fleet,

  • Oversees the assembly, maintenance, and dismantling of nuclear weapons,

  • Carries out tasks related to nuclear deterrence, munitions transportation, and nuclear counterterrorism.

This is not the first time NNSA systems have been breached. In 2020, the agency fell victim to a cyberattack during the SolarWinds software breach, which also affected only the business network and did not compromise classified data.

The full scope of the 2025 cyberattack is still being assessed. However, cybersecurity experts are calling for the immediate modernization of protective measures across government systems, especially amid increasing cyber activity by hostile states.

On July 18, the United Kingdom imposed sanctions on more than 20 individuals, including Russian intelligence officers, hackers, and several organizations, accusing them of conducting a systematic cyber campaign aimed at destabilizing Europe and Africa.