# Cyber Attack Exposes Vulnerabilities in Philippine Nuclear Agency

*Published September 4, 2026*
*Source: [https://www.darkreading.com/cyberattacks-data-breaches/old-unpatched-flaws-attackers-philippines-nuclear-agency](https://www.darkreading.com/cyberattacks-data-breaches/old-unpatched-flaws-attackers-philippines-nuclear-agency)*

## Executive Summary

A cyber attack on the Philippine nuclear agency exploited unpatched systems, allowing attackers to access sensitive data. The breach highlights the importance of maintaining updated security measures to protect critical infrastructure.

## Article

A recent cyber attack revealed significant vulnerabilities in the Philippine nuclear agency's systems. The breach occurred due to unpatched servers, allowing attackers to access sensitive information regarding nuclear material processes, IT planning, and personnel data. This attack also impacted a naval contractor associated with the Philippine Navy. Hunt.io, a threat hunting firm, discovered that the attackers exploited an ownCloud server in Amsterdam, which served as a hub for offensive tools and stolen data. The server contained over 1,300 files, including data from the nuclear agency and a marine engineering company. Although the identity of the attackers remains uncertain, indicators suggest a Chinese-speaking threat actor. However, no definitive evidence links the attack to a specific nation-state. The attackers leveraged vulnerabilities that had been disclosed and patched over two years ago, highlighting the critical need for organizations to maintain up-to-date security measures. Specifically, the vulnerabilities were related to the ownCloud platform and the LiteSpeed Cache WordPress plug-in. Despite these patches being available, the flaws remained exploitable on systems that should have been more securely managed given their sensitivity. The broader impact of the breach is suggested by a document indicating that up to 9GB of data might have been exfiltrated, although only 372MB of victim data was directly found. The attack underscores the necessity for robust cybersecurity practices, particularly in politically sensitive regions like the South China Sea. Organizations are urged to strengthen their defenses by patching known vulnerabilities, configuring systems with secure defaults, and implementing multifactor authentication to protect sensitive data and infrastructure.
