HomeSecurityUS nuclear weapons plant breached via SharePoint

US nuclear weapons plant hacked via SharePoint

Foreign hackers infiltrated the Kansas City National Security Center (KCNSC), a key manufacturing facility within the National Nuclear Security Administration (NNSA), by exploiting unpatched security vulnerabilities in Microsoft SharePoint, according to a source involved in responding to an incident at the facility in August.

See also: Microsoft SharePoint Server zero-day attack affects African Ministry of Finance

SharePoint breach

The breach targeted a factory that produces the vast majority of critical non-nuclear components for U.S. nuclear weapons under the NNSA, a semi-autonomous agency within the Department of Energy (DOE) that oversees the design, production, and maintenance of the country's nuclear weapons.

Honeywell Federal Manufacturing & Technologies (FM&T) operates the Kansas City center under contract to the NNSA. The Kansas City center, Honeywell FM&T, and the Department of Energy did not respond to repeated requests for comment throughout September, well before the current government shutdown. NSA public affairs officer Eddie Bennettresponded by saying, “We have nothing to contribute,” and referred the CSO back to the DOE.

While it is unclear whether the attackers were Chinese state hackers or Russian cybercriminals — the two most likely culprits — experts say the incident highlights the importance of securing systems that protect business technology from exploits that primarily affect IT systems.

Attackers exploited two recently disclosed vulnerabilities in Microsoft SharePoint — CVE-2025-53770, a spoofing vulnerability, and CVE-2025-49704, a remote code execution (RCE) vulnerability — both of which affect on-premises servers. Microsoft released patches for the vulnerabilities on July 19. On July 22, the NNSA confirmed that it was one of the organizations affected by attacks enabled by the SharePoint vulnerabilities.

See also: Hackers target SharePoint servers with Warlock ransomware

US nuclear weapons plant hacked via SharePoint

While most of the design and programming details remain classified, the factory's manufacturing role makes it one of the most sensitive facilities in the federal weapons complex. Microsoft attributed the broader wave of SharePoint exploits to three groups linked to China: Linen Typhoon, Violet Typhoon, and a third actor it tracks as Storm-2603. The company said the attackers were preparing to deploy the Warlock ransomware on the affected systems.

However, the source familiar with the Kansas City incident tells CSO that a Russian malicious actor, not a Chinese one, was responsible for the intrusion. Cybersecurity firm Resecurity, which tracked the SharePoint exploits, tells CSO that its own data pointed primarily to groups of Chinese state actors, but it does not rule out Russian involvement.

Resecurity analysts observed early-stage scanning and exploitation activity from infrastructure located in Taiwan, Vietnam, South Korea, and Hong Kong, a distribution pattern consistent with tactics used by Chinese advanced persistent threat (APT) groups to disguise performance.

OT cybersecurity experts interviewed by CSO say that KCNSC's production systems are likely isolated or otherwise isolated from corporate IT networks, significantly reducing the risk of direct cross-contamination.

See also: US National Nuclear Security Administration hacked via SharePoint

US nuclear weapons plant hacked via SharePoint

Whether the attackers were Chinese state actors or Russian cybercriminals, the Kansas City breach exposes the fragile intersection of IT security and operations in critical defense infrastructure. As Claroty’s Jen Sovada emphasizes, “We can no longer think of zero-trust as an IT concept. It must extend to the physical systems that support national defense.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS