Published: · Region: Southeast Asia · Category: cyber

ownCloud Flaw Used to Steal Nuclear-Material Files and Security Keys From Philippine Research Body

Attackers exploited a known ownCloud vulnerability to steal 176 sensitive files, including nuclear-material records and core IT security keys, from a Philippine nuclear research body.

Attackers have exploited a known flaw in the ownCloud file-sharing platform to steal sensitive data from a Philippine nuclear research body, exposing nuclear-related records and key elements of the institution’s IT security.

Technical reporting on the incident says the hackers took 176 files totaling about 372 megabytes of data. The stolen material reportedly includes nuclear-material records, strategic plans, employee information, BitLocker recovery keys for encrypted Windows systems, and a KeePass password database that may hold further credentials.

The entry point was CVE-2023-49105, a previously disclosed ownCloud vulnerability. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its Known Exploited Vulnerabilities catalog, a list of bugs that are confirmed to be actively used by attackers and that U.S. federal agencies are required to fix.

For the Philippine institution, the breach threatens not only the confidentiality of nuclear-related files but also the integrity of its wider networks. With BitLocker keys and a KeePass database, attackers may be able to unlock encrypted drives, impersonate staff and reuse passwords or tokens to move into other systems that were not directly connected to ownCloud.

Nuclear-material records and strategic plans can be highly sensitive even if they do not involve weapons design. They may reveal what materials are held, where they are stored, and how facilities are planned and protected. In hostile hands, such information can assist physical or cyber targeting or be used to spread doubt about nuclear safety.

Leaked employee data can also be used for spear-phishing and identity theft. Names, contact details and organizational charts can help attackers craft convincing messages that persuade staff to click links or share access, deepening the compromise.

The incident underlines how nuclear security now depends heavily on basic digital hygiene. Many research and regulatory bodies use widely available tools such as ownCloud to share files. If those systems are left unpatched or misconfigured, they can provide a relatively easy route into sensitive environments.

It also fits a broader pattern: many successful attacks on high-value targets rely on already known software bugs rather than undisclosed, highly technical vulnerabilities. Once an exploit is publicly available, any organization that has not applied security updates is exposed, regardless of how critical its mission is.

The case shows that oversight of nuclear-related activity can be weakened by the same kinds of IT flaws that have affected hospitals, local governments and schools. A single unpatched server can turn a specialist research body into an opening for further attacks.

Key developments to watch include whether Philippine authorities disclose more detail about the scope of the breach, whether outside partners offer incident-response help, and whether regulators issue new cyber requirements for nuclear-related organizations. Any sign that the stolen nuclear-material or planning data is being leaked, sold or reused in additional operations would sharply increase the impact beyond a single institution.

Sources