Comment by msbhvn

9 days ago

Woah, read the timeline at the top of this. The fire happened the very day the government ordered onsite inspection was supposed to start due to Chinese/NK hacking.

Phrack's timeline may read like it, but it wasn't an onsite inspection due to hacking, but a scheduled maintenance to replace the overdue UPS, hence battery-touching involved. Even the image they linked just says "scheduled maintenance."

  • So right after the investigation was announced, they suddenly scheduled a UPS battery replacement which happened to start a fire big enough to destroy the entire data centre and all data or evidence?

    Yeah, that's way less suspicious, thanks for clearing that up.

    • My mind initially went to a government cover-up, but then:

      > 27th of September 2025, The fire is believed to have been caused while replacing Lithium-ion batteries. The batteries were manufactured by LG, the parent company of LG Uplus (the one that got hacked by the APT).

      Could the battery firmware have been sabotaged by the hacker to start the fire?

      8 replies →

    • UPS, check. Any kind of reasonable fire extinguisher, nah.

      A Kakao datacenter fire took the de-facto national chat app offline not too many years ago. Imagine operating a service that was nearly ubiquitous in the state of California and not being able to survive one datacenter outage.

      After reading the Phrack article, I don't know what to suspect, the typical IT disaster preparedness or the operators turning off the fire suppression main and ordering anyone in the room to evacuate to give a little UPS fire enough time to start going cabinet to cabinet.

      1 reply →

  • Supply chain interceptions can happen for batteries and other electronics being used.

Such coincidences do happen. 20 years ago the plane which was carrying all the top brass of the Russian Black Sea Fleet as well as the Fleet’s accounting documentation for inspection to Moscow burst in flames and fell to the ground while trying to get airborne. Being loaded with fuel it immediately became one large infernal fireball. By some miracle no top brass suffered even minor burn/injury while all the accounting documentation burned completely.

  • One hell of an act of God that... Believable though, given the consistent transparency and low corruption in the Russian government's administration.

  • Quite a few of those top brass years later shot themselves in the head several times before jumping from a window.

    Anyway, shoe production has never been better.

Yeah, this whole thing smells.

Who has the incentive to do this, though? China/North Korea? Or someone in South Korea trying to cover up how bad they messed up? Does adding this additional mess on top mean they looked like they messed up less? (And for that to be true, how horrifically bad does the hack have to be?)

  • It might be different “they”s. Putting on my tinfoil hat, whoever was going to be in hot water over the hack burns it down and now the blame shifts from them to whoever manages G-drive and don’t have a backup plan.

    Not saying I believe this (or even know enough to have an opinion), but it’s always important to not anthropomorphize a large organization. The government isn’t one person (even in totalitarian societies) but an organization that contains large numbers of people who may all have their own motivations.

    • If there was shady behavior, I doubt it’s about a cyber hack. More likely probably the current administration covering their tracks after their purges.

      Alternate hypothesis: cloud storage provided doing the hard sell. Hahaha :)

      1 reply →

    • > whoever was going to be in hot water over the hack burns it down and now the blame shifts from them to whoever manages G-drive and don’t have a backup plan.

      LG is SK firm and manufacturer of hacked hardware and also the batteries that caught fire. Not sure it’s a solid theory just something I took note of while thinking the same

      1 reply →

The good news is: there are still off-site backups.

The bad news is: they're in North Korea.

  • "Your Holiness! I have terrible news! Jesus has returned!"

    "But that's a blessed event? How could that be terrible?"

    "He appeared in Salt Lake City."

"NK hackers" reminds me "my homework was eaten by a dog". It's always NK hackers that steal data/crypto and there is absolutely no possibility to do something with it or restore the data, because you know they transfer the info on a hard disk and they shoot it with an AD! Like that general!

How do we know it's NK? Because there are comments in north-korean language, duh! Why are you asking, are you russian bot or smt??