A hacker has claimed to have procured a trove of personal information from the Shanghai police on one billion Chinese citizens, which tech experts say, if true, would be one of the biggest data breaches in history
The anonymous internet user, identified as "ChinaDan", posted on hacker forum Breach Forums last week offering to sell the more than 23 terabytes (TB) of data for 10 bitcoin, equivalent to about $200,000.
"In 2022, the Shanghai National Police (SHGA) database was leaked. This database contains many TB of data and information on Billions of Chinese citizen," the post said.
"Databases contain information on 1 Billion Chinese national residents and several billion case records, including: name, address, birthplace, national ID number, mobile number, all crime/case details."
Reuters was unable to verify the authenticity of the post.
The Shanghai government and police department did not respond to requests for comment on Monday.
Reuters was also unable to reach the self-proclaimed hacker, “China Dan”, but the post was widely discussed on China’s Weibo and WeChat social media platforms over the weekend, with many users worried it could be real.
The hashtag "data leak" was blocked on Weibo by Sunday afternoon.
Kendra Schaefer, head of tech policy research at Beijing-based consultancy Trivium China, said in a post on Twitter, it was "hard to parse truth from rumor mill".
If the material the hacker claimed to have come from the Ministry of Public Security, it would be bad for "a number of reasons", Schaefer said.
"Most obviously, it would be among the biggest and worst breaches in history," she said.
Zhao Changpeng, CEO of Binance, said on Monday the cryptocurrency exchange had stepped up user verification processes after the exchange's threat intelligence detected the sale of records belonging to 1 billion residents of an Asian country on the dark web.
He said on Twitter that a leak could have happened due to "a bug in an Elastic Search deployment by a (government) agency", without saying if he was referring to the Shanghai police case. He did not immediately respond to a request for further comment.
The claim of a hack comes as China has vowed to improve protection of online user data privacy, instructing its tech giants to ensure safer storage after public complaints about mismanagement and misuse.
Last year, China passed new laws governing how personal information and data generated within its borders should be handled.
“References are being received from security agencies of Government of India regarding targeted attacks on the compromised computers in various CPWD offices for collection of sensitive information. Frequency of such references has increased in past few months,” the CPWD said in an office memorandum issued on July 8.
It added that the references from security agencies sent to the regional heads of CPWD for analysing the root cause and sanitisation of devices. Reports sought on compliance. However, the CPWD said action with regard to the references is not being taken in a timely manner and the reports are getting “delayed abnormally”. The office memorandum informed employees that the CPWD “can’t question the findings of security agencies who are tracking such incidents”.
Reiterating earlier guidelines, including one issued on May 13, the CPWD asked employees to follow the cyber security measures. “Any consequences arising out of such delay shall be the responsibility of concerned official (sic),” the office memo stated.
A CPWD official told The Hindu that one or two such instances are being observed every month from various offices. The official said the CPWD has about 2,000 offices across the country and employees are being reminded to follow the cybersecurity rules. The official further said CERT-In (Indian Computer Emergency Response Team) is tracking the attacks. Aq
You must be logged in to post a comment.