News: 1657001058

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Billion-record stolen Chinese database for sale on breach forum

(2022/07/05)


A threat actor has taken to a forum for news and discussion of data breaches with an offer to sell what they assert is a database containing records of over a billion Chinese civilians – allegedly stolen from the Shanghai Police.

Over the weekend, reports started to surface of [1]a post to a forum at Breached.to. The post makes the following claim:

In 2022, the Shanghai National Police (SHGA) database was leaked. This database contains many TB of data and information on Billions of Chinese citizens.

HackerDan offered to sell the lot for 10 Bitcoin – about $200,000. We've saved HackerDan's post [2]as a PDF in case it vanishes.

HackerDan released sample datasets: one containing delivery addresses and often instructions for drivers; another with police records; and the last with personal identification information like name, national ID number address, height, and gender.

China has a national police force, and that presumably has a Shanghai office. But an entity called the "Shanghai National Police" is hard to find.

[3]

Media outlets were nonetheless able to verify that the contents of the sample - whatever the source - describe actual people.

Gigantic civilian data leak if confirmed: A hacker is selling an alleged Shanghai police data leak containing 1 billion Chinese nationals' names, home addresses, ID #, phone #, criminal records, etc. Hacker says it's from an Aliyun (Alibaba) private cloud server. [4]pic.twitter.com/IRPG35SWYI — Zeyi Yang (@ZeyiYang) [5]July 3, 2022

"Five people confirmed all of the data, including case details that would be difficult to obtain from any source other than the police. Four more people confirmed basic information such as their names before hanging up," [6]reported the Wall Street Journal .

The WSJ 's reporter Karen Hao described the experience on Twitter:

I was truly stunned when the first person picked up—I really believed the whole thing to be fake. By the third, I was shaking—both from the nerves of trying to explain why I had their extremely private information and the weight of realizing what this leak could mean for so many. — Karen Hao 郝珂灵 (@_KarenHao) [7]July 4, 2022

[8]China orders annual security reviews for all critical information infrastructure operators

[9]Millions of people's info stolen from MGM Resorts dumped on Telegram for free

[10]China puts continuous consent at the center of data protection law

[11]China finds and kills 42,000 counterfeit apps – many of them investment scams

While the Shanghai government and police department have largely been silent over the leak, social media platforms Weibo and WeChat were not – at least until Sunday afternoon when users on Weibo began [12]experiencing data leak-related blocked hashtags.

On Monday, an unusual voice joined in the analysis of the event: Changpeng Zhao, the CEO of cryptocurrency exchange Binance.

[13]

[14]

"CZ" – as he's known – took to Twitter with the following:

Our threat intelligence detected 1 billion resident records for sell in the dark web, including name, address, national id, mobile, police and medical records from one asian country. Likely due to a bug in an Elastic Search deployment by a gov agency. This has impact on ... — CZ 🔶 Binance (@cz_binance) [15]July 3, 2022

CZ's post came four days after HackerDan's so, while some facts matched, it was unclear if the CEO was referring to a different event.

He later [16]tweeted again, this time alleging "this exploit happened because the gov developer wrote a tech blog on CSDN and accidentally included the credentials."

Whatever the source of the leak, it will mightily annoy China. The nation's government has recently prioritized [17]personal data protection and [18]critical infrastructure security . If the People's Police have mucked up on both counts, that will not go down well. ®

Get our [19]Tech Resources



[1] https://breached.to/Thread-Selling-2022-SHGA-Shanghai-Gov-National-Police-database

[2] https://regmedia.co.uk/2022/07/05/hackerdan_forum_post.pdf

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YsQLwTnpU0IcR7QRJ2x56AAAAAw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://t.co/IRPG35SWYI

[5] https://twitter.com/ZeyiYang/status/1543409345815355399?ref_src=twsrc%5Etfw

[6] https://www.wsj.com/articles/vast-cache-of-chinese-police-files-offered-for-sale-in-alleged-hack-11656940488

[7] https://twitter.com/_KarenHao/status/1543956094896132096?ref_src=twsrc%5Etfw

[8] https://www.theregister.com/2021/08/18/china_critical_information_infrastructure_rules/

[9] https://www.theregister.com/2022/05/25/mgm_customers_data_dumped_again/

[10] https://www.theregister.com/2021/08/23/china_new_personal_data_protection_law/

[11] https://www.theregister.com/2022/07/04/beijing_cracks_down_on_investment/

[12] https://www.reuters.com/world/china/hacker-claims-have-stolen-1-bln-records-chinese-citizens-police-2022-07-04/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YsQLwTnpU0IcR7QRJ2x56AAAAAw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YsQLwTnpU0IcR7QRJ2x56AAAAAw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://twitter.com/cz_binance/status/1543700689611792386?ref_src=twsrc%5Etfw

[16] https://twitter.com/cz_binance/status/1543700689611792386

[17] https://www.theregister.com/2021/08/23/china_new_personal_data_protection_law/

[18] https://www.theregister.com/2021/08/18/china_critical_information_infrastructure_rules

[19] https://whitepapers.theregister.com/



Ooops

Anonymous Coward

Couldn't have happened to a nicer bunch of oppressive dictators!!

Meanwhile in the UK

Anonymous Coward

all you would need to do is make a Donation to the current Party of Government to get hold of that sort of data.

Re: Meanwhile in the UK

Dan 55

Don't mention Palantir. I mentioned it once but I think I got away with it.

Dinanziame

With no end in sight of this type of leaks, we can hardly expect our privacy to ever be safe... Then again, privacy has never been safe from people deliberately targeting you.

What could possibly go wong?

Anonymous Coward

This is wan ton disrespect by some dim son!

So that's about $10?

sarusa

Chinese lives are worth nothing according to the CCP. Like everyone inside or outside of Putin's Russia, anyone who's not a stupid uneducated white piece of crap for American republicans, anyone who likes foliage for Brazil's Bolsinaro, etc. etc. China's citizens are just fodder for the meat grinder for panda boy.

There's little anyone could to do a Chinese mainland citizen that's worse that what their dictatorship is already doing to them.

Re: So that's about $10?

lglethal

Oh there are always things that can be done to make people's lives worse than what they currently are.

The truth is that the vast majority of Chinese in the middle classes dont find themselves on the radar of the CCP, and so live relatively comfortably. With the data in these breaches though (if it's as bad as people seem to be saying), it would be child's play for someone to falsely obtain loans leaving the real people being chased by not very nice people wanting repayments for the debt and you better believe there wont be any support from the CCP there. Alternatively, people can start agitating against the CCP using fake names and identities and leave the real people behind those identities in a whole other world of pain.

There's lots that can be done to ruin a person's day...

tapemonkey

The ultimate chinese take away.

sanmigueelbeer

this exploit happened because the gov developer wrote a tech blog on CSDN and accidentally included the credentials

Wait, if someone gave you the keys to the house and entered, why would the action be called a "breach"?

Doing gets it done.