Shanghai data leak: China tested by possible largest hack in history

“ChinaDan,” a Chinese hacker, claims to possess the phone numbers, names, and ages of 1 billion Chinese citizens. Although the scale of the leak seems huge, experts say many online advertising companies already get the same type of data when browsing online.

|
Ng Han Guan/AP
Chinese policemen patrol the Bund area in Shanghai, June 1, 2022. Hackers claim to have obtained a trove of data on 1 billion Chinese from a Shanghai police database in a leak that, if confirmed, could be one of the largest data breaches in history.

Hackers claim to have obtained a trove of data on 1 billion Chinese from a Shanghai police database in a leak that, if confirmed, could be one of the largest data breaches in history.

In a post on the online hacking forum Breach Forums last week, someone using the handle “ChinaDan” offered to sell nearly 24 terabytes (24 TB) of data including what they claimed was information on 1 billion people and “several billion case records” for 10 Bitcoin, worth about $200,000.

The data purportedly includes information from the Shanghai National Police database including names, addresses, national identification numbers, and mobile phone numbers as well as case details.

A sample of data seen by The Associated Press listed names, birthdates, ages and mobile numbers. One person was listed as having been born in “2020,” with their age listed as “1,” suggesting that information on minors was included in the data obtained in the breach.

The Associated Press could not immediately verify the authenticity of the data samples. Shanghai police did not immediately respond to a request for comment.

The data leak initially sparked discussion on Chinese social media platforms such as Weibo, but censors have since moved to block keyword searches for “Shanghai data leak.”

One person said they were skeptical until they managed to verify some of the personal data leaked online by attempting to search for people on Alipay using their personal information.

“Everyone, please be careful in case there are more phone scams in the future!” they said in a Weibo post.

Another person commented on Weibo that the leak means everyone is “running naked” – slang used to refer to a lack of privacy – and it’s “horrifying.”

Experts said the breach, if confirmed, would be the biggest in history.

Kendra Schaefer, a partner for technology at policy research firm Trivium China, said in a tweet that it’s “hard to parse truth from the rumor mill, but can confirm file exists.”

Such data leaks are fairly common, according to Michael Gazeley, managing director at Hong Kong-based security firm Network Box.

“There are approximately 12 billion compromised accounts posted on the Dark Web right now. That’s more than the total number of people in the world,” he said, adding that a majority of data leaks often come from the United States.

Chester Wisniewski, principal research scientist at cybersecurity firm Sophos, said that the breach is “potentially incredibly embarrassing to the Chinese government,” and the political harm would probably outweigh damage to the people whose data was leaked.

Most of the data is similar to what advertising companies that run banner ads would have, he said.

“When you’re talking about a billion people’s information and it’s static information, it’s not about where they traveled, who they communicated with or what they were doing, then it becomes very much less interesting,” Mr. Wisniewski said.

Still, once hackers get data and put it online it’s impossible to fully remove.

“The information, once it’s unleashed, is forever out there,” Mr. Wisniewski said. “So if someone believes their information was part of this attack, they have to assume it’s forever available to anyone and they should be taking precautions to protect themselves.”

A major cryptocurrency exchange said it had stepped up verification procedures to guard against fraud attempts such as using personal information from the reported hack to take over people’s accounts.

Zhao Changpeng, CEO of Binance, a cryptocurrency exchange, said in a tweet Monday that its threat intelligence had detected the sale of “1 billion resident records.”

“This has impact on hacker detection/prevention measures, mobile numbers used for account take overs, etc.,” Mr. Zhao wrote in his tweets, before saying that Binance had already stepped up verification measures.

In 2020, a major cyberattack believed to be by Russian hackers compromised several U.S. federal agencies such as the State Department, the Department of Homeland Security, telecommunications firms and defense contractors.

Last year, over 533 million Facebook users had their data published in a hacking forum after hackers scraped its data due to a vulnerability that has since been patched.

The story was reported by The Associated Press. AP journalist Emily Wang in Beijing and researcher Chen Si in Shanghai contributed to this report.

You've read  of  free articles. Subscribe to continue.
Real news can be honest, hopeful, credible, constructive.
What is the Monitor difference? Tackling the tough headlines – with humanity. Listening to sources – with respect. Seeing the story that others are missing by reporting what so often gets overlooked: the values that connect us. That’s Monitor reporting – news that changes how you see the world.

Dear Reader,

About a year ago, I happened upon this statement about the Monitor in the Harvard Business Review – under the charming heading of “do things that don’t interest you”:

“Many things that end up” being meaningful, writes social scientist Joseph Grenny, “have come from conference workshops, articles, or online videos that began as a chore and ended with an insight. My work in Kenya, for example, was heavily influenced by a Christian Science Monitor article I had forced myself to read 10 years earlier. Sometimes, we call things ‘boring’ simply because they lie outside the box we are currently in.”

If you were to come up with a punchline to a joke about the Monitor, that would probably be it. We’re seen as being global, fair, insightful, and perhaps a bit too earnest. We’re the bran muffin of journalism.

But you know what? We change lives. And I’m going to argue that we change lives precisely because we force open that too-small box that most human beings think they live in.

The Monitor is a peculiar little publication that’s hard for the world to figure out. We’re run by a church, but we’re not only for church members and we’re not about converting people. We’re known as being fair even as the world becomes as polarized as at any time since the newspaper’s founding in 1908.

We have a mission beyond circulation, we want to bridge divides. We’re about kicking down the door of thought everywhere and saying, “You are bigger and more capable than you realize. And we can prove it.”

If you’re looking for bran muffin journalism, you can subscribe to the Monitor for $15. You’ll get the Monitor Weekly magazine, the Monitor Daily email, and unlimited access to CSMonitor.com.

QR Code to Shanghai data leak: China tested by possible largest hack in history
Read this article in
https://www.csmonitor.com/World/Asia-Pacific/2022/0706/Shanghai-data-leak-China-tested-by-possible-largest-hack-in-history
QR Code to Subscription page
Start your subscription today
https://www.csmonitor.com/subscribe