Zürcher Nachrichten - Hacker claims major Chinese citizens' data theft

EUR -
AED 3.827198
AFN 81.799111
ALL 98.987373
AMD 414.987417
ANG 1.87911
AOA 952.88586
ARS 1095.408841
AUD 1.672688
AWG 1.875557
AZN 1.750679
BAM 1.960506
BBD 2.105243
BDT 126.684073
BGN 1.953855
BHD 0.392729
BIF 3045.695858
BMD 1.041976
BND 1.408674
BOB 7.204396
BRL 6.120672
BSD 1.042698
BTN 90.283403
BWP 14.511832
BYN 3.412174
BYR 20422.729665
BZD 2.094397
CAD 1.503014
CDF 2964.421402
CHF 0.944758
CLF 0.037453
CLP 1033.436453
CNY 7.555732
CNH 7.571586
COP 4346.08191
CRC 528.962027
CUC 1.041976
CUP 27.612364
CVE 110.757331
CZK 25.121014
DJF 185.179535
DKK 7.462661
DOP 64.342121
DZD 140.666716
EGP 52.324594
ERN 15.62964
ETB 131.181328
FJD 2.428585
FKP 0.858158
GBP 0.83752
GEL 3.001184
GGP 0.858158
GHS 15.939164
GIP 0.858158
GMD 75.022482
GNF 9018.302432
GTQ 8.065359
GYD 218.143599
HKD 8.118462
HNL 26.676221
HRK 7.689312
HTG 136.276444
HUF 407.964737
IDR 16903.351516
ILS 3.763263
IMP 0.858158
INR 90.278416
IQD 1364.988564
IRR 43854.168916
ISK 145.720135
JEP 0.858158
JMD 164.07224
JOD 0.73918
JPY 161.634473
KES 134.938289
KGS 91.120975
KHR 4189.785236
KMF 492.134633
KPW 937.778519
KRW 1503.57145
KWD 0.321324
KYD 0.868886
KZT 539.41697
LAK 22678.607676
LBP 93308.950828
LKR 309.142018
LRD 204.751183
LSL 19.328724
LTL 3.076684
LVL 0.630281
LYD 5.116525
MAD 10.415072
MDL 19.419612
MGA 4892.07759
MKD 61.497581
MMK 3384.297414
MNT 3540.634571
MOP 8.367965
MRU 41.522876
MUR 48.32672
MVR 16.048954
MWK 1808.349662
MXN 21.380676
MYR 4.574446
MZN 66.580798
NAD 19.328396
NGN 1618.439132
NIO 38.293024
NOK 11.771542
NPR 144.455035
NZD 1.842835
OMR 0.401157
PAB 1.042718
PEN 3.884227
PGK 4.170986
PHP 60.89255
PKR 290.555226
PLN 4.203425
PYG 8239.698261
QAR 3.794095
RON 4.975017
RSD 117.130593
RUB 103.379449
RWF 1451.993561
SAR 3.908109
SBD 8.793673
SCR 14.901732
SDG 626.227061
SEK 11.460741
SGD 1.406626
SHP 0.858158
SLE 23.835169
SLL 21849.715718
SOS 595.486325
SRD 36.578588
STD 21566.799527
SVC 9.122897
SYP 13547.771979
SZL 19.328518
THB 35.234935
TJS 11.364879
TMT 3.646916
TND 3.329154
TOP 2.44041
TRY 37.287732
TTD 7.054832
TWD 34.242467
TZS 2647.482803
UAH 43.703079
UGX 3847.234326
USD 1.041976
UYU 45.328364
UZS 13530.058219
VES 59.634986
VND 26132.758163
VUV 123.705483
WST 2.918394
XAF 657.532086
XAG 0.033941
XAU 0.000379
XCD 2.815992
XDR 0.797009
XOF 654.360408
XPF 119.331742
YER 259.452237
ZAR 19.342946
ZMK 9379.031976
ZMW 29.116306
ZWL 335.515848
  • RIO

    -0.3150

    59.585

    -0.53%

  • CMSC

    -0.1600

    23.64

    -0.68%

  • BTI

    0.1200

    39.29

    +0.31%

  • SCS

    -0.0900

    11.5

    -0.78%

  • RBGPF

    1.7000

    63.9

    +2.66%

  • NGG

    -0.2600

    60.82

    -0.43%

  • CMSD

    -0.1400

    24.03

    -0.58%

  • RYCEF

    0.0500

    7.27

    +0.69%

  • BP

    -0.1300

    31.03

    -0.42%

  • RELX

    -0.1600

    49.24

    -0.32%

  • GSK

    -0.0650

    35.035

    -0.19%

  • JRI

    -0.1190

    12.571

    -0.95%

  • AZN

    0.3300

    69.92

    +0.47%

  • BCE

    -0.1450

    23.735

    -0.61%

  • BCC

    -1.0700

    126.57

    -0.85%

  • VOD

    0.0200

    8.53

    +0.23%

Hacker claims major Chinese citizens' data theft
Hacker claims major Chinese citizens' data theft / Photo: Andrew CABALLERO-REYNOLDS - AFP

Hacker claims major Chinese citizens' data theft

A hacker claiming to have stolen personal data from hundreds of millions of Chinese citizens is now selling the information online.

Text size:

A sample of 750,000 entries posted online by the hacker showed citizens' names, mobile phone numbers, national ID numbers, addresses, birthdays and police reports they had filed.

AFP and cybersecurity experts have verified some of the citizen data in the sample as authentic, but the scope of the entire database is hard to determine.

Advertised on a forum late last month but only picked up by cybersecurity experts this week, the 23-terabyte database -- which the hacker claims contains the records of a billion Chinese citizens -- is being sold for 10 bitcoin (approximately $200,000).

"It looks like it's from multiple sources. Some are facial recognition systems, others appear to be census data," said Robert Potter, co-founder of cybersecurity firm Internet 2.0.

"There is no verification of the total number of records and I'm sceptical of the one billion citizens number," he added.

China maintains an extensive nationwide surveillance infrastructure that siphons massive amounts of data from its citizens, ostensibly for security purposes.

Growing public awareness of data privacy has led to stronger data protection laws targeting individuals and private firms in recent years, although there is little citizens can do to stop the state from collecting their data.

Some of the leaked data appeared to be from express delivery user records, while other entries contained summaries of incidents reported to police in Shanghai over a span of more than a decade, with the most recent from 2019.

The incident reports ranged from traffic accidents and petty theft to rape and domestic violence.

- 'Heads will roll' -

At least four people out of over a dozen contacted by AFP confirmed their personal details, such as names and addresses, as listed in the database.

"So that's why so many people have been adding my WeChat over the past few days. Should I report this to the police?" said one woman surnamed Hao.

"I'm really confused about why my personal data has been leaked," said another woman surnamed Liu.

In replies to the original post, users speculated that the data may have been hacked from an Alibaba Cloud server where it was apparently being stored by the Shanghai police.

Potter, the cybersecurity analyst, confirmed that the files were hacked from Alibaba Cloud, which did not respond to an AFP request for comment.

If confirmed, the breach would be one of the largest in history and a major violation of the recently approved Chinese data protection laws.

"Heads will roll over this one," tweeted Kendra Schaefer, tech partner at research consultancy Trivium China.

China's cybersecurity administration did not respond to a fax requesting comment.

F.Schneider--NZN