Massive Chinese Police Database Hacked/Sold, Gov’t Responds By Trying To Bury The News

from the china's-national-bird-is-the-third-person-ostrich dept

The problem with gathering tons of sensitive data and storing it indefinitely is sooner or later someone with even worse intentions is going to come looking for it. And China’s massive surveillance apparatus collects oh so much data.

It’s far too tempting to resist. Someone with the guts and audacity to go after one of the most repressive regimes in the world has made a mockery of the government’s security measures and is now, presumably, making a tidy profit. Rachel Cheung has the details for Motherboard.

An anonymous hacker is selling a massive database that allegedly contains the personal information of a billion Chinese citizens, more than two-thirds of the country’s population. 

In a recent post on the cybercrime site Breach Forums, a user going by ChinaDan claimed to offer more than 23 terabytes of data for 10 bitcoin, which is around $200,000. The trove of data was allegedly leaked from a Shanghai police database. 

Researchers and journalists are still trying to verify the hacker’s claims. ChinaDan released 750,000 files, which is still only a very small percentage of the alleged total haul. Some of the criminal records released have been verified, suggesting this reported breach may be legitimate.

Not only is there the potential for massive fraud, what with apparent access to the credentials and other personal information belonging to nearly one billion people, there’s plenty that could be used to embarrass Chinese residents, personally or professionally.

Another file listed 250,000 reports of crime to Shanghai authorities. They include cases of looting, online fraud, and domestic abuse, as well as offenses as petty as a 43-year-old getting an “illegal” handjob for 50 yuan (about $7.5) at a bathhouse in 2004.

And the damage could go further than simply ruining someone financially via regular old identity fraud. This being China, a truly malicious person could theoretically convert stolen credentials into lifetime imprisonment for victims by using this info to fire up accounts on internet services to traffic in anti-government rhetoric.

There’s a private (well… as private as a company can be in China) contractor in the mix as well. Alibaba’s cloud service apparently hosted the database. In a comment to Motherboard, the company said it was aware of the incident and was investigating.

Chinese citizens may be the victims, but they’ll also be the last to know, if the government can do anything about it.

The alleged hack set Chinese social media abuzz for a brief period over the weekend, but by Monday microblogging network Weibo and Tencent’s WeChat had begun to censor the topic.

Hashtags such as “data leak”, “Shanghai national security database breach” and “1 billion citizens’ records leak”, which had amassed millions of views and comments, were blocked on Twitter-like Weibo.

One Weibo user with 27,000 followers said a viral post about the hack had been removed by censors and that she had already been invited by local authorities to discuss the post.

So far, so China. The censorship is in full effect. And the government, which should feel obligated to inform citizens their personal information has possibly been compromised, refuses to discuss the hacking. According to the Financial Times, numerous branches of the Shanghai government have refused to comment on the incident and the agency in charge of national data security (Cyberspace Administration of China) chose not to respond to reporters’ questions.

I realize the Chinese government cares far more about its well-being than the concerns of its billions of constituents, but burying bad news and pretending it isn’t happening is insanely harmful. But, in the end, it will be citizens that are harmed the most, so why should the government care?

Filed Under: , , , ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Massive Chinese Police Database Hacked/Sold, Gov’t Responds By Trying To Bury The News”

Subscribe: RSS Leave a comment
17 Comments
That One Guy (profile) says:

'We are the ruling body, we are Never Wrong.'

It makes a warped sort of sense that the government would try to bury the hack, if they own it people might think that the government should do something about it and start wondering how good an idea it is to have the most valuable hacking target in the world compiled by said government.

If instead they go silent then when people start having problems due to the hack they’re more likely to think it was something they did or a personal problem, leaving dealing with it all on them and the government squeaky clean since clearly they had nothing to do with it.

DBA Phillip Cross says:

Re:

the most valuable hacking target in the world

[Citation needed]

I would think the Stratfor hack, or the police unions hack was that, or any of so many that Julian Assange is being persecuted for, noy some simple easy-peezy China infrastructure thingy.

After all, Chinese switches were pre-hacked by NSA, et-ass a decade ago.

Anonymous Coward says:

There’s no eff or independent consumer council in China, there’s company’s that do work for the government , the police, the military, the government can acess the database of any company that wish. This could be used to blackmail government officials or blackmail citizens. Or just commit id fraud. China is basically an open air prison where there’s millions of camera, s and user data is constantly being harvested.
If you switch off your phone , the government will put a camera outside your house.
The problem is when you constantly collect data on millions of people it creates a massive target for hackers. If it gets leaks it could cause chaos

Anonymous Coward says:

And the damage could go further than simply ruining someone financially via regular old identity fraud. This being China, a truly malicious person could theoretically convert stolen credentials into lifetime imprisonment for victims by using this info to fire up accounts on internet services to traffic in anti-government rhetoric.

Hello ID theft my old friend, I’ve come to rue your life again…

(Let’s just say it goes beyond anti-CCP rhetoric and leave it at that.)

Anonymous Coward says:

Re:

Right. Communist nations, at least, are very transparent about the fact that they have a thriving blackmail industry.

Which reminds me of how the US outsourced that thriving blackmail industry to corporate entities 20 years ago ala Forbes Magazine’s excursion into “free” nations activities designed to blackmail folks with those grotesque Mugshot websites. US is so free!

Six of one, half a dozen the other…

DBA Phillip Cross says:

This being China, a truly malicious person could theoretically convert stolen credentials into lifetime imprisonment for victims by using this info to fire up accounts on internet services to traffic in anti-government rhetoric

Interesting point. I read that and almost sent it in, but knew you would cover it one way or another. Looking into it right now.

Meanwhile, back in Freedomland, Amazon is again handing data over to police without a warrant.

Lovin-me-some-outsourced-police-state! Censorship-by-proxy!

And the Uvalde, Texas video of cops with their thumbs up their asses in a grade schol hallway, as a shooter waks in “on script” was an eye opener, for f@cks sake! It was 77 minutes, and so for apocalypic christians and other whack-jobs, , the number 77 has a numerological meaning, in case anyone wonders why all those” well-meaning” cops stood down as kids were murdered there.

But why is the footage of the two people who showed up out of nowhere, and tried to “assist” the shooter after he crashed missing?” Lol/

As for ChinaDan, check put the crypto boards and discussions–he/she them/ pronoun-as-ye-invented-CIAgency-et-ass darksider, is worth a story, all by him/herself.

Hopes-N-Prayer’s Y’all!

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...
Loading...