Researcher finds what appears to be an unsecured facial recognition database of 2.5M+ Uyghur Muslims in China, with ID card data and near real-time GPS data
Catalin Cimpanu / ZDNet : Tweets: @b_nishanov , @einsteinsattic , @mattburgess1 , and @alfredwkng . Thanks: @campuscodi Tweets: Bakhti Nishanov / @b_nishanov : If you continue to have doubts China is trying to make #Xinjiang into an open air prison http://www.zdnet.com/... Phil Booth / @einsteinsattic : “The database... wasn't just some dead servers with old data. The researcher said that during the past 24 hours a stream of nearly 6.7 million GPS coordinates were recorded, meaning the database was actively tracking #Uyghur Muslims as they moved around.” http://www.zdnet.com/... Matt Burgess / @mattburgess1 : Ouch. Unsecured database with used for tracking China's Uyghur Muslim population found online. Includes: GPS location data, names, ID card numbers and details, sex, nationality, home addresses, DOB, photos, and employer http://www.zdnet.com/... Alfred / @alfredwkng : .@0xDUDE found out that this leaked database we wrote about yesterday was used by the Chinese government for tracking Uyghur Muslims. https://twitter.com/... Thanks: @campuscodi
Context & Ripple Effects
This finding lands on top of two years of reporting that had already mapped the machinery: interviews documenting how authorities surveil Xinjiang residents with AI, iris scanning, and tools built by private firms, and evidence that Beijing compiles a global registry of Uyghurs extending surveillance to the diaspora, including people living in the US. What is new here is not the intent but the exposure — an unsecured database showing ID card records and a live stream of GPS coordinates, meaning the tracking was running in near real time while anyone could read it.
The discovery also fits a recurring failure mode rather than a one-off: months later an unprotected system matching faces to police records surfaced in Beijing, and subsequent years brought further exposures, including a facial-recognition database on schoolchildren and a trove of up to 800M records left open for months.
First-order effects
- The roughly 2.5 million Uyghurs whose ID card data and movements are in the database are exposed to identification and targeting beyond what authorities already hold, since the data was readable by outsiders for an unknown period.
- Chinese authorities face confirmation, from their own leaked telemetry, that the system was actively tracking Uyghur movements — nearly 6.7 million GPS coordinates logged in a single day — turning a policy question into documented operational fact.
Second-order effects
- Foreign governments and export-control bodies gain concrete evidence for restricting sales of surveillance and biometric systems to Chinese buyers, strengthening the case built by earlier reporting on private firms supplying Xinjiang monitoring tools.
- Diaspora communities and the researchers tracking them — the same open-source effort that has located internment camps online — get a new evidentiary thread connecting domestic tracking to the overseas registry effort.
Third-order effects
- If the pattern holds — repeated unsecured biometric and location databases across Beijing, schools, and Xinjiang — it points to systemic data-handling failures inside China's surveillance buildout, where collection scales faster than operational security.
- Independent security researchers are becoming the de facto auditors of state surveillance systems, a role regulators and platforms have no formal mechanism for but which increasingly shapes the public record and policy responses.
The trend: China's biometric surveillance expansion keeps outrunning its own operational security, leaving misconfigured databases for independent researchers to expose and governments to act on.