In a forum post, an unidentified hacker claims to have stolen 23TB of data on up to 1B Chinese residents after breaching a Shanghai police database
Unknown hackers claimed to have stolen data on as many as a billion Chinese residents after breaching a Shanghai police database …
BloombergSarah Zheng
Context & Ripple Effects
The initial claim was followed by reporting that a police-database management dashboard had been exposed for more than a year, providing a concrete account of the alleged access path. Later coverage also described smaller tranches of the purported resident data appearing on forums, extending the incident beyond a single sale listing.
The story matters because the alleged dataset concerns police-held records at population scale, while the later dashboard reporting ties the claim to an operational security failure rather than an isolated forum assertion.
First-order effects
Shanghai police face immediate pressure to secure the allegedly exposed database-management dashboard and assess what resident records were accessed.
People included in the claimed dataset face heightened exposure of personal information and national IDs as the material is offered for sale.
Second-order effects
The appearance of a 23TB-plus data sale listing gives downstream fraud and identity-abuse actors a potential source of structured personal records, rather than isolated leaked files.
The reported dashboard exposure makes access-control and internet-facing administrative systems a focal point for other Chinese public-sector database operators.
Third-order effects
If large government datasets continue to be broken into smaller saleable releases, a single intrusion can create a persistent secondary market for identity data long after the initial access is closed.
The incident points toward public-sector cybersecurity being judged not only by breach prevention but by whether administrative tools can be continuously discovered, isolated, and monitored.
The trend: Large-scale public-sector data breaches are becoming enduring identity-data supply events when exposed management systems enable bulk extraction and resale.
Our threat intelligence detected 1 billion resident records for sell in the dark web, including name, address, national id, mobile, police and medical records from one asian country. Likely due to a bug in an Elastic Search deployment by a gov agency. This has impact on ...
Gigantic civilian data leak if confirmed: A hacker is selling an alleged Shanghai police data leak containing 1 billion Chinese nationals' names, home addresses, ID #, phone #, criminal records, etc. Hacker says it's from an Aliyun (Alibaba) private cloud server. https://twitter.…
Apparently, this exploit happened because the gov developer wrote a tech blog on CSDN and accidentally included the credentials. 1 billion records of private citizens' data. 😭 https://twitter.com/... https://twitter.com/...
If you're not following this, you should be: word on the social media street is that China's police force (MPS - Shanghai) database was hacked, with the personal information and case records of 1 billion citizens, and the records are for sale on Telegram - 23TB of data. 1/7 https…
hacker detection/prevention measures, mobile numbers used for account take overs, etc. It is important for all platforms to enhance their security measures in this area. @Binance has already stepped up verifications for users potentially affected. Stay #SAFU. 🙏
CZ, founder and CEO of Binance, talked about the leak here: https://twitter.com/... I wonder if Binance bought or would buy the leaked data. https://twitter.com/...
Shanghai police database with one billion PRC residents info got hacked in the biggest cybersecurity breach in China's history. https://www.bloomberg.com/... by @_szheng https://twitter.com/...
CZ: detected 1 billion resident records for sell in the dark web, including name, address, national id, mobile, police and medical records (may China), likely due to a bug in an Elastic Search deployment by gov. Binance has stepped up verifications for users potentially affected.…