HT TECH wants to start sending you push notifications. Click allow to subscribe

Record Cyber Breach in China Spurs Eruption in Data for Sale

Since the data of about roughly 1 billion Chinese citizens appeared for sale on a popular dark web forum in June, researchers have observed a surge in other kinds of personal records from China appearing on cybercriminal marketplaces.

By: BLOOMBERG
Updated on: Sep 15 2022, 15:37 IST
According to reports, an estimated 290 million records about people in China surfaced on an underground bazaar known as Breach Forums in July, (Bloomberg)

Since the data of about roughly 1 billion Chinese citizens appeared for sale on a popular dark web forum in June, researchers have observed a surge in other kinds of personal records from China appearing on cybercriminal marketplaces.

In the aftermath of that record leak, an estimated 290 million records about people in China surfaced on an underground bazaar known as Breach Forums in July, according to Group-IB, a cybersecurity firm based in Singapore. In August, one seller hawked personal information belonging to nearly 50 million users of Shanghai’s mandatory health code system, used to enforce quarantine and testing orders. The alleged hoard included names, phone numbers, IDs and their Covid status -- for the price of $4,000.

You may be interested in

Mobiles Tablets Laptops
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹156,900
Check details
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹107,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,990₹74,999
Buy now
41% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹52,990₹89,999
Buy now
41% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹34,490₹57,999
Buy now
40% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,350₹51,990
Buy now
35% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹25,999₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,668₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹16,998
Check details

“The forum has never seen such an influx of Chinese users and interest in Chinese data,” said Feixiang He, a researcher at Group-IB. “The number of attacks on Chinese users may grow in the near future.”

Also read: Looking for a smartphone? To check mobile finder click here.

Bloomberg was unable to confirm the authenticity of the datasets for sale on Breach Forums. The website, like other markets where illicit goods are sold, has been home to false advertisements meant to generate attention, as well as legitimate data apparently stolen in security incidents, including an instance where users marketed user information taken from Twitter Inc.

The interest in leaked Chinese data has trained a spotlight on the vast amount of information that government officials collect through Beijing’s sprawling surveillance apparatus. In the summer incident, the unknown hackers claimed to have stolen data of about 1 billion Chinese residents after their discovery of an unsecured Shanghai police database, laying bare significant vulnerabilities in how government agencies store citizens’ information.

Before that episode, there were three China-related databases marketed on Breach Forums, according to Group-IB’s Feixiang He. In July, that number jumped to 17, the firm found. Researchers were unable to confirm the legitimacy of all the information in databases posted that month.

Chinese-speaking users on Breach Forums expressed surprise that data about the country’s citizens was available for sale, according to a Bloomberg News review. The posts were so frequent that a forum administrator asked website visitors to keep posts in the English language. “Please do not send Chinese characters,” they wrote.

In the 10-day period following the apparent Shanghai leak, researchers from San Francisco-based Reposify Ltd. discovered more than 12,700 exposed assets — including web servers and remote access sites — when scanning for software vulnerabilities in Chinese government websites. This also included 1,436 exposed databases, which “could account for millions of potentially accessible data points representing Chinese citizens,” the company said.

The uptick in databases for sale comes in spite of Beijing’s increasingly strict cybersecurity and data privacy standards, which President Xi Jinping has tied closely to national security.

Shanghai authorities and China’s internet regulators haven’t publicly addressed leaks of police and health system data, and discussions of the incidents have been scrubbed by censors from local social media. Shanghai’s government and the Cyberspace Administration of China, the main internet regulator, didn’t respond to multiple faxes requesting comment.

“We can see tens of thousands, more than 20,000 servers in China alone that are completely open,” said Stanislav Pratossov, co-founder of the security firm Acronis International GmbH. “This happens everywhere. In China, I guess, the amount is outrageous just because of the size of the Chinese economy, and the number of servers in China is huge.”

Away from the public view, analysts said, they expect an internal review within the government agencies in question and tighter scrutiny of those involved in data management.

“It doesn’t matter how this plays out, it’s going to shed a bad light on the cybersecurity regime, on institutions that enforce these regulations,” said Michael Frick, a cyber consultant for businesses in China and a published author on the country’s cyber industry.

In the meantime, hackers are readying themselves for more data dumps. One new user on the underground database forum, who claimed to be selling the Shanghai health system data after joining the site in July, alleged that they had more leaked information to share. “In my humble opinion, no amount of cyber security [or] data protection could stop data leaks from ever happening,” the unnamed user wrote.

As for Breach Forums, its administrators offered a pointed reminder in its welcome message to new Chinese users: “We are not in China and we are not Chinese, so we do not have to obey Chinese laws.”

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 15 Sep, 15:37 IST

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
9% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹82,000₹89,900
Buy now
38% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹34,000
Buy now
31% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,949₹28,999
Buy now
18% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹94,349₹115,197
Buy now
31% OFF
realme Pad 2 WiFi
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,949₹28,999
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
36% OFF
Asus VivoBook Pro 15 OLED K6500ZC L501WS Laptop
  • Quiet Blue
  • 16 GB RAM
  • 512 GB SSD
₹61,990₹96,990
Buy now
42% OFF
Asus ROG Zephyrus G14 GA401IHR K2067TS Laptop
  • White
  • 8 GB RAM
  • 1 TB SSD
₹89,990₹155,990
Buy now
34% OFF
Asus TUF Gaming F17 FX706HC HX070T Laptop
  • Graphite Black
  • 8 GB RAM
  • 1 TB SSD
₹49,990₹75,990
Buy now
NEXT ARTICLE BEGINS