Record Chinese cyber breach spurs eruption in data for sale


An estimated 290 million records about people in China surfaced on an underground bazaar known as Breach Forums in July, according to Group-IB, a cybersecurity firm based in Singapore. — DARWIN LAGANZON/Pixabay

Since the data of about roughly one billion Chinese citizens appeared for sale on a popular dark web forum in June, researchers have observed a surge in other kinds of personal records from China appearing on cybercriminal marketplaces.

In the aftermath of that record leak, an estimated 290 million records about people in China surfaced on an underground bazaar known as Breach Forums in July, according to Group-IB, a cybersecurity firm based in Singapore.

ALSO READ: Hackers claim theft of police info in China’s largest data leak

In August, one seller hawked personal information belonging to nearly 50 million users of Shanghai’s mandatory health code system, used to enforce quarantine and testing orders. The alleged hoard included names, phone numbers, IDs and their Covid status – for the price of US$4,000 (RM18,130).

“The forum has never seen such an influx of Chinese users and interest in Chinese data,” said Feixiang He, a researcher at Group-IB. “The number of attacks on Chinese users may grow in the near future.”

Bloomberg was unable to confirm the authenticity of the datasets for sale on Breach Forums.

The website, like other markets where illicit goods are sold, has been home to false advertisements meant to generate attention, as well as legitimate data apparently stolen in security incidents, including an instance where users marketed user information taken from Twitter Inc.

ALSO READ: Shanghai data breach exposes dangers of China’s trove

The interest in leaked Chinese data has trained a spotlight on the vast amount of information that government officials collect through Beijing’s sprawling surveillance apparatus. In the summer incident, the unknown hackers claimed to have stolen data of about one billion Chinese residents after their discovery of an unsecured Shanghai police database, laying bare significant vulnerabilities in how government agencies store citizens’ information.

Before that episode, there were three China-related databases marketed on Breach Forums, according to Group-IB’s Feixiang He. In July, that number jumped to 17, the firm found.

Researchers were unable to confirm the legitimacy of all the information in databases posted that month.

Chinese-speaking users on Breach Forums expressed surprise that data about the country’s citizens was available for sale, according to a Bloomberg News review.

The posts were so frequent that a forum administrator asked website visitors to keep posts in the English language. “Please do not send Chinese characters,” they wrote.

In the 10-day period following the apparent Shanghai leak, researchers from San Francisco-based Reposify Ltd discovered more than 12,700 exposed assets – including web servers and remote access sites – when scanning for software vulnerabilities in Chinese government websites.

This also included 1,436 exposed databases, which “could account for millions of potentially accessible data points representing Chinese citizens”, the company said.

The uptick in databases for sale comes in spite of Beijing’s increasingly strict cybersecurity and data privacy standards, which President Xi Jinping has tied closely to national security.

ALSO READ: Claim of TikTok breach spotlights viral app’s lure as target

Shanghai authorities and China’s Internet regulators haven’t publicly addressed leaks of police and health system data, and discussions of the incidents have been scrubbed by censors from local social media.

Shanghai’s government and the Cyberspace Administration of China, the main Internet regulator, didn’t respond to multiple faxes requesting comment.

“We can see tens of thousands, more than 20,000 servers in China alone that are completely open,” said Stanislav Pratossov, co-founder of the security firm Acronis International GmbH. “This happens everywhere. In China, I guess, the amount is outrageous just because of the size of the Chinese economy, and the number of servers in China is huge.”

Away from the public view, analysts said, they expect an internal review within the government agencies in question and tighter scrutiny of those involved in data management. “It doesn’t matter how this plays out, it’s going to shed a bad light on the cybersecurity regime, on institutions that enforce these regulations,” said Michael Frick, a cyber consultant for businesses in China and a published author on the country’s cyber industry.

In the meantime, hackers are readying themselves for more data dumps. One new user on the underground database forum, who claimed to be selling the Shanghai health system data after joining the site in July, alleged that they had more leaked information to share.

“In my humble opinion, no amount of cyber security (or) data protection could stop data leaks from ever happening,” the unnamed user wrote.

As for Breach Forums, its administrators offered a pointed reminder in its welcome message to new Chinese users: “We are not in China and we are not Chinese, so we do not have to obey Chinese laws.” – Bloomberg

Follow us on our official WhatsApp channel for breaking news alerts and key updates!
   

Next In Tech News

Amazon Prime Video to exclusively stream two NHL seasons in Canada
T-Mobile to invest $950 million in venture with EQT to buy fiber optic network provider Lumos
Hertz Global eyes worst day on record as EV rental business falters
EU court adviser backs data privacy activist Schrems in Meta fight
Spotify says Apple has rejected its app update with price information for EU users
Amazon to invest $11 billion in Indiana to build data centers
IBM falls as enterprise-spending constraints choke consulting demand
Net neutrality rules to be restored in US agency vote
India's Tech Mahindra misses Q4 revenue view on weak communications segment
Explainer-Where are Wall Street's analyst notes on Trump's Truth Social?

Others Also Read