Stock Market News

Hacker offers to sell data of 48.5 million users of Shanghai’s COVID app

2022.08.12 14:01

Hacker offers to sell data of 48.5 million users of Shanghai's COVID app
FILE PHOTO: A man wearing protective gear checks his mobile phone at a subway station, after the lockdown placed to curb the coronavirus disease (COVID-19) outbreak was lifted in Shanghai, China June 2, 2022. REUTERS/Aly Song

By Eduardo Baptista

BEIJING (Reuters) -A hacker claims to have obtained the personal information of 48.5 million users of a COVID health mobile app run by the city of Shanghai, the second claim of a breach of the Chinese financial hub’s data in just over a month.

The hacker with the username as “XJP” posted an offer to sell the data for $4,000 on the hacker forum Breach Forums on Wednesday.

The person provided a sample of the data including the phone numbers, names and Chinese identification numbers and health code status of 47 people.

Eleven of the 47 reached by Reuters confirmed that they were listed in the sample, though two said their identification numbers were wrong. Reuters was unable to further verify the authenticity of the hacker’s claim.

The true size and nature of these kinds of data hacks is sometimes overstated by the seller in an attempt to make a quick profit.

“This DB (database) contains everyone who lives in or visited Shanghai since Suishenma’s adoption,” XJP said in the post, which originally asked for $4,850 before lowering the price later the same day.

Suishenma is the Chinese name for Shanghai’s health code system, which the city of 25 million people established in early 2020 to combat the spread of COVID-19. All residents and visitors have to use it.

The app collects travel data to give users a red, yellow or green rating indicating the likelihood of having the virus. The code has to be shown to enter public venues.

The data is managed by the city government and users can access Suishenma either by downloading the app or opening it using the Alipay app, owned by fintech giant and Alibaba (NYSE:BABA) affiliate Ant Group, and Tencent Holdings (OTC:TCEHY)’ WeChat app.

XJP, the Shanghai government, Ant and Tencent did not immediately respond to requests for comment.

The purported Suishenma breach comes after a hacker last month claimed to have procured 23 terabytes of personal information belonging to one billion Chinese citizens from the Shanghai police.

That hacker also offered to sell the data on Breach Forums.

The first hacker was able to steal data from the police as a dashboard for managing a police database had been left open on the public internet without password protection for more than a year, the Wall Street Journal reported, citing cyber security researchers.

The newspaper said data was hosted on Alibaba’s cloud platform and Shanghai authorities had summoned company executives over the matter.

Neither the Shanghai government, nor police nor Alibaba have commented on the police database matter.

Chinese regulatory bodies have in the past two years announced a barrage of new rules strengthening oversight over the private sector’s management of user data, after years of complaints by residents of how their personal data could be easily stolen or sold.

A screenshot of XJP’s offer on Breach Forums went viral on Chinese social media on Friday, prompting several Weibo (NASDAQ:WB) users to weigh in on this latest leak and its broader implications, as well as question what sort of action would be taken.

“Data leaks in China are really no longer uncommon news,” said one.

Source

Related Articles

Leave a Reply

Back to top button
bitcoin
Bitcoin (BTC) $ 98,886.49 0.90%
ethereum
Ethereum (ETH) $ 3,470.49 0.09%
tether
Tether (USDT) $ 0.999331 0.01%
xrp
XRP (XRP) $ 2.28 0.78%
bnb
BNB (BNB) $ 707.03 1.30%
solana
Solana (SOL) $ 198.40 1.01%
dogecoin
Dogecoin (DOGE) $ 0.332281 0.47%
usd-coin
USDC (USDC) $ 0.999726 0.03%
staked-ether
Lido Staked Ether (STETH) $ 3,467.18 0.06%
cardano
Cardano (ADA) $ 0.912079 1.41%
tron
TRON (TRX) $ 0.257628 0.80%
avalanche-2
Avalanche (AVAX) $ 39.97 2.64%
chainlink
Chainlink (LINK) $ 24.17 2.34%
the-open-network
Toncoin (TON) $ 5.93 0.19%
wrapped-steth
Wrapped stETH (WSTETH) $ 4,118.64 0.06%
shiba-inu
Shiba Inu (SHIB) $ 0.000023 3.15%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 98,573.41 1.00%
sui
Sui (SUI) $ 4.43 2.80%
hedera-hashgraph
Hedera (HBAR) $ 0.31579 0.31%
stellar
Stellar (XLM) $ 0.380572 3.21%
polkadot
Polkadot (DOT) $ 7.43 0.63%
weth
WETH (WETH) $ 3,471.94 0.14%
bitcoin-cash
Bitcoin Cash (BCH) $ 462.69 0.44%
leo-token
LEO Token (LEO) $ 9.51 0.37%
hyperliquid
Hyperliquid (HYPE) $ 26.08 12.20%
bitget-token
Bitget Token (BGB) $ 6.23 25.29%
uniswap
Uniswap (UNI) $ 13.69 4.16%
litecoin
Litecoin (LTC) $ 108.87 0.65%
pepe
Pepe (PEPE) $ 0.000018 3.82%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,664.72 0.02%
near
NEAR Protocol (NEAR) $ 5.35 3.69%
ethena-usde
Ethena USDe (USDE) $ 0.998802 0.01%
aave
Aave (AAVE) $ 361.01 1.36%
usds
USDS (USDS) $ 0.998553 0.14%
internet-computer
Internet Computer (ICP) $ 11.09 1.92%
aptos
Aptos (APT) $ 9.46 3.50%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.506964 3.13%
crypto-com-chain
Cronos (CRO) $ 0.156579 3.66%
vechain
VeChain (VET) $ 0.050843 1.80%
mantle
Mantle (MNT) $ 1.22 0.31%
ethereum-classic
Ethereum Classic (ETC) $ 27.08 2.14%
render-token
Render (RENDER) $ 7.48 4.06%
bittensor
Bittensor (TAO) $ 490.15 1.89%
mantra-dao
MANTRA (OM) $ 3.77 2.61%
whitebit
WhiteBIT Coin (WBT) $ 24.83 0.18%
monero
Monero (XMR) $ 191.01 0.02%
fetch-ai
Artificial Superintelligence Alliance (FET) $ 1.33 3.73%
dai
Dai (DAI) $ 0.999754 0.02%
arbitrum
Arbitrum (ARB) $ 0.79347 1.60%
virtual-protocol
Virtuals Protocol (VIRTUAL) $ 3.25 9.65%