Anonymous hackers Offer It sells stolen personal data of more than 1 billion Chinese citizens for about $ 200,000 in 10 Bitcoin (BTC).
The data includes name, place of origin, address, phone number, national ID, criminal information, and other information about domestic civilians.
hacker Reportedly You can now access the Shanghai Police Database in China, which steals more than 26 terabytes of personal data.
Huge private data breach if confirmed: Hackers sell alleged data breaches of Shanghai police, including billions of Chinese names, home addresses, ID numbers, phone numbers, criminal records, etc. .. Hackers say it’s from the Aliyun (Alibaba) private cloud server. pic.twitter.com/IRPG35SWYI
Zeyi Yang (@ZeyiYang) July 3, 2022
Given the size and impact of such data, many initially questioned the credibility of hacker claims. However, hackers revealed some of the data to show the extent of the damage.
Binance CEO Changpeng Zhao acknowledged this claim. He tweeted today that his company’s threat intelligence has detected someone offering to sell data on a billion residents from Asian countries.
Our threat intelligence has detected 1 billion resident records sold on the dark web, including names, addresses, national IDs, mobile phones, police and medical records from one Asian country. This could be due to a bug in your ElasticSearch deployment by a government agency.This affects …
CZ Binance (@cz_binance) July 3, 2022
According to CZ, this breach could be “due to a bug in ElasticSearch deployment by a government agency.”But he Confirmed The exploit was because “government developers created a technical blog about CSDN and mistakenly included their credentials.”
Apparently, this exploit was caused by a government developer writing a technical blog on CSDN and mistakenly including credentials.
1 billion records of civilian data. https://t.co/vPISm534Tn pic.twitter.com/FpMCGrpx08
CZ Binance (@cz_binance) July 4, 2022
Zhao said Binance has improved its security measures to verify affected users. He also called on other platforms to do the same.
Chinese authorities have not yet confirmed or denied the breach.