The personal data of more than 100 Australian citizens, including a former federal MP, is among those exposed by a hacker in a major leak of stolen records to Chinese police authorities.
Key points:
- The hacker is trying to sell personal information for 10 bitcoins (about $ 300,000)
- Leaked police reports clarify the treatment of Uighurs and other minorities
- Data sets are believed to span more than 20 years
Last week, a hacker claimed in an online forum that he had stolen 1 billion records, mostly belonging to Chinese citizens, in an ongoing bid to sell the information for 10 bitcoins, or nearly $ 300,000.
The reports offer a strange view of how the authorities repress political dissent and persecute minorities in China, including Uighurs and Falun Gong practitioners.
This hacker published three sets of sample data online, amounting to 750,000 individual records.
The ABC called 20 people in China who were identified in the leak to confirm the authenticity of police reports.
Cybersecurity and other media experts have also verified some of the data in the 23-terabyte database.
However, Chinese authorities have not confirmed the overall size of the files and the data breach, which remains with their lips closed.
In a Shanghai police file that has 250,000 tickets, the ABC found personal data of a former Australian federal MP, who in 2004 had called police to report a theft from the trunk of a car.
The ABC contacted the individual but received no response.
Dozens of Australian citizens were also identifiable in this data set, along with their passport details, home addresses, birthdays and police reports.
More than half of Australian records were related to failure to register with local police within 24 hours of their arrival in China, a requirement of the China Exit and Entry Act, which came into force on 2013.
The records span more than 20 years from 1995 to 2019.
The China Cyberspace Administration, the Australian Department of Foreign Affairs and Trade, the Australian Federal Police and the Australian Cybersecurity Center have been contacted for comment.
All mentions of the leak were censored on the popular Chinese social media platforms Weibo and WeChat.
On Weibo, the Chinese equivalent of Twitter, the Chinese keywords “Shanghai database” and “data breach” have been banned since last week, but posts questioning the authenticity of the database that go avoid these keywords staying online.
“There’s data, so there’s money”
Robert Potter, the co-founder of cybersecurity company Internet 2.0, told the ABC that he had evaluated the data sets and that they looked authentic because the records are like other Chinese government data systems he has evaluated in the past.
The hacker released three sets of free data to the public: a total of 750,000 records. (Reuters: Aly Song)
“Given the scale of the data set, it would be difficult to make large-scale changes,” Potter said.
He said the leaked information comes from a server in Alibaba’s cloud.
Since 2019, the Shanghai Public Security Office has been storing its database in a cloud service provided by Alibaba.
The ABC has contacted Alibaba for comment.
Potter suggested that Australians who find their names on the list should get a new passport.
Loading
Monash University cybersecurity and cybercrime specialist Lennon Chang said the amount of data leaked by the hacker was “unprecedented.”
“This is a huge database, which includes all the personal information and criminal records that have been kept [by the police]”Dr. Chang said.
“On Twitter or other social media, people are confirming the accuracy of the data, so it’s actually increasing the value of the data.”
By posting some of the records online, Dr. Chang explained, the hacker was showing that the data set is accurate to attract more potential buyers.
“He’s not just trying to sell to one person,” Dr. Chang said, adding that many people were looking for sample data and trying to play with it.
“There’s data, so there’s money.”
Police data reveal investigations into minority groups
Chinese officials have been silent since the leak of Shanghai’s public security database. (AAP: Lukas Coch)
The leak reveals a series of police investigations into human rights activists and people from religious minorities, including Muslim Uighurs and Falun Gong practitioners.
China has reportedly detained more than a million people of Muslim ethnic groups, including Uighurs and Kazakhs, in re-education centers that the state calls vocational training centers.
Falun Gong, a controversial spiritual movement, has been banned in China since 1999, and practitioners around the world claim that their comrades were imprisoned and silenced in a subsequent crackdown.
In one case, the ABC spoke with a woman in China identified in the leak, who confirmed that she had reported a Falun Gong practitioner to the local police.
Others were contacted by police to make political comments, including “humiliating” the national leader and posting comments against the Chinese Communist Party (CCP) on foreign websites.
Unverified reports from the police archive showed that two people were visited by Shanghai police to post “inappropriate comments,” criticizing President Xi Jinping and the CCP on Twitter via a virtual private network (VPN) in 2018 and in 2019.
In one of the police reports, which the ABC has not been able to independently verify, a Uyghur police officer called for help from the local police because a Shanghai hotel did not allow him to register.
The report said it was due to his Uyghur background, which Chinese authorities often consider to be related to terrorism or a security threat.
In another incident, Shanghai police inspected a hotel room where an Uyghur guest was staying in 2018 and wrote in the report that the chances of terrorism had been ruled out.
Data leakage occurs when Xi Jinping makes a third historic candidacy for the presidency
While the identity of the hacker is unknown, the incident again exposes the challenge facing China in terms of data vulnerability.
China passed a new Personal Data Protection Act last November, which tightened rules on data collection, use and storage as Beijing intensified its control and data collection during the pandemic. .
Data breach comes at a politically sensitive time. (Reuters)
Dr. Chang said that piracy, or leaking private information from citizens, would be seen as a violation of the law.
“It’s actually a good time to let us see if the data protection law is in action with the Chinese government,” he said.
Dr. Chang said another possible intention of the data leak could be to disrupt or affect Xi’s bid for a third term as party leader.
“What I’m most interested in seeing is when the data is leaked,” Dr. Chang said.
“[It is] important moment for the PCC to make sure everything is fine, so that they can have a good transition. “
The CCP will hold its annual meeting in a few months, and Xi’s mandate is widely expected to be extended for a third term.
It is a crucial moment for the country’s political stability, as Xi’s opponents are expected to challenge his power, although many of them have been drowned out as his anti-corruption campaign intensifies. .
Posted 2 hours, 2 hours ago, Thursday, July 7, 2022 at 7:28 PM, updated 29 minutes ago, 29 minutes ago, Thursday, July 7, 2022 at 9:07 PM