![]() |
A man wearing protective gear
checks his mobile phone at a subway station, after the lockdown placed to curb
the coronavirus disease (COVID-19) outbreak was lifted in Shanghai, China June
2, 2022. REUTERS/Aly Song
The
city of Shanghai's COVID health code mobile app is used by 48.5 million people,
and a hacker has claimed to have gotten their personal information. This is the
second time in less than a month that a data breach has been reported in the
Chinese financial center.
On
Wednesday, the hacker posting under the alias "XJP" offered to sell
the data for $4,000 on the hacker forum Breach Forums.
A
sample of the data, which included 47 people's phone numbers, names, Chinese
identity numbers, and health code status, was made available by the hacker.
Of
the 47 people Reuters spoke with, eleven verified that they were included in
the sample, but two claimed that their identifying numbers were incorrect.
"This
DB (database) contains everyone who lives in or visited Shanghai since
Suishenma's adoption," XJP said in the post, which originally asked for
$4,850 before lowering the price later in the day.
Suishenma
is the Chinese name for Shanghai's health code system, which the city of 25
million people, like many across China, established in early 2020 to combat the
spread of COVID-19. All residents and visitors have to use it.
The
app collects travel data to give people a red, yellow or green rating
indicating the likelihood of having the virus and users have to show the code
to enter public venues.
Users
can access Suishenma through the Alipay app, owned by financial behemoth and
Alibaba affiliate Ant Group, as well as the WeChat app from Tencent Holdings.
The data is handled by the city administration.
Requests
for comment from XJP, the Shanghai government, Ant, and Tencent were not
immediately fulfilled.
The
alleged Suishenma breach was reported after a hacker claimed early last month
that the Shanghai police had given them 23 terabytes of personal data belonging
to one billion Chinese individuals.
On
breach forums, the hacker allegedly made the data available for sale.
The
Wall Street Journal, citing cyber security researchers, said the first hacker
had been able to steal the data from the police as a dashboard for managing a
police database had been left open on the public internet without password
protection for more than a year.
The
newspaper said data was hosted on Alibaba's cloud platform and Shanghai
authorities had summoned company executives over the matter.
Neither
the Shanghai government, nor police nor Alibaba have commented on the police
database matter.
Source:
Reuters

0 Comments