Hacker claims to sell data of 48.5 million users of Shanghai's COVID app

 

A man wearing protective gear checks his mobile phone at a subway station, after the lockdown placed to curb the coronavirus disease (COVID-19) outbreak was lifted in Shanghai, China June 2, 2022. REUTERS/Aly Song

A man wearing protective gear checks his mobile phone at a subway station, after the lockdown placed to curb the coronavirus disease (COVID-19) outbreak was lifted in Shanghai, China June 2, 2022. REUTERS/Aly Song


The city of Shanghai's COVID health code mobile app is used by 48.5 million people, and a hacker has claimed to have gotten their personal information. This is the second time in less than a month that a data breach has been reported in the Chinese financial center.

 

On Wednesday, the hacker posting under the alias "XJP" offered to sell the data for $4,000 on the hacker forum Breach Forums.

 

A sample of the data, which included 47 people's phone numbers, names, Chinese identity numbers, and health code status, was made available by the hacker.

 

Of the 47 people Reuters spoke with, eleven verified that they were included in the sample, but two claimed that their identifying numbers were incorrect.

"This DB (database) contains everyone who lives in or visited Shanghai since Suishenma's adoption," XJP said in the post, which originally asked for $4,850 before lowering the price later in the day.

 

Suishenma is the Chinese name for Shanghai's health code system, which the city of 25 million people, like many across China, established in early 2020 to combat the spread of COVID-19. All residents and visitors have to use it.

 

The app collects travel data to give people a red, yellow or green rating indicating the likelihood of having the virus and users have to show the code to enter public venues.

 

Users can access Suishenma through the Alipay app, owned by financial behemoth and Alibaba affiliate Ant Group, as well as the WeChat app from Tencent Holdings. The data is handled by the city administration.

 

Requests for comment from XJP, the Shanghai government, Ant, and Tencent were not immediately fulfilled.

 

The alleged Suishenma breach was reported after a hacker claimed early last month that the Shanghai police had given them 23 terabytes of personal data belonging to one billion Chinese individuals.

 

On breach forums, the hacker allegedly made the data available for sale.

The Wall Street Journal, citing cyber security researchers, said the first hacker had been able to steal the data from the police as a dashboard for managing a police database had been left open on the public internet without password protection for more than a year.

 

The newspaper said data was hosted on Alibaba's cloud platform and Shanghai authorities had summoned company executives over the matter.

 

Neither the Shanghai government, nor police nor Alibaba have commented on the police database matter.


Source: Reuters


Post a Comment

0 Comments