https://www.theregister.com/2022/07/05/shanghai_police_database_for_sell/ [user] [user] Sign in The Register(r) -- Biting the hand that feeds IT [magn] [burg] [burg] Topics Security Security All SecurityCyber-crimePatchesResearchCSO (X) Off-Prem Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem On-Prem All On-PremSystemsStorageNetworksHPCPersonal Tech (X) Software Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Vendor Voice Vendor Voice Vendor Voice All Vendor VoiceAmazon Web Services (AWS) Business Transformation CofenseGoogle CloudOutsystemsRapid7Rockwell Automation (X) Resources Resources Whitepapers Webinars Newsletters [cybercrime] Cyber-crime Billion-record stolen Chinese database for sale on breach forum Appears to have leaked from a cloud thanks to sloppy coding Laura Dobberstein Tue 5 Jul 2022 // 06:04 UTC 14 comment bubble on white --------------------------------------------------------------------- 14 comment bubble on white # reddit Twitter Facebook linkedin WhatsApp email [https://www.theregis] Copy A threat actor has taken to a forum for news and discussion of data breaches with an offer to sell what they assert is a database containing records of over a billion Chinese civilians - allegedly stolen from the Shanghai Police. Over the weekend, reports started to surface of a post to a forum at Breached.to. The post makes the following claim: In 2022, the Shanghai National Police (SHGA) database was leaked. This database contains many TB of data and information on Billions of Chinese citizens. HackerDan offered to sell the lot for 10 Bitcoin - about $200,000. We've saved HackerDan's post as a PDF in case it vanishes. HackerDan released sample datasets: one containing delivery addresses and often instructions for drivers; another with police records; and the last with personal identification information like name, national ID number address, height, and gender. China has a national police force, and that presumably has a Shanghai office. But an entity called the "Shanghai National Police" is hard to find. [cybercrime] Media outlets were nonetheless able to verify that the contents of the sample - whatever the source - describe actual people. Gigantic civilian data leak if confirmed: A hacker is selling an alleged Shanghai police data leak containing 1 billion Chinese nationals' names, home addresses, ID #, phone #, criminal records, etc. Hacker says it's from an Aliyun (Alibaba) private cloud server. pic.twitter.com/IRPG35SWYI -- Zeyi Yang (@ZeyiYang) July 3, 2022 "Five people confirmed all of the data, including case details that would be difficult to obtain from any source other than the police. Four more people confirmed basic information such as their names before hanging up," reported the Wall Street Journal. The WSJ's reporter Karen Hao described the experience on Twitter: I was truly stunned when the first person picked up--I really believed the whole thing to be fake. By the third, I was shaking--both from the nerves of trying to explain why I had their extremely private information and the weight of realizing what this leak could mean for so many. -- Karen Hao Hao Ke Ling (@_KarenHao) July 4, 2022 * China orders annual security reviews for all critical information infrastructure operators * Millions of people's info stolen from MGM Resorts dumped on Telegram for free * China puts continuous consent at the center of data protection law * China finds and kills 42,000 counterfeit apps - many of them investment scams While the Shanghai government and police department have largely been silent over the leak, social media platforms Weibo and WeChat were not - at least until Sunday afternoon when users on Weibo began experiencing data leak-related blocked hashtags. On Monday, an unusual voice joined in the analysis of the event: Changpeng Zhao, the CEO of cryptocurrency exchange Binance. [cybercrime] [cybercrime] "CZ" - as he's known - took to Twitter with the following: Our threat intelligence detected 1 billion resident records for sell in the dark web, including name, address, national id, mobile, police and medical records from one asian country. Likely due to a bug in an Elastic Search deployment by a gov agency. This has impact on ... -- CZ Binance (@cz_binance) July 3, 2022 CZ's post came four days after HackerDan's so, while some facts matched, it was unclear if the CEO was referring to a different event. He later tweeted again, this time alleging "this exploit happened because the gov developer wrote a tech blog on CSDN and accidentally included the credentials." Whatever the source of the leak, it will mightily annoy China. The nation's government has recently prioritized personal data protection and critical infrastructure security. If the People's Police have mucked up on both counts, that will not go down well. (r) Get our Tech Resources # Share reddit Twitter Facebook linkedin WhatsApp email [https://www.theregis] Copy 14 Comments Similar topics * China * Cybersecurity * Data Breach * Police Broader topics * APAC * Security Narrower topics * China Mobile * China telecom * China Unicom * Cyberspace Administration of China * Great Firewall * Hong Kong * Interpol * JD.com * RSA Conference * Semiconductor Manufacturing International Corporation * Shenzhen * Uyghur Muslims Corrections Send us news --------------------------------------------------------------------- [cybercrime] Other stories you might like * Carnival Cruises torpedoed by US states, agrees to pay $6m after wave of cyberattacks Now those are some phishing boats Jeff Burt Tue 28 Jun 2022 // 02:58 UTC 18 comment bubble on white Carnival Cruise Lines will cough up more than $6 million to end two separate lawsuits filed by 46 states in the US after sensitive, personal information on customers and employees was accessed in a string of cyberattacks. A couple of years ago, as the coronavirus pandemic was taking hold, the Miami-based biz revealed intruders had not only encrypted some of its data but also downloaded a collection of names and addresses; Social Security info, driver's license, and passport numbers; and health and payment information of thousands of people in almost every American state. It all started to go wrong more than a year prior, as the cruise line became aware of suspicious activity in May 2019. This apparently wasn't disclosed until 10 months later, in March 2020. Continue reading * Beijing probes security at academic journal database It's easy to see why - the question is, why now? Laura Dobberstein Mon 27 Jun 2022 // 05:30 UTC 7 comment bubble on white China's internet regulator has launched an investigation into the security regime protecting academic journal database China National Knowledge Infrastructure (CNKI), citing national security concerns. In its announcement of the investigation, the China Cyberspace Administration (CAC) said: Continue reading * Xi Jinping himself weighs in on how Big Tech should deploy FinTech Beijing also outlines its GovTech vision and gets very excited about data Simon Sharwood, APAC Editor Fri 24 Jun 2022 // 03:29 UTC 11 comment bubble on white China's government has outlined its vision for digital services, expected behavior standards at China's big tech companies, and how China will put data to work everywhere - with president Xi Jinping putting his imprimatur to some of the policies. Xi's remarks were made in his role as director of China's Central Comprehensively Deepening Reforms Commission, which met earlier this week. The subsequent communique states that at the meeting Xi called for "financial technology platform enterprises to return to their core business" and "support platform enterprises in playing a bigger role in serving the real economy and smoothing positive interplay between domestic and international economic flows." The remarks outline an attempt to balance Big Tech's desire to create disruptive financial products that challenge monopolies, against efforts to ensure that only licensed and regulated entities offer financial services. Continue reading * US expands efforts to hamstring China's chipmaking mojo Beijing can't get next-gen lithography gear, America now trying to block sales of older machines Dylan Martin Tue 5 Jul 2022 // 21:12 UTC 1 comment bubble on white The US government is reportedly stepping up efforts to hamper China's ability to grow its semiconductor manufacturing capabilities by pressing for a wider ban on key chipmaking gear. Uncle Sam hopes to convince officials in the Netherlands to block Dutch-native semiconductor equipment maker ASML from selling its older deep ultraviolet lithography (DUV) systems to China, according to a Tuesday report from Bloomberg that cited unnamed sources. US and Dutch officials declined to comment on the report, as did ASML. DUV systems use a less advanced lithography process than ASML's extreme ultraviolet light (EUV) machines that chipmakers are increasingly turning to for leading-edge components coming to the market, such as Apple's homegrown M2 silicon for Macs or Nvidia's H100 datacenter GPU. Continue reading * Biden considers removal of Trump-era China tariffs to ease inflation But US administration split on loss of leverage, according to reports Lindsay Clark Tue 5 Jul 2022 // 13:30 UTC 10 comment bubble on white US president Joe Biden is debating whether to end or cut Trump-era tariffs imposed on Chinese imports into the United States, according to reports. Introduced in 2018 during the Trump administration, tariffs on more than $300 billion in imports from China -- including products and components vital in consumer and business technologies -- were inherited by the Biden administration. According to Bloomberg, president Biden and his cabinet have discussed the inflationary impact of these levies with Treasury Secretary Janet Yellen. The cabinet was looking at all of the possible ways to curb inflation and to provide some relief on cost of living for Americans, the report said. Continue reading * China is trolling rare-earth miners online and the Pentagon isn't happy Beijing-linked Dragonbridge flames biz building Texas plant for Uncle Sam Jessica Lyons Hardcastle Tue 28 Jun 2022 // 22:05 UTC 37 comment bubble on white The US Department of Defense said it's investigating Chinese disinformation campaigns against rare earth mining and processing companies -- including one targeting Lynas Rare Earths, which has a $30 million contract with the Pentagon to build a plant in Texas. Earlier today, Mandiant published research that analyzed a Beijing-linked influence operation, dubbed Dragonbridge, that used thousands of fake accounts across dozens of social media platforms, including Facebook, TikTok and Twitter, to spread misinformation about rare earth companies seeking to expand production in the US to the detriment of China, which wants to maintain its global dominance in that industry. "The Department of Defense is aware of the recent disinformation campaign, first reported by Mandiant, against Lynas Rare Earth Ltd., a rare earth element firm seeking to establish production capacity in the United States and partner nations, as well as other rare earth mining companies," according to a statement by Uncle Sam. "The department has engaged the relevant interagency stakeholders and partner nations to assist in reviewing the matter. Continue reading * China finds and kills 42,000 counterfeit apps - many of them investment scams Constant crackdowns on bad online behavior don't seem to deter crims Laura Dobberstein Mon 4 Jul 2022 // 05:29 UTC 8 comment bubble on white The Cyberspace Administration of China (CAC) announced a crackdown on investment fraud platforms on Friday in conjunction with the country's Ministry of Public Security. "Since the beginning of this year, the Anti-Fraud Center of the CAC has investigated and cracked down on 42,000 counterfeit apps," declared the internet regulator. The CAC said those apps have been added to a database that currently includes around 3.8 million fraud-related websites and 514,000 apps, which have collectively seen it issue over two billion alerts. Continue reading * TikTok: Yes, some staff in China can access US data We thought you guys were into this whole information hoarding thing Thomas Claburn in San Francisco Sat 2 Jul 2022 // 00:30 UTC 18 comment bubble on white TikTok, owned by Chinese outfit ByteDance, last month said it was making an effort to minimize the amount of data from US users that gets transferred outside of America, following reports that company engineers in the Middle Kingdom had access to US customer data. "100 percent of US user traffic is being routed to Oracle Cloud Infrastructure," TikTok said in a June 17, 2022 post, while acknowledging that customer information still got backed up to its data center in Singapore. The biz promised to delete US users' private data from its own servers and to "fully pivot to Oracle cloud servers located in the US." That pivot has not yet been completed. According to a June 30, 2022 letter [PDF] from TikTok CEO Shou Zi Chew, obtained by the New York Times on Friday, some China-based employees with sufficient security clearance can still access data from US TikTok users, including public videos and comments. Continue reading * China rallies support for Kylin Linux in war on Windows openKylin project is latest chapter in Beijing's love-hate relationship with Redmond Tobias Mann Sun 3 Jul 2022 // 09:33 UTC 48 comment bubble on white China's efforts to end its reliance on Microsoft Windows got a boost with the launch of the openKylin project. The initiative aims to accelerate development of the country's home-grown Kylin Linux distro by opening the project up to a broader community of developers, colleges, and universities to contribute code. Launched in 2001, Kylin was based on a FreeBSD kernel and was intended for use in government and military offices, where Chinese authorities have repeatedly attempted to eliminate foreign operating systems. Continue reading * One of the first RISC-V laptops may ship in September, has an NFT hook A notebook with an RV SoC is cool enough. Did we really need the Web3 jargon? Dylan Martin Fri 1 Jul 2022 // 19:59 UTC 25 comment bubble on white It seems promoters of RISC-V weren't bluffing when they hinted a laptop using the open-source instruction set architecture would arrive this year. Pre-orders opened Friday for Roma, the "industry's first native RISC-V development laptop," which is being built in Shenzen, China, by two companies called DeepComputing and Xcalibyte. And by pre-order, they really mean: register your interest. No pricing is available right now, quantities are said to be limited, and information is sparse. Continue reading ABOUT US* * Who we are * Under the hood * Contact us * Advertise with us MORE CONTENT* * Latest News * Popular Stories * Forums * Whitepapers * Webinars SITUATION PUBLISHING* * The Next Platform * DevClass * Blocks and Files * Continuous Lifecycle London * M-cubed Situation Publishing The Register - Independent news and views for the tech community. Part of Situation Publishing SIGN UP TO OUR DAILY NEWSLETTER Subscribe Twitter Facebook LinkedIn feeds no-js Biting the hand that feeds IT (c) 1998-2022 Do not sell my personal information Cookies Privacy Ts&Cs