Log in
Log in
Or log in with
GoogleGoogle
Twitter Twitter
Facebook Facebook
Apple Apple     
Sign up
Or log in with
GoogleGoogle
Twitter Twitter
Facebook Facebook
Apple Apple     
News
All NewsCompaniesIndexesCurrency / ForexCommoditiesCryptocurrenciesETFInterest RatesEconomyThemesSectors 

Hacker offers to sell data of 48.5 million users of Shanghai's COVID app

08/12/2022 | 03:18am EST
FILE PHOTO: COVID-19 lockdown lifted in Shanghai

BEIJING (Reuters) - A hacker has claimed to have obtained the personal information of 48.5 million users of a COVID health code mobile app run by the city of Shanghai, the second claim of a breach of the Chinese financial hub's data in just over a month.

The hacker with the username as "XJP" posted an offer to sell the data for $4,000 on the hacker forum Breach Forums on Wednesday.

The hacker provided a sample of the data including the phone numbers, names and Chinese identification numbers and health code status of 47 people.

Eleven of the 47 reached by Reuters confirmed that they were listed in the sample, though two said their identification numbers were wrong.

"This DB (database) contains everyone who lives in or visited Shanghai since Suishenma's adoption," XJP said in the post, which originally asked for $4,850 before lowering the price later in the day.

Suishenma is the Chinese name for Shanghai's health code system, which the city of 25 million people, like many across China, established in early 2020 to combat the spread of COVID-19. All residents and visitors have to use it.

The app collects travel data to give people a red, yellow or green rating indicating the likelihood of having the virus and users have to show the code to enter public venues.

The data is managed by the city government and users access Suishenma via the Alipay app, owned by fintech giant and Alibaba affiliate Ant Group, and Tencent Holdings' WeChat app.

XJP, the Shanghai government, Ant and Tencent did not immediately respond to requests for comment.

The purported Suishenma breach comes after a hacker early last month said they had procured 23 terabytes of personal information belonging to one billion Chinese citizens from the Shanghai police.

That hacker also offered to sell the data on Breach Forums.

The Wall Street Journal, citing cyber security researchers, said the first hacker had been able to steal the data from the police as a dashboard for managing a police database had been left open on the public internet without password protection for more than a year.

The newspaper said data was hosted on Alibaba's cloud platform and Shanghai authorities had summoned company executives over the matter.

Neither the Shanghai government, nor police nor Alibaba have commented on the police database matter.

(Reporting by Eduardo Baptista and the Shanghai newsroom; Writing by Brenda Goh; Editing by Robert Birsel)

By Eduardo Baptista


ę Reuters 2022
Stocks mentioned in the article
ChangeLast1st jan.
ALIBABA GROUP HOLDING LIMITED 4.79% 90.06 Delayed Quote.-24.19%
TENCENT HOLDINGS LIMITED 0.54% 296 Delayed Quote.-35.20%
Latest news "Economy"
05:01aMagnitude 6.4 quake hits Indonesia's West Java
RE
04:49aThree Arrows Capital says its founders still not cooperating with asset recovery
RE
04:44aKherson officials ease river crossings from Russian-held territory
RE
04:41aRenault and Nissan forgo Wednesday announcement of alliance deal -media
RE
03:57aIndian state will proceed 'no matter what' with protest-hit Adani port-minister
RE
03:54aRussia: price cap is 'dangerous' and will not curb demand for our oil
RE
03:51aAT&T to pay $6 million to SEC to settle lawsuit over leaks to analysts-court filing
RE
03:51aIndia kerala state minister says he won't order construction hal…
RE
03:51aIndia's kerala state hopeful of resolving deadlock with proteste…
RE
03:43aEx-South Korean official arrested over case of man slain by North Korea
RE
Latest news "Economy"