惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
GbyAI
GbyAI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Apple Machine Learning Research
Apple Machine Learning Research
大猫的无限游戏
大猫的无限游戏
阮一峰的网络日志
阮一峰的网络日志
Last Week in AI
Last Week in AI
V
Visual Studio Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
The Cloudflare Blog
博客园 - 【当耐特】
博客园 - 叶小钗
量子位
博客园 - 聂微东
S
SegmentFault 最新的问题
美团技术团队
Hugging Face - Blog
Hugging Face - Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
月光博客
月光博客
宝玉的分享
宝玉的分享
小众软件
小众软件
罗磊的独立博客
有赞技术团队
有赞技术团队
Stack Overflow Blog
Stack Overflow Blog

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
UK Biobank Data Breach: Health Data of 500,000 Listed for...
Danny Palmer · 2026-04-24 · via www.infosecurity-magazine.com

The personal health data of over half a million UK Biobank volunteers has been put up for on e-commerce platforms and online marketplaces in China, following a data beach at the scientific research organization.

In a statement made to the House of Commons, the Minister for Digital Government and Data, Ian Murry, confirmed the breach.

“Biobank told us that three listings that appear to sell UK Biobank participant data had been identified. At least one of these three datasets appears to contain data from all 500,000 UK Biobank volunteers,” he said.

Murray told the Commons that Biobank informed the government that the data about their volunteers had been advertised for sale by several dealers on Alibaba e-commerce platforms in China.

The listings have since been removed and both the government and UK Biobank believe that nobody purchased the leaked data.

The UK Biobank collects data to support thousands of scientific research papers. The data gathered includes whole body scans, DNA sequences and other, sensitive medical records.

However, UK Biobank stressed that the breach didn’t contain personal information about participants, such as their names, addresses, contact details, telephone numbers or NHS Numbers.

“We understand that the existence of these listings, even temporarily, will be concerning to you. We want to reassure you that all the data are de-identified; they do not contain any personally identifying information,” said Professor Sir Rory Collins, chief executive and principal investigator of UK Biobank.

The data breach has been traced to researchers at three academic institutions who had misused their access to the data.

Collins described their actions as a “clear breach” of the contract the institutions signed, and both the researchers and the institutions have had their access to the project suspended.

“Researchers are required to do their research on our restricted, cloud-based research platform hosted in the UK to prioritise the safe and secure use of your data. In light of this incident, we are taking further steps to enhance our systems to prevent this from happening again,” he said in a statement published on April 23.

In reaction to the incident, UK Biobank has temporarily suspended all access to the research platform and is set to implement strict limits on the number of files which can be downloaded by users.

The organization added that it will conduct a “comprehensive and forensic” board-led investigation of the incident. UK Biobank also noted that it was “grateful” for the support from the UK government, as well as the “rapid co-operation” of Chinese authorities and Alibaba to remove the data.