惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
D
Darknet – Hacking Tools, Hacker News & Cyber Security
P
Proofpoint News Feed
Spread Privacy
Spread Privacy
C
Cisco Blogs
L
Lohrmann on Cybersecurity
宝玉的分享
宝玉的分享
I
Intezer
aimingoo的专栏
aimingoo的专栏
Cisco Talos Blog
Cisco Talos Blog
The Register - Security
The Register - Security
GbyAI
GbyAI
C
CERT Recently Published Vulnerability Notes
Apple Machine Learning Research
Apple Machine Learning Research
U
Unit 42
Cyberwarzone
Cyberwarzone
爱范儿
爱范儿
I
InfoQ
博客园_首页
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
量子位
P
Palo Alto Networks Blog
Microsoft Azure Blog
Microsoft Azure Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
有赞技术团队
有赞技术团队
T
Tailwind CSS Blog
腾讯CDC
阮一峰的网络日志
阮一峰的网络日志
NISL@THU
NISL@THU
T
Threatpost
T
The Blog of Author Tim Ferriss
云风的 BLOG
云风的 BLOG
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
S
Schneier on Security
Security Latest
Security Latest
Martin Fowler
Martin Fowler
H
Help Net Security
小众软件
小众软件
The Hacker News
The Hacker News
Know Your Adversary
Know Your Adversary
博客园 - 司徒正美
人人都是产品经理
人人都是产品经理
T
The Exploit Database - CXSecurity.com
Jina AI
Jina AI
Engineering at Meta
Engineering at Meta
The GitHub Blog
The GitHub Blog
P
Proofpoint News Feed
IT之家
IT之家
WordPress大学
WordPress大学
S
Securelist

The Register - Security: Cyber-crime

Election interlopers register 5K+ domains, hope to catch some voting phish Palo Alto VPN bug graduates from advisory to active exploitation ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak Carnival confirms ShinyHunters cruised off with 6M customer records after April breach CrowdStrike, Google shatter Glassworm botnet MyPillow must decide whether to be firm or soft as ransomware crims demand pay A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Shai-Hulud copycat worm infects yet another npm package Grafana Labs admits all its codebase are belong to someone who popped its GitHub account Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files Cache-poisoning caper turns TanStack npm packages toxic 'CopyFail' attackers start cashing in on Linux flaw Cushman & Wakefield confirms vishing cyberattack ShinyHunters claims dump puts 119K Vimeo emails in the wild ShinyHunters claims 119K Vimeo emails in the wild Critical cPanel exploited: 'Millions' of sites could be hit Pro-Iran group turns Ubuntu DDoS into shakedown French prosecutors link 15-year-old to gov mega-breach UK business breach rate stuck at 43%... blame the phishing What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia Chinese spy group caught lurking in Poland, Asia networks Don’t pay VECT a ransom - your big files are likely gone Pitney Bowes the latest victim of ShinyHunters’ breach-spree Ongoing supply-chain attack targets security, dev tools Medical and utility tech companies admit digital breakins Burglar alarm biz gets burgled, ShinyHunters pursues ransom Crime crew impersonates help desk, abuses Teams chats ShinyHunters claim they have cruise giant Carnival’s booty CISA, NCSC issue Firestarter backdoor warning Another npm supply chain worm hits dev environments France's 'Secure' ID agency probes breach as crooks claim 19M records France's 'Secure' ID agency probes claimed 19M record breach macOS ClickFix attacks deliver AppleScript stealers to snarf credentials, wallets macOS ClickFix attacks deliver AppleScript stealers Yet another ex-ransomware negotiator admits turning rogue after payoff from crimelords Third ransomware pro pleads guilty to cybercrime U-turn AI-assisted intruders pwned Vercel via OAuth abuse and a pilfered employee account AI-pwned: Vercel breach traced to stolen employee creds Crook claims to leak 'video surveillance footage' of companies Crook claims to leak 'video surveillance footage' of firms Adaptavist Group breach spawns imposter emails as ransomware crew claims mega-haul Adaptavist Group breach: Ransomware crew claims mega-haul Scot becomes second Scattered Spider-linked crook to plead guilty in US US gets second Scattered Spider-linked guilty plea North Korea targets macOS users in latest heist McGraw Hill linked to 13.5M-record data leak McGraw Hill linked to 13.5M-record data leak Autovista blames ransomware for service disruption Autovista blames ransomware for service disruption No honor among thieves as 0APT threatens rival ransomware gang Krybit 0APT ransomware gang extorts Krybit amid doxxing threat Fake Linux leader using Slack to con devs into giving up their secrets Fake Linux Foundation leader using Slack to phish devs Booking.com warns of possible reservation data exposure Booking.com warns of possible reservation data exposure Gym giant Basic-Fit breached with at least 1M affected US, UK, Canadian cops disrupt $45M global crypto scam www.theregister.com Old Adobe Reader zero-day uses PDFs to size up targets Zephyr Energy loses £700K to contractor payment fraud Russia's Fancy Bear still attacking routers to boost fake sites, NCSC warns Russia's APT28 behind latest wave of router, DNS attacks AI recruiting biz Mercor says it was 'one of thousands' hit in LiteLLM supply-chain attack Mercor says it was 'one of thousands' hit in LiteLLM attack Telnyx package latest hit in PyPI supply-chain compromise Telnyx package latest hit in PyPI supply-chain compromise European Commission admits breach of public web systems European Commission admits breach of public web systems AFC Ajax drops ball as hackers transfer tickets, lift bans AFC Ajax drops ball as hackers transfer tickets, lift bans HackerOne slams supplier for delayed breach notice after staff data exposed HackerOne slams supplier over delayed breach notice Russian initial access broker jailed for 81 months in US Russian initial access broker jailed for 81 months in US Smooth criminals talking their way into cloud environments, Google says Chip tester shrugged off ransomware – then came the leak Chip tester shrugged off ransomware – then came the leak Russians posing as Signal support to launch phishing raids JLR cyber bailout risks dangerous precedent, watchdog warns Unknown attackers exploit yet another critical SharePoint bug Microsoft Intune: Lock it down, warn feds after Stryker Ransomware crims abused Cisco 0-day weeks before disclosure North Korea's 100,000-strong fake IT worker army rake in $500M a year for Kim Jong Un Robotics surgical biz Intuitive discloses phishing attack Cybercrime up 245% since the start of the Iran war AI-driven fraud far more profitable, Interpol warns Credential-stealing crew spoofs Ivanti, Fortinet, Cisco VPNs Interpol sinkholes 45,000 IPs linked to global cybercrime SocksEscort fraud-enabling proxy service taken down CISA warns max-severity n8n bug is being exploited in the wild Iran-linked cyber crew claims hit on US med-tech firm Meta, cops deploy AI and handcuffs in scam crackdown Dutch police collar teen over string of bank card frauds EU law advisor wants cybercrime protections fast-tracked Cybercrime isn't just a cover for Iran's government goons Crooks compromise WordPress sites, spread infostealers Ericsson breach blamed on third party vendor vishing attack Polish cyber police busts gang of alleged teen DDoS peddlers
500k Biobank volunteers' data listed for sale on Alibaba
Connor Jones Connor Jones · 2026-04-23 · via The Register - Security: Cyber-crime

UPDATED Details of volunteers of UK-based Biobank, which describes itself as the custodian of the world's most comprehensive biomedical dataset, are for sale on Chinese ecommerce site Alibaba.

The organization confirmed the data on roughly half a million volunteers was anonymized, but could not guarantee it would be impossible to identify individuals if it fell into the wrong hands.

The revelation came from UK technology minister Ian Murray speaking in the House of Commons on Thursday, with his comments delivered at the same time as Biobank confirming the data mishap.

Updated to add at 1525 April 23:

Three Chinese research institutions have been banned from UK Biobank's platform after the data belonging to half a million volunteers was listed for sale on Chinese e-commerce site Alibaba.

UK Biobank is a charity that runs the eponymous research project. It describes itself as the custodian of the world's most comprehensive biomedical dataset that's used by medical researchers globally.

The charity confirmed to the UK government on April 20 that three separate listings of data, one of which contained data belonging to all 500,000 UK participants, were listed for sale online by an unknown source. The revelation came from UK technology minister Ian Murray addressing the House of Commons on Thursday, with his comments delivered at the same time as UK Biobank confirming the data mishap via its website.

Both Murray and UK Biobank said the data was anonymized, but could not be wholly certain that it couldn't be used to identify individuals if it ended up in the wrong hands. Investigations into the abuse of data are ongoing, but there is currently no evidence to suggest that the data was bought or downloaded. Murray said that the Chinese government was heavily influential in supporting the takedown of the listings, as was Alibaba.

"I want to thank the Chinese government for the speed and seriousness with which they worked with us to help remove these listings and the ongoing work to remove any further listings," said Murray.

The tech minister added that although the three institutions from which the data was derived were Chinese, this fact alone makes no suggestions about the intent behind the data's listing.

UK Biobank revoked the accreditation of the three research institutions, meaning they can no longer access the charity's platform or its data, but other institutions, such as Yale University, have also previously had their access revoked for "a breach of data," Murray confirmed.

A root cause analysis remains ongoing, although the current thinking is that the three Chinese institutions downloaded the bulk UK Biobank dataset to local storage, and through means yet to be identified, the data was listed for sale on Alibaba.

In 2024, UK Biobank changed the way accredited institutions access volunteers' data. It previously handed bulk datasets to said institutions for research purposes, but changed access models to one where only UK Biobank stored the data, and accredited researchers were then given logins to access the UK Biobank platform. Researchers carried out their required data analysis on the UK Biobank platform and downloaded the results of that analysis, not the data that informed it.

"What the system also allowed you to do, although you were contractually as an accredited organization not supposed to do, is download the datasets," Murray told the Commons.

"We understand from UK Biobank that this is probably what happened here - those three institutions have downloaded the datasets themselves, and we are yet unclear about how those data sets have ended up on that website, but the UK Biobank and institutions and organizations attached to government are working through that at the moment."

UK Biobank's response

UK Biobank said that the data listed for sale contained no personally identifiable information, such as names of the volunteers, their addresses, phone numbers, or NHS numbers, and expressed its gratitude to the authorities that helped remove the listings.

The charity did not specify the types of data that were included, but Murray stated in the Commons that several markers were included in the listings:

  • Gender
  • Age
  • Month and year of birth
  • Assessment center data
  • Attendance dates
  • Socioeconomic status
  • Lifestyle habits
  • Measures from biological samples related to haematology, biology, and chemistry
  • Sleep, diet, work environment, mental health, and health outcomes data.

UK Biobank told the government that it could not be 100 percent sure that the data could be used to identify a volunteer, but it would require highly advanced interpretations of the data to do so.

In a statement issued on Thursday, UK Biobank said it had introduced a number of security improvements in the wake of the findings. "We have temporarily suspended all access to the UK Biobank research platform, while we put in place a strict limit on the size of files that can be taken off the platform," said Professor Sir Rory Collins, CEO and principal investigator of UK Biobank.

"This measure will allow researchers to export the results of their research, while severely limiting their ability to take any de-identified participant data off the platform. In addition, all files exported from the research platform will be monitored daily for any suspicious behavior. These security measures will further minimize the potential for misuse of UK Biobank data. In addition, we will conduct a comprehensive and forensic board-led investigation of this incident.

"We are developing the world's first automated checking system able to prevent de-identified participant data from being taken off the UK Biobank research platform, without preventing the important research that is being done by thousands of scientists around the world. We intend to have this automated system in place around the end of this year."

UK Biobank launched its project in 2012, and the anonymized data it provides experts (institutions in Russia, Iran, and North Korea are banned) informs leading medical research into conditions such as dementia, cancer, Parkinson's disease, chronic pain, COVID-19 immunity, and more.

Despite the "unacceptable abuse" of medical data in this case, the UK expects UK Biobank to be the world's leading provider of biomedical data for research institutions going forward.

The charity reported the incident to the UK government on April 20 and reported itself to the Information Commissioner's Office shortly after.

"People's medical data is highly sensitive information, not only do people expect it to be handled carefully and securely, organizations also have a responsibility under the law," an ICO spokesperson told The Register.

"UK Biobank has made us aware of an incident and we are making enquiries."The Register contacted Alibaba for more information. ®