Trending

ee-track">
Link copied!

200 million+ Records of Chinese Citizens for Sale on the Darkweb

During our routine Dark web monitoring, the Research team at Cyble found multiple posts where the Threat Actors are selling alleged data leaks related to Chinese citizens. The alleged leaks could be related to Gongan…

January 3, 2021 · 2 min read

During our routine Dark web monitoring, the Research team at Cyble found multiple posts where the Threat Actors are selling alleged data leaks related to Chinese citizens. The alleged leaks could be related to Gongan County, Weibo, and QQ as shared by the actors in the posts.

  1. Gong’an County is in southern Hubei province, People’s Republic of China, bordering Hunan to the south. It is under the administration of Jingzhou City.

Sample data of alleged 999 household registrations of Chinese citizens from Gong’an county was shared as proof.

gongan1

 After the analysis of sample data by our researchers, it was noticed that –

  • Id
  • Sex
  • Name
  • Birth
  • Mobile
  • Address, and
  • Code number

of 7.3 million Chinese citizens are available for sale.

gongan2

2. Weibo is a platform based on fostering user relationships to share, disseminate and receive information. Through either the website or the mobile app, users can upload pictures and videos publicly for instant sharing, with other users being able to comment with text, pictures and videos, or use a multimedia instant messaging service. The threat actor was selling 41.8 million records on a Russian-speaking cybercrime forum. Screenshot shared below –

weibo

During the analysis of the sample data, it was noticed that the weibo_id and respective mobile number were listed in an excel sheet. The threat actor is selling details of 41.8 Million chinese users on the darkweb

report-ad-banner
Sample data

3. QQ is an instant messaging software service and web portal developed by the Chinese tech giant Tencent. QQ offers services that provide online social games, music, shopping, microblogging, movies, and group and voice chat software. The threat actor is selling details of 192 Million Chinese users on the darkweb

Sample data

During the analysis of the sample data, it was noticed that the qq number and respective mobile number were listed in an excel sheet.

qq number and respective mobile number

Here are a few ways to prevent cyber-attacks:

About Cyble

Cyble is a global threat intelligence SaaS provider that helps enterprises protect themselves from cybercrimes and exposure in the darkweb. Cyble’s prime focus is to provide organizations with real-time visibility into their digital risk footprint. Backed by Y Combinator as part of the 2021 winter cohort, Cyble has also been recognized by Forbes as one of the top 20 Best Cybersecurity Startups To Watch In 2020. Headquartered in Alpharetta, Georgia, and with offices in Australia, Singapore, and India, Cyble has a global presence. 

AI Threat Intelligence

Stop Executive Threats
Before They Strike

Monitor dark web chatter, detect lookalike domains, and protect your C-suite from targeted impersonation — in real time, across 50+ countries.

Scroll to Top

Book your session

Request a Personalized Demo

See how Cyble's threat intelligence protects your organization. A specialist will reach out within one business day.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams

Download the brochure

Get the Cyble Vision Brochure

Explore how Cyble Vision delivers AI-powered threat intelligence across your attack surface. Fill in your details to access the brochure.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams