UK officials said de-identified health and biological data linked to about 500,000 UK Biobank volunteers was advertised for sale in three Alibaba listings, prompting parliamentary disclosure and a public confirmation from the biomedical research repository. Authorities said the exposed records did not include direct identifiers such as names, addresses, or contact details, but warned that misuse could still create a risk of re-identification. The listings were removed after the UK government said it worked with UK Biobank, Alibaba, and Chinese authorities, and officials said they did not believe any data had been sold.
The government said the exposed dataset appears to have originated from legitimate downloads by accredited research institutions, not from a direct intrusion into UK Biobank’s own systems. In response, UK Biobank revoked access for three research institutions, paused further data access, took its research platform offline for security upgrades, and referred itself to the Information Commissioner’s Office. The incident has intensified criticism of UK Biobank’s long-standing practice of allowing researchers to download datasets to local environments, with officials reportedly describing its security controls as lax.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
In response to the exposure, UK Biobank revoked access for three research institutions, paused further data access, took its research platform offline for upgrades, and referred itself to the Information Commissioner's Office.
Three Alibaba listings offering the UK Biobank dataset were taken down after the UK government worked with UK Biobank, Alibaba, and the Chinese government. Authorities said they did not believe any sale had taken place before removal.
UK Technology Minister Ian Murray said the government was informed on 2026-04-29 that de-identified UK Biobank data tied to about 500,000 volunteers had been advertised for sale online. Officials later said the data appeared to have come from legitimate researcher downloads rather than an external intrusion.
Ian Murray disclosed in the House of Commons that de-identified health and biological data relating to roughly 500,000 UK Biobank volunteers had been offered for sale on Alibaba. UK Biobank simultaneously confirmed the incident and acknowledged re-identification risks if the data were misused.
On 2026-04-21, reporting revealed that a Discord-linked private forum had obtained unauthorized access to Anthropic's Mythos Preview. Anthropic publicly confirmed it was investigating and said it had found no evidence that its internal systems were affected.
On the same day Mythos was announced, a small unauthorized group allegedly gained access through a third-party vendor environment using shared contractor access, API keys, and inferred model URL patterns. Reporting said the group continued using the model after obtaining access.
Anthropic announced Claude Mythos Preview on 2026-04-07 as a tightly controlled cybersecurity-focused AI model made available only to a limited group of partners because of concerns it could be weaponized if broadly released.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcedatabreaches.net
Open sourcehackread.com
Open sourcecybersecuritynews.com
Open sourceeuronews.com
Open sourcetheguardian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.