De-identified medical and genomic data linked to up to 500,000 UK Biobank volunteers was advertised for sale in three listings on Alibaba, prompting a UK government response and an ongoing investigation. Officials said the exposure did not result from an external hack but from a legitimate download by accredited research institutions, with three institutions identified as the source of the postings.
The exposed dataset reportedly included sensitive health, genetic, demographic, socioeconomic, and lifestyle information, raising concerns that individuals could still be re-identified when combined with other data. Alibaba and Chinese authorities removed the listings before any sales were confirmed, while UK Biobank revoked the institutions’ access, temporarily suspended wider access to its research platform, and referred itself to the UK Information Commissioner's Office.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Following the discovery of UK Biobank data listings on Alibaba, the organization said it imposed stricter controls on data exports from its UK-hosted cloud research platform. The measure accompanied its forensic investigation and suspensions of the implicated institutions and individuals.
UK officials publicly disclosed the exposure and said an investigation was underway. UK Biobank also referred itself to the UK Information Commissioner's Office as scrutiny increased over foreign access to genomic data.
Alibaba and the Chinese government cooperated to remove the listings before any sales occurred. UK Biobank identified three institutions as the source of the postings, revoked their access, and temporarily suspended broader access to its research platform.
De-identified medical and genomic data from UK Biobank covering up to 500,000 British volunteers was found advertised for sale in three listings on Alibaba. UK officials said the exposure resulted from a legitimate download by accredited research institutions rather than an external hack.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
bankinfosecurity.com
Open sourcetechrepublic.com
Open sourcescworld.com
Open sourcemalwarebytes.com
Open sourceteiss.co.uk
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.