A dark web seller has advertised a dataset allegedly containing personal information on about 15 million people in Kazakhstan, claiming the data was stolen from the country’s eGov platform. Reports said the archive was offered for roughly 0.5 bitcoin—about $32,000—and was described as a 2.7 GB file with 47 million rows. The listing allegedly included passport details, phone numbers, email addresses, employment information, website passwords, and document scans, although key elements of that description have not been independently verified.
Kazakhstan’s Ministry of Artificial Intelligence and Digital Development said it is examining the claim but has found no confirmed evidence so far that government e-services were breached or that the data originated directly from eGov. Officials said specialists are analyzing samples and cautioned that large databases sold online can be assembled from older leaks and multiple sources. The alleged sale comes after other major personal-data exposures in Kazakhstan, including a 2025 incident affecting more than 16 million records and another 2026 case involving a seized database, intensifying scrutiny of data protection as the country expands digital public services.

See attribution, scope, and your downstream exposure.
9 events from the most recent confirmed update back to the earliest known activity.
Two months before the current allegation, police seized another large database containing personal information on nearly 16 million Kazakhstanis from employees of a collection agency in the Zhetysu region. The references say it is not known whether that dataset is connected to the newly advertised one.
In April 2026, Kazakhstan’s National Security Committee said the criminal case related to the 2025 leak remained under investigation. It disclosed no further details, citing confidentiality.
In September 2025, Kazakhstan’s Ministry of Digital Development, Innovation, and Aerospace Industry was rebranded as the Ministry of Artificial Intelligence and Digital Development. This changed the ministry name used in later official statements on data-leak allegations.
In July 2025, Kazakh government officials said inspections found no breaches of government information systems related to the June 2025 leak. They said the circulating database contained outdated information current as of 2022 and was compiled from previous leaks, partly supplemented by users with official access.
Kazakhstan’s Ministry of Digital Development, Innovation, and Aerospace Industry announced an investigation into the June 2025 leak of citizen data. The probe followed public reporting that millions of records were circulating online.
Earlier in June 2025, Kazakh authorities detained a network of more than 140 people allegedly involved in selling personal data via Telegram. The references do not state whether this action was directly tied to the later-reported June 2025 archive.
In June 2025, the SecuriXy.kz Telegram channel reported that an archive containing data on 16.3 million Kazakhstani citizens had leaked and was posted on a hacker forum for free download as “Residents of Kazakhstan 2024.” The archive reportedly included identification numbers, phone numbers, names, dates of birth, and addresses.
Kazakhstan’s Ministry of Artificial Intelligence and Digital Development said a preliminary review found no confirmed evidence that government e-services were breached or that the advertised database came directly from eGov. The ministry said specialists were analyzing samples and noted inconsistencies between the seller’s description and eGov’s data structure.
A dataset allegedly containing personal information on 15 million people in Kazakhstan was advertised for sale on the dark web for about $32,000 or 0.5 bitcoin. The seller claimed the data came from a hack of Kazakhstan’s eGov service and described the file as containing passport details, phone numbers, email addresses, passwords, and document scans.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.