Half a million confidential health records from UK Biobank participants were advertised for sale on Chinese e-commerce site Alibaba last week. The UK government has confirmed the listings and says the data has been removed with no evidence of sales.
The data breach affects volunteers in the UK Biobank, a long-running health research project that collects genetic and medical information from British participants. Three separate listings offering the records appeared on Alibaba before being taken down.
Technology minister Penny Mordaunt confirmed the incident to Parliament, noting the information was described as "de-identified"—meaning personal names and identifiers had been removed. However, the listings still contained sensitive health and genetic data that could potentially be used to identify individuals when combined with other datasets.
UK Biobank is a publicly-funded research initiative storing biological samples and health information from over 500,000 volunteers. The project supports medical research into diseases including cancer, heart disease, and diabetes. Participants agreed to have their data used for approved research purposes only.
Investigators are now working to determine how the data reached Alibaba and who attempted to sell it. The government has not disclosed whether a breach of UK Biobank's systems occurred or if data was obtained through another route. Initial findings suggest the records may have been de-identified before being listed, potentially lowering their immediate commercial value.
This incident raises fresh concerns about data security in health research. While de-identification is intended to protect privacy, research has shown that genetic data can sometimes be re-identified through cross-referencing with public databases. The UK's Information Commissioner's Office is expected to investigate the matter.
Alibaba removed the listings after being contacted by UK authorities. The company stated it has zero tolerance for illegal activities on its platform. No formal criminal investigation has been announced, though authorities are examining whether any laws were broken under UK data protection regulations.
The Department of Homeland Security is leveraging a little-known legal provision to request records from journalists, non-profits, and unions, according to reporting from The Guardian. The tactic raises concerns about surveillance overreach and First Amendment protections.
Major artificial intelligence companies have issued urgent warnings that a significant cybersecurity threat could materialize within months. The alert comes as hackers continue targeting critical infrastructure across the United States.
Authorities have arrested two alleged members of TeamPCP, a hacking group responsible for infecting over 1,000 organizations through supply-chain attacks.
A Georgia police officer used Flock surveillance technology to track the movements of his ex-partner and another officer after their affair ended, according to internal investigation records.