UK BIOBANK DATA OF 500K BRITONS LISTED FOR SALE ON ALIBABA
INDUSTRY DESK■ 2 MIN READ
THU, APR 23, 2026■ AI-SUMMARIZED FROM 1 SOURCE BELOW
Half a million confidential health records from UK Biobank participants were advertised for sale on Chinese e-commerce site Alibaba last week. The UK government has confirmed the listings and says the data has been removed with no evidence of sales.
The data breach affects volunteers in the UK Biobank, a long-running health research project that collects genetic and medical information from British participants. Three separate listings offering the records appeared on Alibaba before being taken down.
Technology minister Penny Mordaunt confirmed the incident to Parliament, noting the information was described as "de-identified"—meaning personal names and identifiers had been removed. However, the listings still contained sensitive health and genetic data that could potentially be used to identify individuals when combined with other datasets.
UK Biobank is a publicly-funded research initiative storing biological samples and health information from over 500,000 volunteers. The project supports medical research into diseases including cancer, heart disease, and diabetes. Participants agreed to have their data used for approved research purposes only.
Investigators are now working to determine how the data reached Alibaba and who attempted to sell it. The government has not disclosed whether a breach of UK Biobank's systems occurred or if data was obtained through another route. Initial findings suggest the records may have been de-identified before being listed, potentially lowering their immediate commercial value.
This incident raises fresh concerns about data security in health research. While de-identification is intended to protect privacy, research has shown that genetic data can sometimes be re-identified through cross-referencing with public databases. The UK's Information Commissioner's Office is expected to investigate the matter.
Alibaba removed the listings after being contacted by UK authorities. The company stated it has zero tolerance for illegal activities on its platform. No formal criminal investigation has been announced, though authorities are examining whether any laws were broken under UK data protection regulations.
■ MORE FROM THE SECURITY DESK
Apple has patched a vulnerability that retained Signal message data even after users deleted the app, potentially allowing law enforcement to access private communications. Signal confirmed the fix resolves the security issue.
1H AGO— Industry Desk
The Trump administration says it has evidence of large-scale industrial distillation campaigns by Chinese actors targeting American AI models. The government is now moving to counter the threat.
1H AGO— AI Desk
Attackers compromised Bitwarden's command-line interface as part of an ongoing campaign targeting Checkmarx users. The malicious code was injected into the package repository, affecting developers using the tool.
3H AGO— AI Desk
Health records from half a million British research participants have been compromised and listed for sale on an Alibaba marketplace. The data belongs to individuals enrolled in UK studies on aging and disease.
3H AGO— Security Desk