:

UK BIOBANK DATA REPEATEDLY LEAKED ON GITHUB

DEV DESK1 MIN READ
FRI, APR 24, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Researchers have tracked 110 DMCA takedown notices targeting 197 code repositories containing UK Biobank health data. The exposures reveal ongoing governance challenges for the major health research initiative.

A privacy researcher monitoring Digital Millennium Copyright Act notices found that sensitive UK Biobank data has been repeatedly uploaded to GitHub by developers across 170 accounts worldwide. The instances represent the latest in a series of data handling issues for UK Biobank, a repository of health records and genetic information from 500,000 British participants used for medical research. The leaked repositories contained portions of the biobank's dataset, which researchers access for studies but are bound by data usage agreements. The repeated uploads suggest either accidental commits or misunderstandings about data sharing restrictions. GitHub has been removing the repositories following takedown notices, but the pattern indicates a systemic problem. Researchers and the institution have published commentary in the British Medical Journal highlighting the governance gaps. The exposures underscore broader challenges in managing sensitive health data as research becomes increasingly collaborative and code-sharing platforms grow more prevalent in academic work.

■ SOURCES

Hacker News

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Authorities have arrested two alleged members of TeamPCP, a hacking group responsible for infecting over 1,000 organizations through supply-chain attacks.

1H AGOSecurity Desk

A Georgia police officer used Flock surveillance technology to track the movements of his ex-partner and another officer after their affair ended, according to internal investigation records.

1H AGOIndustry Desk

McKesson, a major healthcare and pharmaceutical distributor, confirmed a cybersecurity incident involving unauthorized access to third-party applications. Extortion group ShinyHunters claims responsibility for stealing 284 million patient data records.

1H AGOAI Desk

Fraudsters are exploiting Microsoft Teams and similar enterprise chat apps to deceive Chinese users into sending large sums of money. The trend has sparked a wave of complaints across the region.

5H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.