Menu
Browse

Shanghai Municipal Public Security Bureau

Aliases: 2 aliases
Primary URL Location Industry
gaj[.]sh[.]gov[.]cn
Country China
Government - Local Icon
Government - Local
Profile

The Shanghai Municipal Public Security Bureau, also known as the Shanghai National Police (SHGA) or Shanghai Police, is a governmental law enforcement agency operating within China. Its core responsibilities involve maintaining public order, preventing and investigating crime, and enforcing laws and regulations within the Shanghai municipality. As a key component of China's public security apparatus, the bureau handles sensitive citizen data integral to its duties, including personal identification details, contact information, addresses, and criminal records. This function places it within the critical infrastructure sector responsible for citizen security and data management at a municipal level.

The agency gained significant international attention following a major cybersecurity incident in July 2022. A threat actor using the alias 'ChinaDan' claimed to have successfully breached the bureau's systems, exfiltrating approximately 22 terabytes of highly sensitive data allegedly pertaining to one billion Chinese citizens. The compromised information reportedly included names, national ID numbers, addresses, contact details, and criminal records. The hacker offered this vast dataset for sale on the dark web, providing a sample of 750,000 records for potential buyers to verify authenticity. Some individuals reportedly confirmed the accuracy of their personal information within this sample. Initial technical analysis suggested the breach originated from an improperly secured ElasticSearch database instance hosted on Alibaba Cloud, potentially compromised due to exposed credentials published in a technical blog post by a government developer. While the full extent and ultimate verification of the claimed one billion records remain unconfirmed by independent sources, this incident represents one of the largest alleged compromises of sensitive government-held citizen data globally, highlighting the significant data stewardship role inherent to the bureau's law enforcement mandate.

Incidents
Linked incidents available to members
1 incident