Advertisement
UK markets close in 3 hours 4 minutes
  • FTSE 100

    7,499.41
    +45.66 (+0.61%)
     
  • FTSE 250

    18,297.46
    +63.99 (+0.35%)
     
  • AIM

    715.15
    +1.37 (+0.19%)
     
  • GBP/EUR

    1.1617
    +0.0027 (+0.23%)
     
  • GBP/USD

    1.2643
    +0.0015 (+0.12%)
     
  • Bitcoin GBP

    30,373.58
    +452.88 (+1.51%)
     
  • CMC Crypto 200

    795.63
    +11.98 (+1.53%)
     
  • S&P 500

    4,567.80
    +17.22 (+0.38%)
     
  • DOW

    35,950.89
    +520.47 (+1.47%)
     
  • CRUDE OIL

    75.39
    -0.57 (-0.75%)
     
  • GOLD FUTURES

    2,055.90
    -1.30 (-0.06%)
     
  • NIKKEI 225

    33,431.51
    -55.38 (-0.17%)
     
  • HANG SENG

    16,830.30
    -212.58 (-1.25%)
     
  • DAX

    16,325.31
    +109.88 (+0.68%)
     
  • CAC 40

    7,329.13
    +18.36 (+0.25%)
     

Online store exposed millions of Chinese citizen IDs

Image Credits: Fan Jun / Xinhua / Getty Images

A security researcher said he discovered millions of Chinese citizen identity numbers spilling online after an e-commerce store left its database exposed to the internet.

Viktor Markopoulos, a security researcher working for CloudDefense.ai, said he found the database belonging to Zhefengle, a China-based e-commerce store for importing goods from overseas.

The database contained more than 3.3 million orders spanning 2015 through 2020, Markopoulos said, but had not been protected with a password.

The order database contained corresponding customer shipping addresses and phone numbers, as well as the customer's government-issued resident identity card number. Many of the orders also include uploaded copies of the customer's identity card, TechCrunch has seen.

Customers who import goods to China must have their identity verified, and it's not uncommon for stores to ask for customers to upload a copy of their identity card.

It's not known how long the database was exposed. Anyone who knew the IP address of the database could access the data inside using only their web browser.

TechCrunch contacted the owners of the online store with details about the exposed database. A short time later, the database became inaccessible. In reply, the store owners responded: "The vulnerability has been addressed promptly. We are currently investigating the cause internally."

TechCrunch's Rita Liao contributed reporting.