Major Chinese Police Data Leak: A major data exposure has provided an unprecedented look into China’s sprawling state surveillance apparatus. The leak occurred after a Dutch cybersecurity researcher and journalist accidentally stumbled upon an open, unencrypted Chinese police dashboard on the public internet.
The system, which contained detailed profiles on nearly 12,000 individuals, monitored foreign nationals, international journalists, students, and citizens across China with alarming granularity.
The Discovery: A Cyber Researcher Finds His Own Face Online
Major Chinese Police Data Leak: Marc Hofer (46), an Amsterdam-based cybersecurity analyst and former foreign correspondent, made the discovery while auditing open internet databases.
While examining a public system titled the “Dynamic Control Platform for Overseas Personnel,” Hofer discovered that the login portal had auto-filled login credentials left unsecured. Upon clicking through, he was stunned to find a futuristic, Minority Report-style tracking dashboard.
“Whoever put that stuff in there had access to real data,” Hofer noted after seeing his own official Chinese immigration photograph, passport number, and local phone number listed on the active database.
What Was Inside the Dragnet?
Major Chinese Police Data Leak: The dashboard appeared to be built for the Zhangjiakou Public Security Bureau in northern China’s Hebei province, a key host city for the 2022 Winter Olympics.
Despite being localized for Zhangjiakou, the platform’s scope extended far beyond city borders:
12,000 Total Profiles: Included entries for foreign visitors, residents, criminal suspects, fugitives, and individuals from Hong Kong and Taiwan.
300+ Foreign Journalists: Tracked international reporters, many of whom had never even set foot in Zhangjiakou.
700+ Foreign Residents: Detailed dossiers on expats, foreign spouses, activists, and exchange students living in the region.
Geopolitical Groupings: The ‘Five Eyes’ and ‘Special Surveillance’ Nations
The database categorized foreigners using distinct geopolitical classifications:
The ‘Five Eyes’ Alliance: Citizens from Australia, Canada, New Zealand, the United Kingdom, and the United States were grouped into a dedicated surveillance tier.
‘Special Watchlist’ Countries: Individuals from Egypt, Iran, Israel, Morocco, Pakistan, and Sudan were categorized under heightened monitoring.
Deep Profiling of Indian and Pakistani Students
Among the entries were detailed records of foreign students enrolled at local institutions, such as Hebei North University. Profiles for Indian and Pakistani students went far beyond basic visa records, documenting:
Religion and marital status.
Exact academic focus and class schedules.
CCTV Timestamps: Precise logs showing when individual students walked past campus entrance cameras.
Relationship Mapping: Visual network trees connecting individuals whenever facial recognition cameras spotted them walking together.
From Hospital Visits to Gas Bills: Extreme Data Aggregation
The leak demonstrated how Chinese local law enforcement aggregates data from both public facial recognition networks and private commercial sources.
The system tracked daily living habits in painstaking detail:
Travel Logs: Saved flight and train seat assignments, along with hotel guest logs at local destinations like the Thaiwoo Ski Resort.
Financial & Utility Data: Logged utility payments, including home gas bills.
Medical Records: Tracked hospital visits and health registration data.
Law Enforcement Fines: Documented minor administrative penalties, such as a ~$150 fine levied against a foreign resident in 2021 for failing to register a change of address within the mandatory timeframe.
Expert Reaction: “A Privacy and Security Disaster”
Human rights advocates and cybersecurity experts have expressed grave concerns over the exposure.
Lack of Oversight: Maya Wang of Human Rights Watch highlighted that Chinese police agencies operate with almost no external accountability or systemic checks to prevent data abuse.
Compounded Leak Risks: Greg Walton, a senior researcher at the SecDev Group, warned that as local Chinese police departments rush to build custom AI-driven monitoring systems, thousands of unsecured portals are left vulnerable on the open web, exposing private citizen data to malicious hackers worldwide.
System Origins and Broader Implications
Investigations into the underlying software reveal that the platform was partially developed by Origin Dynamic, a technology firm partly owned by the city government of Yancheng in Jiangsu Province.
The company filed a patent application for an “information interface for non-Chinese citizens” matching this exact user interface.
Files downloaded from the database showed that entries were actively updated up until recent months by local officers, including an official tied to an artificial intelligence laboratory inside the Zhangjiakou Police Bureau.
The incident highlights a paradoxical reality of modern digital authoritarianism: while state surveillance capabilities continue to expand, sloppy security controls leave the private data of thousands of global citizens exposed for anyone to see.


