UK Biobank Data Breach: Health Data of 500,000 Listed for Sale in China

2026-04-24T14:52:16Z5448bf8e7b521e3177794f82016902cf15428a5ef5bb50a120a2b3ccaffdb3e2
active-exploitationai-agentsai-securitychinacredential-theftdata-breachdata-for-saledvrecommercegoogle-geminihealth-datamcp-protocolmiraincscnginx-uinpm-supply-chainpasskeysprompt-injectionproxysmartsim-farmssupply-chain-malwareuk-biobankwater-icsworm-like-propagationzionsiphon

What happened

Feed highlights multiple high-impact cyber events: a breach of UK Biobank health records (≈500k records) was confirmed to have been listed for sale on Chinese e‑commerce platforms; active exploitation of a critical nginx-ui MCP authentication bypass (CVE-2026-33032, CVSS 9.8) and Mirai-based attacks leveraging CVE-2024-3721 against DVR devices; a worm-like npm supply‑chain malware campaign stealing developer credentials; and ZionSiphon ICS malware targeting water infrastructure. Additional notable items include large-scale SIM farm tooling (ProxySmart), surge in education-sector attacks, macOS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
5448bf8e7b521e3177794f82016902cf15428a5ef5bb50a120a2b3ccaffdb3e2
Enrichment time
2026-04-24T14:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.