Skip to main content
Breach Signal

Breach report

Social Media

Sina Weibo

Hacker selling data of 538 million Weibo users

Records for 538 million users of Chinese social network Weibo, including 172 million phone numbers, were offered on the dark web in 2020. Weibo said the data was harvested by abusing its contact-matching API.

Reported by ZDNet

Records exposed

538M

538 million users (172 million with phone numbers)

Scale vs. largest on file

When
2019 (disclosed 2020)
How they got in
API abuse of contact-matching feature
Sector
Social Media

In March 2020, a seller on dark web markets began offering a database said to contain information on 538 million users of Sina Weibo, China's largest Twitter-style social platform. According to the listing, about 172 million of the records included phone numbers, while the rest contained account details such as real names, usernames, gender and location. The seller claimed the data had been obtained in mid-2019.

The asking price was strikingly low, a few hundred dollars in Chinese yuan, which analysts attributed to the absence of passwords in the dataset. Weibo acknowledged the leak but disputed that its core databases had been breached. The company said the phone numbers had been collected by abusing a feature that allows users to upload their address book to find friends, effectively a brute-force enumeration of its contact-matching interface, and that other profile details had been scraped. Weibo also said it had strengthened its security and reported the matter to police.

The incident drew attention from Chinese regulators. The Ministry of Industry and Information Technology, which oversees internet companies, summoned Weibo representatives and instructed the company to tighten its data protection practices and improve its handling of personal information. The case came amid a broader push by Beijing to regulate data security, which later culminated in the Personal Information Protection Law of 2021.

Even without passwords, the dataset posed real risks. Pairing phone numbers with real names and locations is valuable for SMS fraud, phishing and telemarketing scams, and it can be combined with other leaked datasets to build fuller profiles. Security experts also noted that Weibo's own statement acknowledged many users reused passwords across platforms, raising the risk of account takeovers if the data were merged with credential dumps from elsewhere.

The Weibo leak belongs to a family of incidents in which contact-upload features at large social networks were turned into mass enumeration tools. It came roughly a year before similar datasets surfaced from Facebook, LinkedIn and Twitter, and it shows that the problem is not confined to Western platforms. Any service that lets users look up accounts by phone number needs strong rate limits, anomaly detection and limits on what data is returned.

More from the wire

More in Social Media.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.