Last Update: 09/22/2026 at 11:34 PM EST

UK Biobank's De-Identified Data Leak

Coverage from The Guardian, Times Higher Education, and others

UK Biobank's De-Identified Data Leak topic image

UK Biobank data covering about 500,000 volunteers was reportedly uploaded to online repositories and later offered for sale through Alibaba-linked listings after legitimate access was granted to three research institutions.

Although officials said the records lacked direct identifiers such as names and addresses, the data reportedly included detailed health, demographic, socioeconomic, lifestyle, and biological measures that could create re-identification risks when combined with other information. UK Biobank revoked access, removed listings, paused platform access, and began investigations, intensifying scrutiny of how biomedical datasets are downloaded, monitored, and shared.

Looking Back
141 Day Timeline
Mar 12Apr 9May 7Jun 4Jul 2Jul 30
History
09/21/2026

The story is now more specifically defined as a large-scale exposure involving roughly 500,000 volunteers and downloads by three Chinese research institutions. UK Biobank's forensic investigation and platform-access pause add concrete containment and oversight measures beyond the earlier pattern of takedowns and access revocation.

All Articles13 articles
Important8 articles · CI Score 60 and above
The Guardian
UK Biobank data exposure in the United Kingdom during 2024 and 2025 highlights privacy risk and governance gaps.
3/14/2026 • Data Breaches & Exposure Events • General
Times Higher Education / Elizabeth Green
UK Biobank temporarily blocked researcher access after anonymised medical data was offered for sale online in China, prompting scrutiny of research data governance.
5/25/2026 • Data Breaches & Exposure Events • General
The European Magazine / Dr Raj Joshi
UK Biobank volunteer biomedical data appeared on Alibaba in 2025 after authorized academic access, prompting scrutiny of de-identification and data containment.
4/28/2026 • Data Breaches & Exposure Events • General
ComputerWeekly.com
Lloyds Banking Group paid further goodwill compensation to customers after a 12 March banking app programming error exposed transaction details, according to UK Treasury Select Committee correspondence.
4/28/2026 • Data Breaches & Exposure Events • General
Sgtreport
Ian Murray reported a breach of UK Biobank de-identified health data for 500,000 citizens after Alibaba listings appeared in China on April 20.
4/26/2026 • Data Breaches & Exposure Events • General
Irvine Times
UK officials confirmed 500,000 UK Biobank participant health records were offered for sale online in China via Alibaba, after China access by research institutions was revoked and listings removed.
4/23/2026 • Data Breaches & Exposure Events • General
BeyondMachines
UK Biobank notified the UK government on April 20, 2026 after 500,000 health records tied to volunteer data were allegedly listed for sale on Alibaba.
4/23/2026 • Data Breaches & Exposure Events • General
Times Higher Education / Jack Grove
Rory Collins announced a temporary UK Biobank access pause after de-identified volunteer data was offered for sale online in China in April 2026, leading to a forensic investigation.
4/23/2026 • Data Breaches & Exposure Events • General
Interesting5 articles · CI Score 45–59
TechStartups / Nickie Louise
ExfilSquad reportedly stole more than 740,000 records from UK education and police systems on July 30, 2026, prompting investigations and Information Commissioners Office notifications.
7/30/2026 • Data Breaches & Exposure Events • General
The Observer / James Tapper
UK Biobank reported 18 months of security work after an anonymous tip led to Alibaba e-commerce listings tied to Chinese-linked researchers offering biomedical data.
4/26/2026 • Data Breaches & Exposure Events • General
Insurance Business / Bryony Garlick
Lloyds Bank, Halifax, and Bank of Scotland assessed UK GDPR breach-notification duties after mobile app users reported brief visibility of other customers transaction data.
3/17/2026 • Cybersecurity (Privacy-Relevant) • General
Alston & Bird Privacy / Hanna Hewitt
The UK Government survey for 2025/2026, using thousands of business submissions, finds phishing-led breaches persist while AI risk controls and supplier personal-data assessments remain limited.
5/14/2026 • Cybersecurity (Privacy-Relevant) • General
The Guardian
ICO investigates IT glitch exposing customer transactions in Lloyds Banking Group mobile apps in the United Kingdom in 2025
3/12/2026 • Data Breaches & Exposure Events • General