China’s Ministry of Public Security on Tuesday published 10 representative cases that expose organised schemes to harvest, traffic and monetise citizens’ personal information, underscoring a sustained law-enforcement effort to curb data-related crime.
The cases, released by the ministry’s cybersecurity bureau, document a range of methods used by criminal networks — including inducements, cyber intrusions and collusion by insiders — to obtain identity credentials and other sensitive records for resale and use in fraud and money-laundering operations.
Methods and markets
Among the examples disclosed, investigators described a gang that offered cash rewards to induce people to set up e‑commerce accounts and business licences in their real names, then sold those credentials to facilitate money-laundering activity. In a separate case, suspects bought large batches of real-name–verified accounts from platforms such as WeChat and Douyin and resold them to overseas syndicates, where they were reportedly used for telecom and online fraud.
The ministry said the individuals involved in the 10 cases have been processed under existing law. The public release appears aimed at both deterring similar conduct and explaining enforcement priorities as Beijing tightens regulation of cyberspace and data handling.
“All suspects in the 10 cases have been handled in accordance with the law,”
Scale and recent enforcement
The published cases form part of a larger campaign. Chinese police agencies, the ministry said, cracked more than 40,000 cases concerning the infringement of personal information during specified operations between 2020 and 2024. In 2025, the ministry said it combined intensified enforcement with stricter regulation to develop a broader governance framework intended to protect networks, data and information security.
| Period | Noted activity |
|---|---|
| 2020–2024 | More than 40,000 cases cracked in targeted campaigns |
| 2025 | Integration of tougher law enforcement with tighter regulation to strengthen cyberspace governance |
Public guidance and enforcement aims
The ministry urged the public to take stronger precautions to protect personal data, to report suspected leaks promptly and to seek remedies through legal channels where rights have been infringed. The messaging aligns with an enforcement posture that mixes criminal investigation with regulatory oversight of internet platforms and data handlers.
- Organised networks used inducements, cyberattacks and insider help to harvest data.
- Stolen or co‑opted real‑name accounts were used to facilitate money‑laundering and cross‑border fraud.
- Authorities cite a multi‑year enforcement campaign with tens of thousands of cases addressed.
Analysts and international privacy advocates will watch whether the emphasis on criminal prosecution is matched by sustained regulatory oversight of platforms where data is concentrated. The cases released by the ministry highlight vulnerabilities created when identity-verified accounts and official records are commodified in underground markets.
For firms and individuals operating in China or with cross‑border data flows, the ministry’s disclosures are a reminder that Beijing is pursuing both punitive and preventive measures. How those measures will intersect with privacy protections, corporate compliance obligations and transnational investigations remains a developing policy and enforcement story.
The ministry did not provide detailed legal outcomes for each case in the public summary. It said only that the matters had been addressed under current law and urged vigilance from citizens and enterprises handling personal information.