Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ 099 · ENFORCEMENT

公安部网安局 Publishes 10 Typical Cases of Infringing Citizens' Personal Information — Insiders, Order Decryption, and Article 253a in Practice

On 11 August 2026 the MPS Cyber Security Bureau (公安部网安局) published ten typical cases (典型案例) of the crime of infringing upon citizens' personal information, brought under the Clean Net special campaign (净网专项行动). Across the batch: 123 suspects, more than 9.6 million items of personal information, and roughly 23.6 million yuan in case value. The striking feature is not the volume but the access route — in at least half the cases the data came out through someone with legitimate access: an employee, a planted hire, a service vendor, a hotel partner, or a school and hospital staffer. This DCC brief translates all ten fact patterns, sets them against Criminal Law Article 253a and the 2017 PI Criminal Interpretation thresholds, and draws out what the batch signals for companies whose exposure runs through their own staff and vendors.

Editor’s Note — DCC.

Most of what DCC translates is administrative: a CAC notification, a MIIT bulletin, a draft rule out for comment. This batch is the other track. The Ministry of Public Security is the only Chinese data regulator whose instrument is the Criminal Law, and its typical cases (典型案例) are the clearest public record of how the 2017 PI Criminal Interpretation is actually applied — which fact patterns get charged, and at what volumes.

Read the ten cases together and one thing dominates. These are not outside intrusions. In at least half the batch the data left through someone who was supposed to have it: a tutoring-centre employee, a planted hire inside a real-estate agency, an IT vendor servicing government units, budget hotels handing over guest lists, staff at schools and eye hospitals. Article 253a treats exactly that route more harshly than an outside hack — and the Interpretation halves the quantitative thresholds when the information was obtained “in the course of performing duties or providing services.” For a company operating in China, the criminal exposure in this batch is not a story about attackers. It is a story about employees and vendors.

What was published

On 11 August 2026 the MPS Cyber Security Bureau (公安部网安局) released ten typical cases of the crime of infringing upon citizens’ personal information (侵犯公民个人信息罪), investigated by provincial and municipal cyber-security police under the recurring Clean Net special campaign (净网专项行动).

Aggregated across the batch:

  • 123 suspects across ten cases
  • More than 9.6 million items of personal information, in the eight cases that give a count
  • Roughly 23.6 million yuan (≈ USD 3.3 million) in stated case value
  • Nine provinces and municipalities: Liaoning, Gansu, Anhui, Sichuan, Guangdong, Shanxi, Shaanxi, Shanghai, Jiangsu, Zhejiang

The ten cases

#LocalityFact patternPI volumeCase valueStage
1Shenyang, LiaoningA man surnamed Yang (杨某国, 25) and an accomplice ran a “studio” recruiting people with a 200-yuan bounty to appear in person with their ID cards and be photographed holding them, then used the identities to register e-commerce accounts and business licences. Accounts sold at 100–300 yuan each to gambling and fraud rings for payment settlement and laundering.3,000+200k+ yuan27 under criminal compulsory measures
2Linxia, GansuA ring led by Cui (崔某伟, 38) advertised “cashing in your idle accounts”, bulk-buying real-name WeChat, QQ and Douyin accounts and soliciting phone numbers from sellers’ friends and family; resold in layers to overseas fraud operations. The bureau notes the sellers themselves became accomplices.20,000+1.3m+ yuan6 transferred for prosecution
3Xuancheng, AnhuiLiu (刘某沅, 20) with two 18-year-olds exploited system vulnerabilities to build a social-engineering database (社工库) with a paid lookup interface, selling record lookups to lawyers, private investigators and information brokers.”a batch”300k+ yuan9 transferred for prosecution
4Neijiang, SichuanTwo people surnamed Li advertised “order decryption” (订单解密) to merchants on Douyin, Kuaishou and Xiaohongshu; with technical support from a fifth defendant they bulk-acquired platform order data and stripped the masking to recover buyers’ phone numbers and delivery addresses, then sold on to the black and grey market.2m+8m+ yuan5 transferred for prosecution
5Foshan, GuangdongWu (吴某通, 36) used a technology company as cover and planted an employee inside a real-estate agency to obtain internal system credentials, then hired others to bypass the agency’s security controls and scrape agent records in bulk, reselling to decorating firms for a 2% cut of each closed job.13,000+4 under criminal compulsory measures
6Taiyuan, ShanxiPolice worked back from a run of “targeted” tutoring cold-calls to a chain of insiders across schools, tutoring institutions and eye hospitals. Wang (王某杰, 34), under enrolment targets, traded and bought student data from staff at multiple institutions — described as “insider theft, industry resale, targeted marketing”.500,000+300k+ yuan12 indicted
7Xianyang, ShaanxiTraced from decorating cold-calls. A ring led by Shi (石某愿, 33) and Huang (黄某威, 29) bought personal information from IT companies servicing government units, demolition-project contractors, property managers, sales offices and village committees, then sold into the decorating, furnishing and estate-agency trades, which resold it again in layers.6m+500k+ yuan11 indicted
8ShanghaiA ring led by Dong (董某, 36) set up a shared power-bank company, placed devices free in budget hotels on a revenue split, then required the hotels to hand over guest names and check-in times in exchange for review manipulation — inflating ratings and scrubbing negative reviews. Run as a company with sales, technical, positive-review, negative-review and after-sales departments.1m+ (plus 100,000+ manipulated reviews)11m+ yuan33 indicted
9Suqian, JiangsuXia (夏某强, 38) ran a “legal consulting” studio sourcing hotel check-in records, vehicle files and travel tracks through overseas social platforms, then reselling at high prices to lawyers, private investigators and brokers for use in divorce, debt-collection and commercial disputes. Marketed on a legal-services app, Taobao, Xianyu and QQ groups.100,000+1m+ yuan10 under criminal compulsory measures
10Zhoushan, ZhejiangA “private detective” outfit incorporated in Shanghai, marketed on WeChat Channels and Douyin as offering marital investigation and missing-person work. Colluded with insiders across several industries for whereabouts and hotel records, and separately employed people for GPS tracking, physical tailing and covert recording — an “online lookups plus offline tailing” chain.services to 12 clients1m+ yuan6 transferred for prosecution

Five things the batch signals

1. The insider is the main channel, and the law knows it. Cases 5, 6, 7, 8 and 10 all turn on someone with legitimate access. This is not incidental colour: the second paragraph of Article 253a imposes heavier punishment (从重处罚) where the information was obtained in the course of performing duties or providing services, and Article 5(VIII) of the Interpretation treats an insider as reaching “serious circumstances” at half the ordinary quantity. An employee who sells 250 items of accommodation data is in the same position as an outsider who sells 500.

2. Your vendors and channel partners are part of the perimeter. Case 7 sources data from IT companies contracted to maintain government systems. Case 8 obtains it from hotels as the price of a commercial partnership. Case 5 gets it by placing a person on the payroll of the target. None of these is a technical control failure in the ordinary sense; all of them would sit outside a security programme scoped to the company’s own network.

3. Masked data is being re-identified as a commercial service. Case 4 is the one that should most concern platform and merchant-side counsel. E-commerce platforms mask order data precisely so merchants cannot read buyers’ phone numbers and addresses; “order decryption” is a paid service that undoes it, and it was sold openly to merchants on three major platforms at a scale of two million-plus records. That is a working demonstration of the gap between de-identification and anonymization that Xu Ke’s reconstruction of the anonymization regime is trying to close — and a reminder that PIPL’s anonymization standard requires that the information cannot be restored, which masked order data plainly can be.

4. Volume and money do not track each other. Case 7 moved six million items for 500,000 yuan; case 8 moved one million for eleven million. Marketing leads are high-volume and cheap; a captive review-manipulation business is low-volume and lucrative. Since the Interpretation sets independent triggers on both quantity (Article 5(III)–(V)) and illegal gains (Article 5(VII), RMB 5,000), neither figure alone tells you where a fact pattern lands.

5. Sensitive categories carry the low thresholds. Cases 9 and 10 deal in whereabouts and tracks (行踪轨迹) and hotel check-in records — the categories the Interpretation singles out at 50 items and 500 items respectively, against 5,000 for ordinary personal information. Selling whereabouts data that is then used for a crime is “serious circumstances” at any quantity under Article 5(I).

The bureau closes with the two provisions that supply the charge.

Criminal Law Article 253a. Selling or providing citizens’ personal information to others in violation of relevant State provisions, where circumstances are serious, carries up to three years’ imprisonment or criminal detention plus a fine; particularly serious circumstances carry three to seven years and a fine. Selling or providing information obtained in the course of performing duties or providing services attracts heavier punishment. Stealing or otherwise illegally obtaining such information is punished under the same first-paragraph standard.

Article 5 of the PI Criminal Interpretation. The bureau reproduces all ten limbs of the “serious circumstances” test. The operative thresholds:

  • 50+ items — whereabouts and tracks, communication content, credit-reporting information, property information
  • 500+ items — accommodation information, communication records, health and physiological information, transaction information, and other information that may affect personal or property safety
  • 5,000+ items — all other citizens’ personal information
  • RMB 5,000+ in illegal gains, independently
  • Half the above where the information was obtained through duties or services
  • Any quantity, where whereabouts data is sold and then used for a crime, or where the seller knows the buyer will use it criminally

Two points that the source does not spell out but that matter for readers outside China. First, “citizens’ personal information” here is a criminal-law term of art and is not co-extensive with 个人信息 under PIPL — the definitional work is done by Article 1 of the Interpretation, not by PIPL Article 4. Second, despite the word “citizens”, the Supreme People’s Procuratorate has confirmed in a 2018 reply letter that the offence covers the personal information of foreign nationals and stateless persons as well. Data about a multinational’s non-Chinese staff or customers, held in China, sits squarely inside Article 253a.

For the doctrinal argument that both elements of the offence — “relevant State provisions” and “serious circumstances” — are looser than they should be, and have been stretched by courts in ways compliance teams should watch, see Hong Yanqing on the criminal threshold.

A note on two numbers

MPS case releases state a 涉案金额 — the amount involved in the case, meaning the total value transacted. This is not 违法所得, illegal gains, which is the offender’s actual profit and the figure the RMB 5,000 trigger in Article 5(VII) is measured against. English coverage routinely renders both as “amount involved” or, worse, “proceeds”. They are different numbers doing different legal work, and the gap between them can be an order of magnitude. The aggregate cited above is case value, not profit.

Similarly, the three procedural phrases in the release mark three distinct stages, and DCC keeps them apart: subjected to criminal compulsory measures (采取刑事强制措施) is pre-indictment coercion — detention, arrest or bail; transferred for prosecution (移送起诉) means the police have handed the file to the procuratorate for examination; public prosecution initiated (提起公诉) means an indictment has been filed. Only cases 6, 7 and 8 have reached the third stage. None of the ten has been tried.

The tail

The release closes, as these posts usually do, with a promotion for the National Network Identity Authentication Public Service Platform (国家网络身份认证公共服务平台) — the state-run 网号/网证 scheme MPS built with five other departments and governs through MPS Order No. 173, effective 15 July 2025.

The placement is not accidental. Cases 1 and 2 are both about harvesting real-name online accounts: the value in them exists only because platforms must verify identity and therefore hold the identity documents that make an account resellable. A state authentication layer is the policy answer to that specific failure — Article 8 of the Measures gives an integrating platform the verification result rather than the document, and Article 7 bars it from asking the user for plaintext identity information on the side. Whether overseas-invested platforms will be expected to adopt it, and on what terms, is the live question; Article 6 promises that existing authentication methods survive and Article 7 requires equal service for users who decline the scheme, but the pairing of an enforcement batch with the platform pitch is a reasonable signal of the direction of travel.


Source: 净网专项行动 | 公安部网安局公布打击侵犯公民个人信息犯罪10起典型案例, published by 公安部网安局 (MPS Cyber Security Bureau) on its WeChat Official Account, 11 August 2026. Original. Translated and edited by DCC. Suspect names appear as redacted in the original; ages and locality attributions are the bureau’s own.

— Not legal advice.

— Not legal advice.


§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →