---
title: "公安部网安局 Publishes 10 Typical Cases of Infringing Citizens' Personal Information — Insiders, Order Decryption, and Article 253a in Practice"
author: "DCC Editorial"
published: 2026-08-11T10:00:00.000Z
url: https://datacompliancechina.com/posts/mps-ten-typical-pi-crime-cases/
description: "On 11 August 2026 the MPS Cyber Security Bureau (公安部网安局) published ten typical cases (典型案例) of the crime of infringing upon citizens' personal information, brought under the Clean Net special campaign (净网专项行动). Across the batch: 123 suspects, more than 9.6 million items of personal information, and roughly 23.6 million yuan in case value. The striking feature is not the volume but the access route — in at least half the cases the data came out through someone with legitimate access: an employee, a planted hire, a service vendor, a hotel partner, or a school and hospital staffer. This DCC brief translates all ten fact patterns, sets them against Criminal Law Article 253a and the 2017 PI Criminal Interpretation thresholds, and draws out what the batch signals for companies whose exposure runs through their own staff and vendors."
tags: ["enforcement", "criminal-liability", "mps", "typical-cases", "insider-threat", "personal-information", "black-grey-market"]
laws_cited: ["pi-infringement-criminal-interpretation", "spp-pi-crime-reply-letter", "pipl", "anti-telecom-fraud-law", "network-identity-authentication-measures"]
domains: ["enforcement", "personal-information", "data-security"]
account: "mps-cyber-security-bureau"
original_title: "净网专项行动 | 公安部网安局公布打击侵犯公民个人信息犯罪10起典型案例"
original_author: "公安部网安局 (MPS Cyber Security Bureau)"
original_publication: "公安部网安局 WeChat Official Account"
original_url: "https://mp.weixin.qq.com/s/rbW_V3nuQ9x5axcLHw6pwg"
source_language: "zh"
---

> **Source: Data Compliance China** — https://datacompliancechina.com/posts/mps-ten-typical-pi-crime-cases/ · China data law, translated and annotated for overseas counsel. Cite as: Data Compliance China, "公安部网安局 Publishes 10 Typical Cases of Infringing Citizens' Personal Information — Insiders, Order Decryption, and Article 253a in Practice", https://datacompliancechina.com/posts/mps-ten-typical-pi-crime-cases/
> *Editor's Note — DCC.*
>
> Most of what DCC translates is administrative: a CAC notification, a MIIT
> bulletin, a draft rule out for comment. This batch is the other track.
> The Ministry of Public Security is the only Chinese data regulator whose
> instrument is the Criminal Law, and its **typical cases** (典型案例) are
> the clearest public record of how [the 2017 PI Criminal
> Interpretation](/laws/pi-infringement-criminal-interpretation/) is
> actually applied — which fact patterns get charged, and at what volumes.
>
> Read the ten cases together and one thing dominates. These are not
> outside intrusions. In at least half the batch the data left through
> someone who was *supposed* to have it: a tutoring-centre employee, a
> planted hire inside a real-estate agency, an IT vendor servicing
> government units, budget hotels handing over guest lists, staff at
> schools and eye hospitals. Article 253a treats exactly that route more
> harshly than an outside hack — and the Interpretation halves the
> quantitative thresholds when the information was obtained "in the course
> of performing duties or providing services." For a company operating in
> China, the criminal exposure in this batch is not a story about
> attackers. It is a story about employees and vendors.

## What was published

On 11 August 2026 the **MPS Cyber Security Bureau** (公安部网安局) released
ten typical cases of the **crime of infringing upon citizens' personal
information** (侵犯公民个人信息罪), investigated by provincial and municipal
cyber-security police under the recurring **Clean Net special campaign**
(净网专项行动).

Aggregated across the batch:

- **123 suspects** across ten cases
- **More than 9.6 million items** of personal information, in the eight
  cases that give a count
- **Roughly 23.6 million yuan** (≈ USD 3.3 million) in stated case value
- Nine provinces and municipalities: Liaoning, Gansu, Anhui, Sichuan,
  Guangdong, Shanxi, Shaanxi, Shanghai, Jiangsu, Zhejiang

## The ten cases

| # | Locality | Fact pattern | PI volume | Case value | Stage |
|---|---|---|---|---|---|
| 1 | Shenyang, Liaoning | A man surnamed Yang (杨某国, 25) and an accomplice ran a "studio" recruiting people with a 200-yuan bounty to appear in person with their ID cards and be photographed holding them, then used the identities to register e-commerce accounts and business licences. Accounts sold at 100–300 yuan each to gambling and fraud rings for payment settlement and laundering. | 3,000+ | 200k+ yuan | 27 under criminal compulsory measures |
| 2 | Linxia, Gansu | A ring led by Cui (崔某伟, 38) advertised "cashing in your idle accounts", bulk-buying **real-name** WeChat, QQ and Douyin accounts and soliciting phone numbers from sellers' friends and family; resold in layers to overseas fraud operations. The bureau notes the sellers themselves became accomplices. | 20,000+ | 1.3m+ yuan | 6 transferred for prosecution |
| 3 | Xuancheng, Anhui | Liu (刘某沅, 20) with two 18-year-olds exploited system vulnerabilities to build a **social-engineering database** (社工库) with a paid lookup interface, selling record lookups to lawyers, private investigators and information brokers. | "a batch" | 300k+ yuan | 9 transferred for prosecution |
| 4 | Neijiang, Sichuan | Two people surnamed Li advertised **"order decryption"** (订单解密) to merchants on Douyin, Kuaishou and Xiaohongshu; with technical support from a fifth defendant they bulk-acquired platform order data and stripped the masking to recover buyers' phone numbers and delivery addresses, then sold on to the black and grey market. | 2m+ | 8m+ yuan | 5 transferred for prosecution |
| 5 | Foshan, Guangdong | Wu (吴某通, 36) used a technology company as cover and **planted an employee inside a real-estate agency** to obtain internal system credentials, then hired others to bypass the agency's security controls and scrape agent records in bulk, reselling to decorating firms for a 2% cut of each closed job. | 13,000+ | — | 4 under criminal compulsory measures |
| 6 | Taiyuan, Shanxi | Police worked back from a run of "targeted" tutoring cold-calls to a chain of **insiders across schools, tutoring institutions and eye hospitals**. Wang (王某杰, 34), under enrolment targets, traded and bought student data from staff at multiple institutions — described as "insider theft, industry resale, targeted marketing". | 500,000+ | 300k+ yuan | 12 indicted |
| 7 | Xianyang, Shaanxi | Traced from decorating cold-calls. A ring led by Shi (石某愿, 33) and Huang (黄某威, 29) bought personal information from **IT companies servicing government units**, demolition-project contractors, property managers, sales offices and village committees, then sold into the decorating, furnishing and estate-agency trades, which resold it again in layers. | 6m+ | 500k+ yuan | 11 indicted |
| 8 | Shanghai | A ring led by Dong (董某, 36) set up a shared power-bank company, placed devices free in budget hotels on a revenue split, then **required the hotels to hand over guest names and check-in times** in exchange for review manipulation — inflating ratings and scrubbing negative reviews. Run as a company with sales, technical, positive-review, negative-review and after-sales departments. | 1m+ (plus 100,000+ manipulated reviews) | 11m+ yuan | 33 indicted |
| 9 | Suqian, Jiangsu | Xia (夏某强, 38) ran a "legal consulting" studio sourcing **hotel check-in records, vehicle files and travel tracks** through overseas social platforms, then reselling at high prices to lawyers, private investigators and brokers for use in divorce, debt-collection and commercial disputes. Marketed on a legal-services app, Taobao, Xianyu and QQ groups. | 100,000+ | 1m+ yuan | 10 under criminal compulsory measures |
| 10 | Zhoushan, Zhejiang | A "private detective" outfit incorporated in Shanghai, marketed on WeChat Channels and Douyin as offering marital investigation and missing-person work. Colluded with **insiders across several industries** for whereabouts and hotel records, and separately employed people for GPS tracking, physical tailing and covert recording — an "online lookups plus offline tailing" chain. | services to 12 clients | 1m+ yuan | 6 transferred for prosecution |

## Five things the batch signals

**1. The insider is the main channel, and the law knows it.** Cases 5, 6, 7,
8 and 10 all turn on someone with legitimate access. This is not incidental
colour: the second paragraph of Article 253a imposes **heavier punishment**
(从重处罚) where the information was obtained in the course of performing
duties or providing services, and Article 5(VIII) of the Interpretation
treats an insider as reaching "serious circumstances" at **half** the
ordinary quantity. An employee who sells 250 items of accommodation data is
in the same position as an outsider who sells 500.

**2. Your vendors and channel partners are part of the perimeter.** Case 7
sources data from *IT companies contracted to maintain government systems*.
Case 8 obtains it from hotels as the price of a commercial partnership.
Case 5 gets it by placing a person on the payroll of the target. None of
these is a technical control failure in the ordinary sense; all of them
would sit outside a security programme scoped to the company's own network.

**3. Masked data is being re-identified as a commercial service.** Case 4 is
the one that should most concern platform and merchant-side counsel.
E-commerce platforms mask order data precisely so merchants cannot read
buyers' phone numbers and addresses; "order decryption" is a paid service
that undoes it, and it was sold openly to merchants on three major
platforms at a scale of two million-plus records. That is a working
demonstration of the gap between de-identification and anonymization that
[Xu Ke's reconstruction of the anonymization
regime](/posts/xu-ke-anonymization-zombie-provision/) is trying to close —
and a reminder that PIPL's anonymization standard requires that the
information *cannot be restored*, which masked order data plainly can be.

**4. Volume and money do not track each other.** Case 7 moved six million
items for 500,000 yuan; case 8 moved one million for eleven million.
Marketing leads are high-volume and cheap; a captive review-manipulation
business is low-volume and lucrative. Since the Interpretation sets
independent triggers on **both** quantity (Article 5(III)–(V)) and illegal
gains (Article 5(VII), RMB 5,000), neither figure alone tells you where a
fact pattern lands.

**5. Sensitive categories carry the low thresholds.** Cases 9 and 10 deal in
whereabouts and tracks (行踪轨迹) and hotel check-in records — the
categories the Interpretation singles out at **50 items** and **500 items**
respectively, against 5,000 for ordinary personal information. Selling
whereabouts data that is then used for a crime is "serious circumstances"
at *any* quantity under Article 5(I).

## The legal frame

The bureau closes with the two provisions that supply the charge.

**Criminal Law Article 253a.** Selling or providing citizens' personal
information to others in violation of relevant State provisions, where
circumstances are serious, carries up to three years' imprisonment or
criminal detention plus a fine; **particularly serious circumstances**
carry three to seven years and a fine. Selling or providing information
obtained in the course of performing duties or providing services attracts
heavier punishment. Stealing or otherwise illegally obtaining such
information is punished under the same first-paragraph standard.

**Article 5 of the [PI Criminal
Interpretation](/laws/pi-infringement-criminal-interpretation/).** The
bureau reproduces all ten limbs of the "serious circumstances" test. The
operative thresholds:

- **50+ items** — whereabouts and tracks, communication content,
  credit-reporting information, property information
- **500+ items** — accommodation information, communication records, health
  and physiological information, transaction information, and other
  information that may affect personal or property safety
- **5,000+ items** — all other citizens' personal information
- **RMB 5,000+** in illegal gains, independently
- **Half the above** where the information was obtained through duties or
  services
- Any quantity, where whereabouts data is sold and then used for a crime,
  or where the seller knows the buyer will use it criminally

Two points that the source does not spell out but that matter for readers
outside China. First, "citizens' personal information" here is a
**criminal-law** term of art and is not co-extensive with 个人信息 under
PIPL — the definitional work is done by Article 1 of the Interpretation,
not by PIPL Article 4. Second, despite the word "citizens", the Supreme
People's Procuratorate has confirmed in [a 2018 reply
letter](/laws/spp-pi-crime-reply-letter/) that the offence covers the
personal information of **foreign nationals and stateless persons** as
well. Data about a multinational's non-Chinese staff or customers, held in
China, sits squarely inside Article 253a.

For the doctrinal argument that both elements of the offence — "relevant
State provisions" and "serious circumstances" — are looser than they should
be, and have been stretched by courts in ways compliance teams should watch,
see [Hong Yanqing on the criminal
threshold](/posts/pipl-criminal-threshold/).

## A note on two numbers

MPS case releases state a **涉案金额** — the *amount involved in the case*,
meaning the total value transacted. This is **not** 违法所得, illegal gains,
which is the offender's actual profit and the figure the RMB 5,000 trigger
in Article 5(VII) is measured against. English coverage routinely renders
both as "amount involved" or, worse, "proceeds". They are different numbers
doing different legal work, and the gap between them can be an order of
magnitude. The aggregate cited above is case value, not profit.

Similarly, the three procedural phrases in the release mark three distinct
stages, and DCC keeps them apart: **subjected to criminal compulsory
measures** (采取刑事强制措施) is pre-indictment coercion — detention, arrest
or bail; **transferred for prosecution** (移送起诉) means the police have
handed the file to the procuratorate for examination; **public prosecution
initiated** (提起公诉) means an indictment has been filed. Only cases 6, 7
and 8 have reached the third stage. None of the ten has been tried.

## The tail

The release closes, as these posts usually do, with a promotion for the
**National Network Identity Authentication Public Service Platform**
(国家网络身份认证公共服务平台) — the state-run 网号/网证 scheme MPS built
with five other departments and governs through [MPS Order No.
173](/laws/network-identity-authentication-measures/), effective 15 July
2025.

The placement is not accidental. Cases 1 and 2 are both about harvesting
**real-name online accounts**: the value in them exists only because
platforms must verify identity and therefore hold the identity documents
that make an account resellable. A state authentication layer is the
policy answer to that specific failure — Article 8 of the Measures gives an
integrating platform the verification *result* rather than the document,
and Article 7 bars it from asking the user for plaintext identity
information on the side. Whether overseas-invested platforms will be
expected to adopt it, and on what terms, is the live question; Article 6
promises that existing authentication methods survive and Article 7
requires equal service for users who decline the scheme, but the pairing of
an enforcement batch with the platform pitch is a reasonable signal of the
direction of travel.

---

*Source: 净网专项行动 | 公安部网安局公布打击侵犯公民个人信息犯罪10起典型案例,
published by 公安部网安局 (MPS Cyber Security Bureau) on its WeChat Official
Account, 11 August 2026.
[Original](https://mp.weixin.qq.com/s/rbW_V3nuQ9x5axcLHw6pwg). Translated
and edited by DCC. Suspect names appear as redacted in the original;
ages and locality attributions are the bureau's own.*

— Not legal advice.
