Alibaba's Chinese shopping business Taobao suffered a data breach after a Chinese software developer used web crawling software to obtain 1.1 billion pieces of data, including usernames and mobile phone numbers . The Wall Street Journal (WSJ) reported the massive data leak on June 15, citing a Chinese court ruling.
Specifically, the WSJ reported a recent ruling made by a district court in central Henan, China, which stated that among the data exposed in the data breach were user IDs, mobile phone numbers, and user comments.
The court reported the data breach to police after Alibaba noticed the suspicious activity. Taobao is one of the most popular shopping platforms in China. According to the company, about 925 million people use Taobao and other Alibaba retail sites every month.

Also read: Alibaba Concerned About Apple's App Tracking Transparency
The ruling did not find Alibaba liable for the leak, but it could face administrative sanctions under China's 2017 Cybersecurity Law, said Yuyunting, a senior fellow at Deband's Shanghai office.
According to a complaint filed in a court in Henan province, a software developer named Lu scraped the siteusing a tool developed on the Taobao platform in 2019. Lu began extracting some of the user data on the site, which was then handed over to Lu’s employer. The WSJ reported that a promotion company that worked with Taobao merchants was behind the operation. According to the report, the employer used the data to find new customers and solicit Taobao coupons.
The WSJ reported that both Lu and his unnamed employer were sentenced to more than three years in prison. Chinese court rulings are generally published months later and usually contain only the last name.
See also: Alibaba's browser removed from Chinese app stores

Massive data leaks, in which consumer data is exposed, have become a common occurrence in China in recent yearsas the country's data security regulations struggle to keep up with technological advances. Personal information from these leaks is often sold on the black market, which has led to a new privacy movement among Chinese citizens.
Chinese lawmakers have been pushing for more oversight, aiming to better protect personal data. Last week, China enacted a new data security lawto strengthen Beijing's control over data flows within the country and improve consumer data protection.
Proposal: Ireland's Data Protection Commission (DPC) investigates Facebook data leak

The law, along with proposed legislation based on the European Union's General Data Protection Regulation, aims to strengthen data regulations, such as the Cybersecurity Law enacted in 2017. China's new data security law was passed in April. The law, which follows on from the 2017 Cybersecurity Law, will come into effect on September 1.
Many tech giants, including Facebook, have also been hit by serious data breaches. In April, Facebook accused “malicious actors” of scraping data, including the names and phone numbers of more than 530 million users. Legal and privacy experts said at the time that the social media giant chose to describe the incident as data scraping rather than hacking to avoid triggering laws and regulations in various jurisdictions that require companies to report data leaks to both regulators and the public.
