PRODUCT

Design

Content

Publish

RESOURCES

Blog

Careers

Docs

About

Writings

社工库

社工库

"Social Engineering Attacks"

Preface: Internet surfing in 2026.


In late June 2022, a user calling himself ChinaDan listed a database for sale on an overseas hacker forum, asking 10 bitcoin. He claimed it was Shanghai police data — 23 terabytes, covering roughly a billion people: names, home addresses, birthplaces, national ID numbers, phone numbers, and even police reports. Several foreign media outlets called phone numbers from the sample data, and the people who picked up confirmed the information was theirs. According to security researchers, the database had been sitting open on the public internet for over a year, with no password. If true, this was one of the largest personal data leaks in human history. It never appeared in any of the usual rounds of published "typical cases." Related topics on Weibo soon became unsearchable, and the authorities have never responded to it directly. So what exactly sits at the very top of the supply chain feeding the databases used for doxxing?

I kept digging, and found that the most common type of database is called the "shegongku" — the social engineering database — which holds basic information on nearly everyone. "Shegong" is short for "social engineering." The term originally referred, in hacker circles, to getting information through deception rather than technical exploits — impersonating customer service to phish passwords, for example. Later, "shegongku" came to mean something specific: data leaked over the past decade-plus, collected, cleaned, and deduplicated, then stitched together using phone numbers, QQ numbers, email addresses, and national ID numbers as keys, linking everything the same person left behind in different places. Give it one clue, and it gives you back a person. Doxxing is taking such a database, looking up a specific person, and posting the results. The mid-March 2025 incident involving the daughter of a Baidu vice president drew the attention of several news organizations: where would a middle schooler have gotten this information? Within days, several outlets sent reporters to find the answer the same way — by buying it themselves.

Southern Metropolis Daily (March 19–20, front page). Reporters first searched Xiaohongshu and Weibo for censored keywords like "开X" and "人X," and found posts written in coded slang hinting that they could look up the "three elements of personal information" (name, phone number, national ID number), household registration records, and hotel check-in records. All the posts pointed to a group on an overseas platform. The report didn't name the platform — generally understood to be Telegram. The groups operate on two levels. Basic information, like QQ numbers and phone IMEIs, is answered automatically by bots; for more sensitive data, the bots direct you to a "customer service" contact. One group the reporter saw had as many as 280,000 members, with several hundred new doxxing requests submitted within an hour.

With a colleague's authorization, the reporter used her as a test subject. Customer service quoted: give a name and phone number, get the national ID number — 80 yuan; a screenshot of the household registration record — 240 yuan. The reporter paid via Alipay, and the ID number arrived in under a minute; four hours later the household registration screenshot came through. The screenshot showed the colleague's ID photo taken in Zhanjiang when she was in middle school, along with her education level; another version listed two addresses, precise down to the building: one was her employer-provided dormitory in Foshan, the other was home. The colleague checked and confirmed everything was accurate. Customer service said: "Most databases are inaccurate — ours is real-time." They claimed the 240 yuan was the fee for a "household registration screenshot from the public security website." The Beijing News followed with an editorial saying this claim could be true or could be a sales pitch, but given how fresh and accurate the information was, there was reason to suspect an insider, and it should be investigated on the presumption that it was true. The reporter called the police, whose reply was that "this method involves technical issues, and the situation will be reported to higher-level departments."

The most valuable items on the doxxing price list are full-family household registration records, marriage records, hotel check-in records, movement trajectories, phone location tracking, and property under one's name. Hotel records cost upwards of ten thousand yuan; WeChat chat histories, three thousand. The people behind the social engineering databases themselves claim to have "insiders in public security, banking, and other sectors assisting with queries." Looking into related cases, examples do turn up: a first-grade police officer in Dayi County, Sichuan, used his department-issued digital certificate and mobile policing terminal to look up household registration and vehicle registration information for sale between 2019 and 2020, making over 550,000 yuan in illicit gains, and was sentenced to three years and eight months. There have also been cases involving bank presidents, account managers, real estate platforms, and courier employees.

What is striking is the structure of the price list itself. Full-family household registration records come from the public security population information system. Hotel check-in records exist because hotels are required to upload every guest's ID to the public security hotel-industry security management system in real time. Movement trajectories come from real-name train and flight ticket purchases; phone location tracking comes from carriers' real-name registration. In other words, the most expensive items are all things collected by force under real-name registration rules and stored centrally. What the black market sells is query access — and that access can be sold precisely because there is a single, unified database to query.

As major privacy breach cases continued to unfold, China's privacy-related regulations gradually became more complete.

On the individual side, the 2009 Criminal Law Amendment (VII) first wrote the sale of personal information into the criminal code, with a maximum sentence of three years. The provision initially applied narrowly — only to specific people: state organs, or staff of units in finance, telecommunications, transportation, education, healthcare, and the like. The 2015 Criminal Law Amendment (IX) opened it up to anyone, raising the maximum to seven years, with heavier punishment for insiders. A 2017 judicial interpretation then halved the threshold for insiders: it takes 5,000 records to convict an ordinary person, but only 2,500 for an insider.

On the corporate side, the unit of fines kept growing. The 2013 revision of the Consumer Rights Protection Law began fining businesses that leaked consumer information — up to 500,000 yuan where there were no illegal gains. The Cybersecurity Law, effective 2017, mentioned one million yuan. The 2021 Personal Information Protection Law changed the formula: no longer a fixed number, but 50 million yuan or five percent of the previous year's revenue, plus fines of up to one million yuan on the directly responsible persons in charge. The October 2025 amendment to the Cybersecurity Law raised fine brackets for network operators across the board — for example, failure to fulfill security protection obligations went from 10,000–50,000 yuan to 50,000–500,000 yuan.

On June 30, 2021, Didi listed on the New York Stock Exchange, raising about $4.4 billion — the largest U.S. IPO by a Chinese company in those years. According to multiple later reports, regulators had advised Didi to delay the listing; Didi didn't wait. Two days after the listing, on July 2, the Cybersecurity Review Office announced a cybersecurity review of Didi, citing the National Security Law and the Cybersecurity Law, on the grounds of "preventing national data security risks." On July 4, the Cyberspace Administration of China (CAC) reported that the "Didi Chuxing" app had serious violations in collecting and using personal information, ordered app stores to delist it, and Didi halted new user registration. On July 16, seven departments — cyberspace, public security, national security, natural resources, transportation, taxation, and market regulation — jointly moved into Didi to conduct the review. That December, Didi announced it would delist from the NYSE, completing the process in June 2022 — listed for less than a year.

On July 21, 2022, the CAC announced its penalty decision: Didi Global Inc. was fined 8.026 billion yuan, and chairman and CEO Cheng Wei and president Jean Liu were each fined 1 million yuan. The decision invoked four laws together: the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law, and the Administrative Penalty Law. On January 16, 2023, Didi resumed new user registration — 563 days from the start of the review.

In its Q&A with reporters, the CAC grouped the 16 illegal acts into 8 categories:

  1. Illegally collecting screenshots from users' phone photo albums — 11.9639 million entries.

  2. Excessively collecting clipboard information and lists of installed apps — 8.323 billion entries.

  3. Excessively collecting passengers' facial recognition data (107 million entries), age brackets (53.5092 million), occupations (16.3356 million), family relationships (1.3829 million), and "home" and "work" ride addresses (153 million).

  4. Excessively collecting precise location (latitude and longitude) — 167 million entries — when passengers rated designated-driver services, when the app ran in the background, and when phones connected to Orange Vision dashcams.

  5. Excessively collecting drivers' education information (142,900 entries), and storing 57.8026 million drivers' national ID numbers in plaintext.

  6. Analyzing passengers' travel intent (53.976 billion entries), cities of residence (1.538 billion), and out-of-town business or leisure travel (304 million) without clearly informing passengers.

  7. Repeatedly requesting "phone permission" unrelated to the service when passengers used Hitch.

  8. Failing to accurately and clearly explain the purposes of processing 19 categories of personal information.

Altogether, 64.709 billion entries of personal information were illegally processed. The violations began as early as June 2015 and lasted seven years. "Plaintext storage" means no encryption — anyone who could get into the database could read the ID numbers of more than 50 million drivers directly. "Analyzing travel intent" means Didi inferred from your ride history whether you were traveling for business, leisure, or heading home — inferring it more than 50 billion times, without you knowing. In the Q&A, the CAC said Didi also "engaged in data processing activities seriously affecting national security," but that "as it involves national security, it is not disclosed in accordance with the law."

In other words, all 16 items the public saw were personal information issues — but those were not what triggered the review. What triggered it was another part, whose contents have never been made public. The widespread outside speculation is that Didi's data on the national road network, ride heat maps, and the surroundings of sensitive locations could have been subject to U.S. disclosure rules after the U.S. listing — but that is only speculation, with no official account. The official characterization of the matter also used the language of national security: the violations "disregarded national cybersecurity and data security," were "extremely egregious in nature," and "should be punished severely."

As for the fine, all the money went to the state treasury — users got nothing. The 64.7 billion illegally processed entries belonged to hundreds of millions of real people, but administrative fines include no compensation, and there was no accompanying class action. China has no U.S.-style class action system, and the procuratorate's public interest litigation never appeared in this case. This fine was not really a privacy case. As a commentary in the cybersecurity outlet Anquan Neican put it, the "maximum penalty" reflected the risks Didi posed to the security of national critical information infrastructure and to data security. Had Didi not listed in New York, these problems would likely never have been surfaced in this way, at this moment. The same commentary also acknowledged that these 8 categories of violations were "by no means unique to Didi." Photo albums, clipboards, app lists, background location tracking — these were industry-wide practices across Chinese apps at the time. That only Didi was punished, and punished to the maximum, itself reveals what the trigger for enforcement was. The company wasn't shut down, and business resumed. Didi's license was never revoked. After a year and a half of rectification, the app was relisted, and today it remains China's largest ride-hailing platform.📖

Preface: 老年人尝试适应网上冲浪记录之二。


2022 年 6 月底,一个叫 ChinaDan 的用户在境外的黑客论坛上挂出一个数据库,要价 10 个比特币。他声称这是上海公安的数据,23TB,涉及大约 10 亿人:姓名、住址、出生地、身份证号、手机号,还有报案记录。几家外国媒体拿样本里的电话号码打过去,接电话的人确认了自己的信息。据安全研究人员说,这个库此前在公网上敞开了一年多,没有设密码。如果属实,这是人类历史上最大的一次个人数据泄露之一。它没有出现在任何一批典型案例里。微博上相关的话题很快搜不到了,官方至今没有正面回应过。开盒用的那些库,最上游到底是什么?

我继续搜索,发现最常见的信息库叫”社工库“,里面有几乎所有人的基础信息。"社工"是"社会工程学"(social engineering)的缩写。这个词原本在黑客圈里指不靠技术漏洞、靠骗人拿信息,比如冒充客服套密码。后来"社工库"专指一种东西:把十几年来各种泄露出来的数据收集起来,清洗、去重,再用手机号、QQ 号、邮箱、身份证号当钥匙,把同一个人在不同地方留下的信息串到一起。你给它一条线索,它还给你一个人。开盒就是拿这种库去查一个具体的人,再把结果挂出来。前面提到的2025 年 3 月中旬的百度副总裁女儿事件引起了一些新闻机构的重视:一个初中生从哪儿拿到的这些信息?几天之内,好几家媒体派记者用同一种办法去找答案:亲自去买一次。

南方都市报(3 月 19 至 20 日,头版)。记者先在小红书、微博上搜"开X""人X"这类打了码的关键词,找到一些用黑话写的帖子,暗示能查"个人信息三要素"(姓名、手机号、身份证号)、户籍、开房记录。这些帖子都指向一个海外平台上的群组。报道没点名是哪个平台,一般指 Telegram。群里的运作分两层。基础信息,比如 QQ 号、手机 IMEI,由机器人自动回复;想要更隐秘的,机器人会引导你去加"客服"。记者看到的一个群最多有 28 万人,一小时内就有几百人往里提交要开的人。

记者经一位同事授权,用她当测试对象。客服报价是:给姓名和手机号,出身份证号,80 元;户籍截图,240 元。记者用支付宝付款,不到一分钟身份证号就发了过来,四小时后户籍截图也到了。截图上有这位同事初中时在湛江拍的证件照和文化程度记录,另一个版本还列出两个住址,精确到楼栋:一个是她在佛山工作时的单位宿舍,一个是家。同事核对后确认,全部准确。客服说:"数据库很多都不准,我们是实时的。"他们声称 240 元是"公安网站户籍截图"的费用。新京报随后发社论说,这个说法可能是真的,也可能是招揽生意的话术,但信息这么新、这么准,有理由怀疑背后有内鬼,应当"宁信其有"去查。记者报了警,警方的回复是"该手法涉及技术问题,会把情况反馈给上级部门"。

开盒价目表上最值钱的几项是全家户籍、婚姻记录、开房记录、人身轨迹、手机号定位和名下财产。开房记录要花上万元,微信聊天记录要三千。社工库的人自己声称"在警务、银行等领域有内部人员协助查询"。查查相关的案件,确实可以找到例子:四川大邑县一名一级警员,在 2019 到 2020 年间用单位配发的数字证书和移动警务终端查户籍和车辆登记信息出售,违法所得五十五万多元,判了三年八个月。银行行长、客户经理、房产中介平台、快递员工的案子也都有。

值得注意的是这张价目表本身的结构。全家户籍来自公安的人口信息系统。开房记录之所以存在,是因为旅馆必须把每位住客的身份证实时上传到公安的旅馆业治安管理系统。轨迹来自火车、飞机的实名购票,手机定位来自运营商的实名登记。也就是说,最贵的那几项数据,都是实名制强制收集、集中存放的东西。黑产卖的是查询权限,而这种权限之所以能卖,是因为有一个统一的库可以查。

随着重大隐私泄露案件的发酵,中国的隐私法相关规定也逐渐完善。

个人方面,2009 年《刑法修正案(七)》第一次把出售个人信息写进刑法,最高刑是三年。这条罪一开始的适用范围很窄,只管特定的人:国家机关,或者金融、电信、交通、教育、医疗等单位的工作人员。2015 年《刑法修正案(九)》把范围放开到任何人,最高刑提到七年,内部人员从重处罚。2017 年的司法解释又把内部人员的入罪门槛减半:普通人卖五千条才够判,内部人员两千五百条就够了。

企业方面,罚款的计算单位一路变大。2013 年修订的《消费者权益保护法》开始对泄露消费者信息的经营者罚款,没有违法所得的,最高五十万元。2017 年施行的《网络安全法》提到一百万元。2021 年的《个人信息保护法》换了计算方式,不再是一个固定数字,而是五千万元或者上一年度营业额的百分之五,同时对直接负责的主管人员个人处以最高一百万元的罚款。2025 年 10 月《网络安全法》修正,又把网络运营者的各档罚款普遍上调,比如不履行安全保护义务,从一万到五万,改成了五万到五十万。

2021 年 6 月 30 日,滴滴在纽约证券交易所上市,募资约 44 亿美元,是那几年中国公司在美国最大的一次 IPO。据后来的多方报道,监管部门此前曾建议滴滴暂缓上市,滴滴没有等。上市两天后,7 月 2 日,网络安全审查办公室宣布对滴滴启动网络安全审查,依据是《国家安全法》和《网络安全法》,理由是"防范国家数据安全风险"。7 月 4 日,网信办通报"滴滴出行"App 存在严重违法违规收集使用个人信息的问题,通知各应用商店下架,滴滴停止新用户注册。7 月 16 日,网信、公安、国安、自然资源、交通运输、税务、市场监管七个部门联合进驻滴滴,开展审查。同年 12 月,滴滴宣布从纽交所退市,2022 年 6 月完成摘牌,上市不到一年。

2022 年 7 月 21 日,网信办公布处罚决定:滴滴全球股份有限公司罚款 80.26 亿元,董事长兼 CEO 程维、总裁柳青各罚 100 万元。依据是《网络安全法》《数据安全法》《个人信息保护法》和《行政处罚法》四部法律一起用。2023 年 1 月 16 日,滴滴恢复新用户注册。从审查启动算起,一共 563 天。

网信办在答记者问中把 16 项违法事实归成 8 个方面:

  1. 违法收集用户手机相册里的截图,1196.39 万条。

  2. 过度收集用户剪切板信息和手机里装了哪些应用,83.23 亿条。

  3. 过度收集乘客的人脸识别信息 1.07 亿条、年龄段 5350.92 万条、职业 1633.56 万条、亲情关系 138.29 万条、"家"和"公司"的打车地址 1.53 亿条。

  4. 乘客在评价代驾服务、App 在后台运行、手机连接桔视记录仪时,过度收集精准位置(经纬度),1.67 亿条。

  5. 过度收集司机学历信息 14.29 万条,以明文形式存储司机身份证号 5780.26 万条。

  6. 在未明确告知乘客的情况下分析乘客出行意图 539.76 亿条、常驻城市 15.38 亿条、异地商务和异地旅游 3.04 亿条。

  7. 乘客使用顺风车时,频繁索取与服务无关的"电话权限"。

  8. 未准确、清晰地说明 19 项个人信息的处理目的。

违法处理的个人信息合计 647.09 亿条。违法行为最早从 2015 年 6 月开始,持续了七年。"明文存储"的意思是没有加密,谁能进数据库,谁就能直接读到五千多万名司机的身份证号。"分析出行意图"的意思是,滴滴根据你的打车记录推断你是出差、旅游还是回家,推断了五百多亿次,而你不知道。答记者问时,网信办回答说,滴滴"还存在严重影响国家安全的数据处理活动",但"因涉及国家安全,依法不公开"。

也就是说,公众看到的 16 项全是个人信息问题,但这些并不是启动审查的原因。启动审查的是另一部分,内容至今没有公开。外界普遍的推测是,滴滴掌握的全国道路、出行热力、敏感地点周边的数据,在美国上市后可能受到美国信息披露规则的影响,但这只是推测,没有官方说法。官方对这件事的定性用的也是国家安全的语言:违法行为"置国家网络安全、数据安全于不顾","性质极为恶劣","应当从严从重予以处罚"。

罚款方面,所有钱都交给了国库,用户什么也没得到。 647 亿条违法处理的信息属于几亿个具体的人,但行政罚款不含任何赔偿,也没有配套的集体诉讼。中国没有美国那种集体诉讼制度,检察院的公益诉讼在这个案子里也没有出现。这笔罚单主要不是隐私案。 安全内参的评论说到:"顶格处罚"考虑的是滴滴给国家关键信息基础设施安全和数据安全带来的风险。如果滴滴没有去纽约上市,这些问题很可能不会以这种方式、在这个时间点被翻出来。同一篇评论也承认,这 8 类违法行为"绝不是滴滴所独有的"。相册、剪切板、应用列表、后台定位,是当时整个中国 App 行业的普遍做法。只罚滴滴,而且罚到顶格,这件事本身就说明了执法的触发条件是什么。公司没关,业务恢复了。 滴滴没有被吊销执照。整改一年半之后,App 重新上架,今天仍是中国最大的网约车平台。📖

Preface: Internet surfing in 2026.


2022年6月末、「ChinaDan」と名乗るユーザーが海外のハッカーフォーラムにデータベースを出品し、10ビットコインの値をつけた。上海公安のデータだと称し、容量は23TB、氏名・住所・出生地・身分証番号・携帯番号、それに通報記録など、約10億人分が含まれているという。海外メディア数社がサンプル内の電話番号に実際に電話をかけたところ、応対した人々は自分の情報であることを認めた。セキュリティ研究者によれば、このデータベースはそれ以前の1年以上にわたり、パスワードも設定されずに公開インターネット上に晒されていたという。事実なら、人類史上最大級の個人情報漏洩の一つとなる。ところが、典型事例を集めたどのリストにも載っていない。微博(ウェイボー)上の関連トピックはすぐに検索できなくなり、当局は今日に至るまで正面から回答していない。「開盒」に使われるそれらのデータベース、その最上流は一体何なのか。

調べを進めると、最もよく使われている情報データベースは「社工庫」と呼ばれ、ほぼすべての人の基礎情報を収めていることがわかった。「社工」とは「社会工学」(ソーシャルエンジニアリング)の略だ。この言葉はもともとハッカー界隈で、技術的な脆弱性を突くのではなく人を騙して情報を取る手口——たとえば客服(カスタマーサポート)を装ってパスワードを聞き出すような——を指した。やがて「社工庫」は特定のものを指すようになる。十数年の間に流出したデータをかき集め、洗浄・重複排除したうえで、携帯番号・QQ番号・メールアドレス・身分証番号を鍵にして、同一人物があちこちに残した情報を紐づける。手がかりを一つ渡せば、一人の人間が返ってくる。「開盒」とは、この種のデータベースで特定の個人を調べ、その結果を晒すことだ。前述の2025年3月中旬の百度(バイドゥ)副総裁の娘をめぐる事件は、いくつかの報道機関の注目を集めた。中学生がどこからこんな情報を手に入れたのか。数日のうちに、複数のメディアが記者を送り、同じ方法で答えを探しに行った。自ら買ってみる、という方法で。

南方都市報(3月19日・20日、一面)。記者はまず小紅書(RED)や微博で「開X」「人X」といった伏せ字のキーワードを検索し、隠語で書かれた投稿を見つけた。「個人情報三要素」(氏名・携帯番号・身分証番号)や戸籍、ホテルの宿泊記録を調べられる、と匂わせる内容だ。これらの投稿はどれも、海外プラットフォーム上のグループへ誘導していた。報道はプラットフォーム名を明かしていないが、一般的にはTelegramを指す。グループ内の運営は二層構造だ。QQ番号や携帯のIMEIといった基礎情報はボットが自動返信し、より秘匿性の高い情報を求めると、ボットが「客服」への追加を促す。記者が確認したあるグループは最大28万人規模で、1時間のうちに数百人が「開盒」の対象者を投稿していた。

記者は同僚一人の許可を得て、彼女を実験対象にした。客服の料金はこうだ。氏名と携帯番号を渡せば身分証番号が出てくる、80元。戸籍のスクリーンショットは240元。記者がアリペイで支払うと、1分も経たないうちに身分証番号が送られてきて、4時間後には戸籍のスクリーンショットも届いた。スクリーンショットには、この同僚が中学生の頃に湛江で撮影した証明写真と学歴の記録があり、別のバージョンには住所が二つ、棟番号まで正確に記載されていた。一つは仏山で働いていた頃の社員寮、もう一つは実家だ。同僚が照合したところ、すべて正確だった。客服は言った。「データベースは不正確なものが多いけど、うちはリアルタイムだから」。240元は「公安サイトの戸籍スクリーンショット」の料金だという。新京報はその後社説で、この主張は本当かもしれないし、客寄せの売り文句かもしれないが、情報がこれほど新しく正確なら、内部に協力者がいる疑いは拭えず、「寧ろあると信じて」調査すべきだと論じた。記者は警察に通報したが、返ってきた答えは「その手口は技術的な問題を含むため、状況を上級部門にフィードバックする」というものだった。

「開盒」の料金表で最も高額なのは、全家族の戸籍、婚姻記録、ホテルの宿泊記録、移動履歴、携帯番号の位置特定、名義財産だ。宿泊記録は1万元以上、WeChatのチャット履歴は3000元かかる。社工庫の関係者は自ら「警察・銀行などの分野に内部協力者がいて照会を手伝っている」と称している。関連事件を調べると、確かに例が見つかる。四川省大邑県の一級警員は、2019年から2020年にかけて、支給されたデジタル証明書とモバイル警察端末を使って戸籍や車両登録情報を照会して販売し、違法所得55万元あまりを得て、懲役3年8ヶ月の判決を受けた。銀行の頭取や顧客担当者、不動産仲介プラットフォーム、宅配業者の事件もある。

注目すべきは、この料金表そのものの構造だ。全家族の戸籍は公安の人口情報システムに由来する。宿泊記録が存在するのは、ホテルが宿泊客全員の身分証を公安の旅館業治安管理システムにリアルタイムでアップロードしなければならないからだ。移動履歴は鉄道・航空機の実名購入に、携帯の位置情報は通信事業者の実名登録に由来する。つまり、最も高額な項目のデータはすべて、実名制によって強制的に収集され、一元的に保管されているものだ。闇ビジネスが売っているのは照会権限であり、その権限が売れるのは、照会できる統一データベースが存在するからだ。

重大なプライバシー漏洩事件が相次ぐなかで、中国のプライバシー関連法制度も徐々に整備されてきた。

個人に対する規制では、2009年の『刑法修正案(七)』が初めて個人情報の販売を刑法に書き込み、最高刑は3年だった。この罪の適用範囲は当初きわめて狭く、対象は特定の人々に限られた。国家機関、あるいは金融・通信・交通・教育・医療などの機関の職員だ。2015年の『刑法修正案(九)』で範囲はすべての人に広がり、最高刑は7年に引き上げられ、内部関係者は重く処罰されることになった。2017年の司法解釈ではさらに、内部関係者の入罪ハードルが半減した。一般人が5000件売ってようやく処罰対象になるのに対し、内部関係者は2500件で足りる。

企業に対する規制では、罰金の計算単位がどんどん大きくなった。2013年改正の『消費者権益保護法』は、消費者情報を漏洩させた事業者への罰金を定め、違法所得がない場合の上限は50万元だった。2017年施行の『網絡安全法(サイバーセキュリティ法)』では100万元とされた。2021年の『個人情報保護法』では計算方式が変わり、固定額ではなく5000万元または前年度売上高の5%となり、直接の責任を負う主管者個人にも最高100万元の罰金が科されることになった。2025年10月の『網絡安全法』改正では、ネットワーク運営者に対する各段階の罰金が軒並み引き上げられ、たとえば安全保護義務の不履行は1万元〜5万元から5万元〜50万元に改められた。

2021年6月30日、滴滴(DiDi)はニューヨーク証券取引所に上場し、約44億ドルを調達した。当時の中国企業による米国上場としては最大級のIPOだった。後の複数の報道によれば、規制当局は事前に滴滴へ上場延期を勧めていたが、滴滴は待たなかった。上場から2日後の7月2日、網絡安全審査弁公室(サイバーセキュリティ審査弁公室)は滴滴に対するネットワークセキュリティ審査の開始を発表した。根拠は『国家安全法』と『網絡安全法』、理由は「国家データセキュリティのリスク防止」だった。7月4日、国家インターネット情報弁公室(CAC)は「滴滴出行」アプリに個人情報の深刻な違法収集・利用があると通報し、各アプリストアに削除を通知、滴滴は新規ユーザー登録を停止した。7月16日には、インターネット情報・公安・国家安全・自然資源・交通運輸・税務・市場監督の7部門が合同で滴滴に入り、審査を行った。同年12月、滴滴はニューヨーク証券取引所からの上場廃止を発表し、2022年6月に上場廃止手続きを完了した。上場期間は1年にも満たなかった。

2022年7月21日、国家インターネット情報弁公室は処分決定を公表した。滴滴グローバル株式会社に80億2600万元、董事長兼CEOの程維(チェン・ウェイ)と総裁の柳青(リュウ・チン)にそれぞれ100万元の罰金だ。根拠は『網絡安全法』『データセキュリティ法』『個人情報保護法』『行政処罰法』の4法を併用したものだった。2023年1月16日、滴滴は新規ユーザー登録を再開した。審査開始から起算して、計563日間だった。

国家インターネット情報弁公室は記者会見での質疑応答で、16項目の違法事実を8つの側面に整理した。

  1. ユーザーの携帯電話のアルバム内のスクリーンショットを違法に収集、1196万3900件。

  2. ユーザーのクリップボード情報やインストール済みアプリを過剰に収集、8億3230万件。

  3. 乗客の顔認証情報1億700万件、年齢層5350万9200件、職業1633万5600件、親族関係138万2900件、「自宅」や「会社」の配車住所1億5300万件を過剰に収集。

  4. 乗客が代行運転サービスを評価する際、アプリがバックグラウンドで動作する際、携帯電話が桔視ドライブレコーダーに接続する際に、精密な位置情報(緯度経度)を過剰に収集、1億6700万件。

  5. 運転手の学歴情報を過剰に収集14万2900件、運転手の身分証番号5780万2600件を平文で保存。

  6. 乗客に明確に告知しないまま、乗客の移動意図539億7600万件、常駐都市15億3800万件、他地域での出張・観光3億400万件を分析。

  7. 乗客が相乗りサービスを利用する際、サービスと無関係な「電話権限」を頻繁に要求。

  8. 19項目の個人情報について、処理目的を正確かつ明確に説明しなかった。

違法に処理された個人情報は合計647億900万件にのぼる。違法行為は早いもので2015年6月に始まり、7年間続いた。「平文保存」とは暗号化されていないという意味で、データベースにアクセスできる者なら誰でも、5780万人を超える運転手の身分証番号をそのまま読み取れるということだ。「移動意図の分析」とは、滴滴があなたの配車記録から出張・観光・帰宅のいずれかを推測することで、539億7600万回もの推測を行いながら、あなたは何も知らされていなかったということだ。記者会見での質疑で、国家インターネット情報弁公室は、滴滴には「国家安全に重大な影響を及ぼすデータ処理活動」も存在したが、「国家安全に関わるため、法に基づき公開しない」と回答した。

つまり、公衆の目に触れた16項目はすべて個人情報の問題だが、これらが審査開始の理由ではない。審査を開始させたのは別の部分で、その内容は今日に至るまで公開されていない。外部では、滴滴が保有する全国の道路網・移動ヒートマップ・機微な場所の周辺データが、米国上場後に米国の情報開示ルールの影響を受ける可能性があると広く推測されているが、あくまで推測であり、公式の説明はない。当局によるこの件の位置づけも、国家安全の言葉で語られた。違法行為は「国家のネットワークセキュリティとデータセキュリティを顧みず」、「性質は極めて悪質」であり、「厳しく重く処罰すべき」とされた。

罰金については、全額が国庫に納められ、ユーザーは何も得なかった。違法に処理された647億件超の情報は、数億人の具体的な個人に帰属するものだが、行政罰金にはいかなる賠償も含まれず、それに対応する集団訴訟も存在しない。中国には米国のような集団訴訟制度がなく、検察による公益訴訟もこの案件では提起されなかった。この罰金は、主としてプライバシーの案件ではない。『安全内参』の論評はこう述べている。「上限いっぱいの処罰」が考慮したのは、滴滴が国家の重要情報インフラの安全とデータセキュリティにもたらしたリスクだ。滴滴がニューヨークに上場していなければ、これらの問題がこのような形で、このタイミングで掘り起こされることはおそらくなかった。同じ論評は、この8類型の違法行為が「滴滴に特有のものでは決してない」ことも認めている。アルバム、クリップボード、アプリ一覧、バックグラウンドでの位置情報取得は、当時の中国アプリ業界全体の普遍的なやり方だった。滴滴だけを罰し、しかも上限いっぱいに罰したという事実そのものが、法執行の引き金が何だったかを物語っている。会社は潰れず、事業は回復した。滴滴の営業許可が取り消されることはなかった。1年半の是正を経てアプリは再びストアに戻り、今日も中国最大の配車プラットフォームであり続けている。📖