On March 20, 2025, the Chinese government’s Ministry of Human Resources and Social Security website, mohrss.gov.cn, appeared on the leak site operated by the Babuk2 ransomware group. Internal files were allegedly exfiltrated during a ransomware attack, and the ministry’s data is now publicly listed for anyone who visits the group’s dark-web portal.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Ministry of Human Resources and Social
Get alerted the next time Ministry of Human Resources and Social files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Ministry of Human Resources and Social’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the incident involves the compromise of mohrss.gov.cn, the official online presence of China’s Ministry of Human Resources and Social Security. The Babuk2 group claims to have stolen internal files and has posted proof on its leak site. No exact victim count inside the ministry or among Chinese citizens has been disclosed. Available reporting describes the exposed material as internal documents rather than a structured database of citizen records, though the precise contents remain unverified by independent third parties. The listing date of March 20, 2025 is confirmed on the ransomware.live mirror of the Babuk2 leak site.
Why This Matters for You and Your Family
Even when a breach occurs on the other side of the world, the data can travel quickly. Government human-resources systems often contain employment records, national identification numbers, addresses, and contact details that criminals can link to ordinary families. If your own workplace, pension, or social-security records are tied to Chinese systems—or if you or relatives have interacted with similar services—the leaked files could accelerate identity theft, tax fraud, or spear-phishing campaigns. For families with overseas ties, the risk is concrete: one exposed government file can give attackers the exact personal details needed to impersonate you to banks, schools, or government agencies.
The Doxxing and Identity-Chain Implications
Ransomware leaks rarely stop at the first dataset. A single government file can contain email addresses, employee usernames, or internal phone numbers that match accounts on other platforms. Attackers then follow the chain—correlating leaked credentials with gaming logins, social-media handles, and family addresses. This is exactly how doxxing escalates: one breach exposes a work email, which unlocks a reused password on a shopping site, which reveals a home address, which leads to children’s online accounts. Credential leaks like this one routinely cascade into account takeovers because people reuse passwords across work, personal, and family gaming profiles.