SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach KAZAKHSTAN-15M-CIT 2026-08-14

Kazakhstan eGov: Alleged 15 Million Citizen Data Sale

"A threat actor has advertised a dataset on the dark web claiming to hold the personal data of roughly 15 million Kazakhstani citizens, presenting it as the product of an intrusion into eGov, the country's national…"

A threat actor has advertised a dataset on the dark web claiming to hold the personal data of roughly 15 million Kazakhstani citizens, presenting it as the product of an intrusion into eGov, the country's national e-government platform. Kazakhstan's Ministry of Artificial Intelligence and Digital Development has acknowledged the listing and opened a technical verification, but says it has found no evidence that state e-services were breached. What is confirmed at this point is the existence and content of the advertisement, not the breach behind it. Given a national population of roughly 20 million and an eGov registered-user base that Undercode News puts at more than 15 million, an authentic dataset of this size would amount to near-total exposure of the adult citizenry.

What Happened

The sale was first surfaced by the Russian Telegram channel Mash. The Diplomat notes that RFE/RL, in reporting the Mash post, characterized the channel as linked to Russian security forces, which is a provenance caveat worth carrying through the rest of the analysis: the initial disclosure did not come from a security researcher, a victim notification, or a CERT.

Per infohub.kz and news.az, the listing was posted by a seller using the handle shymzz13, offering a 2.7 GB file for 0.5 bitcoin, roughly $32,000. The Times of Central Asia and The Diplomat report the same price point and the same eGov-breach claim from the seller.

The ministry's response has been consistent across outlets but stops well short of a clean denial or a clean confirmation. In a Telegram statement quoted by The Diplomat, the ministry said there was "no confirmed evidence of a breach of e-government" systems. infohub.kz reports the ministry confirmed it is running technical verification alongside specialized services, analyzing the seller's data samples and attempting to identify the source. The Times of Central Asia reports a preliminary review found no evidence government e-services were breached. Undercode News frames the ministry's position more strongly, as a denial that the data originated from eGov at all.

The most technically substantive part of the official response, reported by The Times of Central Asia, is that the ministry disputes the seller's own field list: eGov does not store scanned passport copies in the form described, and its digital documents have a different structure. That is a falsifiable claim about schema rather than a reputational denial, and it is the single strongest argument in the sources against the eGov attribution. Kazakh law reinforces it. Law No. 44-VIII ZRK, effective 11 February 2024, prohibits the collection and processing of physical copies of identity documents, so a current government system holding bulk passport scans would itself be a compliance anomaly.

What Was Taken

Treat every figure below as seller-claimed and unverified.

The advertised contents, consistent across infohub.kz, news.az, and The Times of Central Asia, are passport details, phone numbers, email addresses, places of employment, document scans, and passwords. The Diplomat's rendering of the same listing differs slightly, citing passport information, phone numbers, email addresses, document scans, and website passwords, with no mention of employment data.

The record counts do not reconcile cleanly and should not be collapsed into a single number. The headline figure of 15 million refers to people. The file itself is described as containing 47 million rows or records, per infohub.kz, news.az, and The Times of Central Asia. Those are compatible only if the dataset carries multiple rows per subject, which is itself a signature of aggregation rather than a single clean database export. The Times of Central Asia states plainly that the 15 million figure has not been independently confirmed.

Population share is also reported inconsistently. infohub.kz and news.az both describe 15 million as roughly three-quarters of the country's population; The Diplomat and Undercode News describe it as approaching the full national or registered-user scale without a fraction. Undercode News makes the sharpest analytical point available in the source set: a dataset whose size closely matches a platform's registered-user count is exactly what a fabricated or aggregated listing would be engineered to look like, because that similarity is what makes an underground advertisement read as credible on first glance.

Accounts Differ

There is real conflict here, and it should be stated rather than smoothed over.

The seller says eGov was hacked. The ministry says there is no evidence of that and that the described data structure does not match eGov's. No independent researcher cited in any of these sources has validated a sample against live government records. Undercode News is explicit that the ministry's denial does not prove the records are fabricated; it only shifts the question from "do 15 million records exist" to "where did they come from, how old are they, and were they ever obtained through an intrusion at all."

Kazakhstan's recent history strongly favors the aggregation hypothesis over the single-breach hypothesis. In the summer of 2025, the personal data of around 16 million Kazakhstanis appeared online. The same ministry concluded at the time that this was most likely not a hack of state systems but the unlawful use of legitimate access to government databases, and a subsequent review found most of the information had already been exposed back in 2022. The Times of Central Asia reports the Health Ministry's finding that a comparable 16 million record dataset, containing names, IINs, addresses and phone numbers, had been compiled from various sources possibly including medical organization systems, with any medical-origin data predating 1 April 2024.

In June 2026, police in the Zhetysu region seized a database of nearly 16 million citizen records, covering IINs, phone numbers and residential addresses, from employees of a debt-collection agency. That case is being worked jointly by internal affairs, the prosecutor's office and the National Security Committee. Vice Minister Doszhan Musaliyev told Tengrinews his working assumption was that those 16 million records were "accumulated over years, possibly even decades," likely from a single database circulating on the darknet, while explicitly labeling it an assumption.

Separately, news.az reports two eGov-specific trust incidents: in early August 2026 the service reportedly allowed users to view other people's personal pages, and in the spring a Kazakh financier who registered a company through the platform began receiving advertising calls within hours. Neither is confirmed as the source of this dataset, but both are the kind of leakage that feeds aggregated corpora over time.

Why It Matters

For defenders, the strategic lesson is not "did eGov get popped." It is that a country can reach a state of effectively total citizen-data exposure without any single catastrophic intrusion. Years of insider misuse, over-broad legitimate access, third-party processors like collection agencies, and historical breaches from 2022 compound into a corpus that is functionally equivalent to a national database dump. At that point, the denial and the harm become disconnected: the ministry can be entirely correct that eGov was not breached while citizens face the same downstream fraud risk.

The downstream risk is concrete rather than theoretical. infohub.kz reports Kazakh security experts' concern that this dataset could be bought by fraud call centers that have used similar data before, and cites a case in which scammers who mistook Kazakhstan for Russia manipulated pensioners in Pavlodar into detonating an explosion at a bank. Passport details plus IINs plus phone numbers plus employment data is a full social-engineering kit, and if the document scans are genuine it also supports KYC bypass and synthetic identity creation at scale.

There is also a regional threat context, though it should not be causally linked to this listing without evidence. Kaspersky's Securelist reports tracking two previously undocumented backdoors, OctLurk and SilkLurk, used against government organizations across Central Asia since January 2025, with identified victims in Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, Afghanistan and Syria, spanning ministries, law enforcement, healthcare, research and public education. Kaspersky assesses with medium confidence that a single Chinese-speaking actor operates both, and has not attributed the activity to a known group. Nothing in the sources connects that campaign to this dataset. What it establishes is that Kazakh government networks are under active, capable, credential-focused targeting, which makes "no evidence of a breach" a statement about a specific investigation rather than a general assurance.

The Attack Technique

No intrusion vector has been established for this dataset. The only claim of a technique is the seller's own assertion of an eGov hack, which the ministry disputes on structural grounds and which no third party has verified.

The mechanisms actually evidenced in Kazakhstan's recent record are abuse of authorized access rather than exploitation. The ministry's own 2025 finding pointed to unlawful use of legal access to state databases. The Zhetysu case involved a private collection agency holding near-nationwide citizen data. Musaliyev's darknet-aggregation theory covers the rest. Analysts working this incident should weight insider-and-broker supply chains above perimeter compromise until a sample is validated against live records.

Where perimeter compromise is relevant is in the Securelist reporting on parallel activity. OctLurk and SilkLurk use per-victim customized loaders that derive their decryption key from information on the target machine, which defeats sandbox detonation and static analysis of the payload. Both backdoors are heavily obfuscated and support plugin injection for command shells, filesystem operations, synthetic keyboard and mouse input, network scanning, credential dumping, keylogging, browser password theft, email collection and remote access. Kaspersky also documents a related utility it names LurkProxy, architecturally similar to OctLurk but not itself a backdoor. Initial deployment observed in that campaign used stolen admin credentials to create a scheduled task named GoogleUpDate on remote machines, running once with SYSTEM privileges to execute a batch script dropped into a user's Videos directory. That capability set, credential dumping plus browser password theft plus email collection, is precisely what produces the kind of bulk data that later appears on a marketplace with unclear provenance.

What Organizations Should Do

Validate the sample before you act on the headline. If you hold Kazakh citizen data, obtain the seller's sample and check it against your own live records for freshness, field structure and IIN validity. A 47 million row file describing 15 million people is a strong aggregation signal. Determining age of data is the highest-value analytic step available; a corpus that is mostly 2022 vintage demands a different response than a current export.

Audit legitimate access, not just the perimeter. Every confirmed large-scale Kazakh citizen data incident in the sources traced back to authorized access being misused, not to an exploited edge device. Instrument bulk-read and bulk-export operations on citizen databases, alert on volume anomalies per account, and review who holds standing query rights against national registries.

Treat third-party processors as the primary exposure. The Zhetysu seizure recovered nearly 16 million records from a debt-collection agency. Enumerate every downstream recipient of citizen data, contractually cap retention, and require attestable deletion. Data you handed to a partner five years ago is still your breach.

Meet the one working day clock. Under Law No. 94-V, as amended by Law No. 231-VIII of 17 November 2025, organizations must notify the Ministry of Digital Development within one working day of discovering a personal data breach, including the categories and approximate number of affected data subjects, likely consequences, and remedial measures taken. Confirm your DPO is appointed and that detection-to-notification is a rehearsed process, not an improvisation.

Purge prohibited identity document copies. Law No. 44-VIII ZRK, effective 11 February 2024, bars collecting and processing physical copies of passports and ID cards. The seller's claim of bulk document scans is a direct prompt to sweep your own storage, including legacy shares, ticketing systems and email archives, for material you are no longer permitted to hold.

Hunt for the regional intrusion set. Given active government-sector targeting in Central Asia, hunt for scheduled tasks masquerading as updaters such as GoogleUpDate, batch scripts executing from user media directories, and SYSTEM-context run-once tasks created via remote admin credentials. Prioritize credential-dumping and browser-credential-theft detections, since those are the collection primitives that turn one compromised host into a bulk dataset.

Assume exposure at the identity layer. For any organization authenticating Kazakh citizens, treat IIN, passport number, address and phone as public knowledge. Retire knowledge-based verification built on those fields and move to possession or biometric factors.

Sources: Data of 15 Million Kazakhstanis Allegedly Leaked – The Diplomat | OctLurk and SilkLurk: new Backdoors in Central Asia Securelist | Kazakhstan Rejects Alleged 15 Million-Record eGov Breach as Questio... | Data Leak of 15 Million Kazakhstanis: Ministry Checks eGov Breach C... | Kazakhstan Examines Data Leak Claim Involving 15 Million People - T... | Kazakhstan faces alleged data leak involving 15 million citizens | Data of 16 million Kazakhstanis could have been sold on the Darknet... | Data Protection Compliance In Kazakhstan — DPO & Breach Response