SYS::ONLINE
Wasteland.
Briefs1888
Issues23
SinceFeb 2026
LIVE
▣ Breach KAZAKHSTAN-CITIZEN 2026-08-12

Kazakhstan eGov: Alleged Darknet Sale of National Citizen Database

"A darknet seller using the alias shymzz13 has listed what they claim is the personal data of 15 million Kazakhstani citizens, allegedly obtained by breaching the government's eGov e-services platform. The listing was…"

A darknet seller using the alias shymzz13 has listed what they claim is the personal data of 15 million Kazakhstani citizens, allegedly obtained by breaching the government's eGov e-services platform. The listing was first surfaced on 12 August 2026 by the Kazakh Telegram channel Mash and reported by Zamin.uz, news.az and Caliber.az, all of which describe a 2.7 GB file containing roughly 47 million rows priced at 0.5 BTC (about $32,000). Kazakhstan's Ministry of Digital Development, Innovation and Aerospace Industry told Zamin.uz the claim is not yet confirmed and that it was conducting technical checks. Nothing in the available sourcing establishes an actual intrusion into eGov, and every figure below comes from the seller's own claims or from secondary reporting of them.

Note on scale: the sources describe 15 million as roughly three-quarters of Kazakhstan's population, not the entire population. Separately, Vice Minister of Artificial Intelligence and Digital Development Doszhan Musaliyev has publicly discussed a 16 million record dataset in circulation, so the record count in play ranges from 15 million (Zamin.uz, news.az, Caliber.az, citing the darknet listing) to 16 million (Tengrinews.kz, citing the Vice Minister and a June seizure). Accounts differ on whether these are the same dataset.

What Happened

On 12 August 2026, a post on a darknet forum offered a database of Kazakhstani citizen records for sale. Zamin.uz, news.az and Caliber.az all attribute the listing to the handle shymzz13 and report the seller's claim that the data came from a compromise of eGov, the state e-government portal. Price: 0.5 bitcoin. File size: 2.7 GB. Claimed contents: about 47 million rows covering 15 million people, which implies multiple records per individual rather than 47 million distinct citizens.

The Ministry of Digital Development, Innovation and Aerospace Industry said the report had not been confirmed and that technical verification was under way. That posture matters, because Kazakhstan's regulator has previously investigated and then disproven a headline breach claim. On 31 July 2026, the Ministry of Artificial Intelligence and Digital Development stated that an unscheduled inspection of Daryn.online LLP found no leak of 4.2 million records, and that the platform's information system holds "more than 90,000 records" in total, which it said excludes a compromise of the claimed size. Daryn.online was nonetheless fined under Article 79 of the Administrative Offenses Code for failing to implement mandatory protection measures. The original 4.2 million claim had come from ThreatMon monitoring of a dark web forum post and was reported by Qazinform on 13 July 2026.

The current claim also lands on top of a documented pattern rather than in isolation:

Musaliyev's own explanation for the collection agency dataset points at aggregation rather than a single breach: he said the 16 million records were likely "accumulated over years, possibly even decades," that there is probably "a single database being sold on the darknet," and that the collectors may simply have bought it. He labelled this an assumption, not a finding.

What Was Taken

Treat the following as seller claims, corroborated only by the fact that multiple outlets read the same listing:

Volume claims: 2.7 GB, about 47 million rows, covering 15 million individuals (Zamin.uz, news.az, Caliber.az).

By contrast, the June 2026 dataset actually seized by police in Zhetysu Region is described more narrowly and with far higher confidence, because it was recovered by investigators: IINs, phone numbers and residential addresses for close to 16 million citizens (Tengrinews.kz, news.az).

The distinction is operationally important. IIN plus phone plus address enables large-scale identity-based fraud on its own. If the additional elements in the darknet listing are real, particularly document scans and passwords, the exposure escalates from fraud enablement to account takeover and identity document forgery. That element is currently unverified.

Why It Matters

If genuine at anything close to the claimed scale, this is a national-population dataset, and the population-level consequence does not expire. Passports get reissued; IINs, dates of birth and historical address and employment history do not. Every Kazakh bank, telecom and government service that uses these attributes as knowledge-based authentication factors should assume those factors are now public.

Two structural findings from the sourcing deserve attention from defenders anywhere:

Aggregation is the real threat model, not the single dramatic hack. Both the 2025 leak and the 2026 collection agency case were attributed by Kazakh authorities not to intrusion but to abuse of legitimate access, compounded over years. The Vice Minister's own assessment of the 16 million record set is that it was assembled over a long period and possibly purchased. Insider and third-party access abuse produced a dataset indistinguishable in impact from a catastrophic breach.

Darknet record counts are routinely inflated. The Daryn.online case is a clean, regulator-documented example: a claim of 4.2 million records against a system the Ministry says holds just over 90,000. Marketplace listings are sales copy. Any 15 million or 16 million figure attributed to shymzz13 should be treated as an upper-bound assertion pending verification, which is exactly the posture the Ministry has taken.

Wider regional context also matters, though it is not linked to this incident by any source. Kaspersky's Securelist team reports tracking two new backdoors, OctLurk and SilkLurk, used against government organizations across Central Asia since January 2025, with confirmed victims in Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, Afghanistan and Syria, spanning ministries of foreign affairs, law enforcement, healthcare, logistics and education. Kaspersky assesses with medium confidence that a single Chinese-speaking actor is behind both and has not attributed the activity to a known group. Separately, Kaspersky documented Armored Likho (also tracked as Eagle Werewolf) targeting government agencies and electric power organizations in Russia, Kazakhstan and Brazil with AI-generated malware, a Python infostealer called BusySnake Stealer, and Go2Tunnel. Kazakh government networks are under sustained, capable, credential-focused espionage pressure. That is the environment in which a claimed national database sale should be evaluated.

The Attack Technique

Unknown and unverified. The seller asserts a breach of eGov. No source in this set corroborates that mechanism, and the Ministry says the report is unconfirmed and under technical review.

The competing explanations that Kazakh authorities have actually substantiated in prior, comparable cases are:

  1. Abuse of legitimate access. The official assessment of the summer 2025 leak of 16 million records was misuse of authorized credentials against state databases, not external intrusion, with most data traced back to 2022 theft.
  2. Downstream commercial resale. In the June 2026 Zhetysu case, a collection agency held near-nationwide data; the Vice Minister's working hypothesis is that they bought it from a darknet source rather than breaching anything.
  3. Access control failure in eGov itself. news.az reports that in early August 2026 the platform allowed users to reach other users' personal pages, an authorization defect rather than a database exfiltration.

The espionage tooling documented by Kaspersky offers a fourth theoretically viable path but with no evidentiary link to this dataset. For completeness: OctLurk deployment involved a scheduled task named GoogleUpDate created on remote machines using admin credentials, executing a batch script from a user's Videos directory, with per-victim customized loaders that derive their decryption keys from host information. Both backdoors are heavily obfuscated and load plugins for credential dumping, keylogging, browser password theft, email collection, network scanning and remote access. Armored Likho's chain starts with spear-phishing (government notices, humanitarian aid applications, psychological tests), delivers NSIS self-extracting archives or LNK files, injects a loader into a legitimate in-memory process, and stages payloads from GitHub repositories into %appdata%\WindowsHelper. Both toolsets steal exactly the credentials that make option 1, abuse of legitimate access, possible at scale.

What Organizations Should Do

  1. Retire IIN, phone number, address and date of birth as authentication factors. Any Kazakh-facing bank, telecom, insurer or government service still using these for identity verification or account recovery should treat them as public data and move to possession or biometric factors. This holds regardless of whether the current listing verifies.
  2. Audit privileged access to citizen and customer databases for volume anomalies, not just intrusion signatures. The two incidents Kazakh authorities have actually substantiated were authorized users pulling data over long periods. Alert on bulk read volume per account, off-hours query patterns, and export operations, and review third parties, contractors and collection agencies with the same rigor as employees.
  3. Fix authorization defects before hunting for exfiltration. The reported eGov cross-account page access issue is a classic IDOR-class failure. Test object-level authorization on every endpoint that returns a user-scoped record, especially in high-traffic citizen portals.
  4. Verify marketplace claims against your own data inventory before you confirm or deny publicly. Kazakhstan's Information Security Committee refuted the Daryn.online claim by comparing it to actual record counts in the system. Know your row counts per system now so you can do that in hours, not weeks.
  5. Hunt for the regional espionage tooling. Look for scheduled tasks named GoogleUpDate or similar Google-lookalike names created with admin credentials, batch scripts executing from user media directories, and any activity under %appdata%\WindowsHelper. Treat GitHub as a payload-staging domain in outbound traffic review, and prioritize detections for credential dumping and browser password theft, since stolen legitimate credentials are the bridge to mass data access.
  6. Prepare for permanent exposure, not a reset cycle. Population-scale identity data cannot be rotated. Build fraud monitoring, SIM-swap controls and step-up verification on the assumption that an attacker already knows the customer's identifiers, and brief fraud and call center teams that caller knowledge of an IIN or address proves nothing.

Sources: Data of 15 million citizens in Kazakhstan reportedly leaked onto th... | OctLurk and SilkLurk: new Backdoors in Central Asia Securelist | AI-Generated Malware Powers New Armored Likho APT Campaign | Data of 16 million Kazakhstanis could have been sold on the Darknet... | Kazakhstan faces alleged data leak involving 15 million citizens | Data of 15 million Kazakh citizens allegedly sold on dark web - PHOTO | Kazakhstan probes possible breach of educational platform affecting... | Digital Development Ministry Reports on Probe into 4.2M Daryn.onlin...