Exposed Chinese Smart City Database Leaks Facial Recognition Scans
A publicly accessible database hosted on Alibaba Cloud reveals how smart city technology collects and stores sensitive facial recognition data on hundreds of residents.
A massive smart city database containing gigabytes of facial recognition scans sits completely exposed on the internet without a password. Security researcher John Wethington discovers this Elasticsearch database hosted by Chinese tech giant Alibaba and shares the findings with TechCrunch to ensure the data gets secured. The leaked records contain highly sensitive biometric data on hundreds of people tracked over several months.
Alibaba quickly denies that its own artificial intelligence-powered City Brain platform powers the database, instead shifting the blame to an unnamed customer. A company spokesperson explains that as a public cloud provider, Alibaba does not have the right to access customer database contents and insists that users are always advised to set secure passwords. The tech giant pulls the database offline shortly after TechCrunch reaches out for comment.
This leak offers a rare and troubling glimpse into the inner workings of modern urban surveillance systems that are expanding across China and abroad. Civil liberties advocates raise serious concerns about the potential for abuse as these AI-powered smart city projects reach Western cities like those in the United States. Wethington warns that without strict civilian and governmental oversight, companies could easily merge this surveillance data with local criminal databases to build invasive profiles on ordinary citizens.