← Uk Biobank

2026 UK Biobank — de-identified research data listed for sale; Oversight Committee report (Apr–Jun)

2026 500.0K records affected Share on X

Data compromised

De-identified research fields (e.g., demographics, lifestyle, biomarker/summary statistics per reporting)—not full identity dossiers per official characterization

Technical writeup

Verified research-data misuse incident — public disclosure April 2026; Oversight Committee report published June 4, 2026. UK Biobank identified that de-identified participant data from its ~500,000-volunteer cohort were offered for sale on a Chinese consumer e-commerce website. Listings were removed; UK Biobank stated it believed the identified listings were not sold. Officials characterized the event as a contractual/policy breach by accredited researchers who downloaded data and offered it for sale—not a traditional external hack of core Biobank systems. Names, NHS numbers, and addresses are stored separately and were not provided to researchers. Responsible individuals and academic institutions (report notes Tongji Hospital / Tongji Medical College, Huazhong University of Science and Technology, Wuhan) were banned. The June 2026 Oversight Committee report set nine recommendations including faster participant communication, external security review, ending downloads of participant-level data from the Research Analysis Platform in favor of secure environments, and proactive monitoring for public exposure of Biobank data. Nature (2026) covered how the episode rekindled debate over open genomics research data security. BreachHistory retains the half-million cohort scale as context for the dataset at issue; no separate sold-record count was attested.

Root cause

Alleged contractual / insider-style misuse of accredited research copies; third-party marketplace listing (per UK Biobank and government narrative)

References