Reports have emerged online about a potential leak of personal data belonging to 15 million Kazakhstanis, allegedly put up for sale on the dark web. Kazakhstan's Ministry of Artificial Intelligence and Digital Development has launched a verification of these claims, as reported by infohub.kz.

According to a publication by Mash, an unknown hacker using the handle shymzz13 posted an ad offering a database containing information on 15 million residents of Kazakhstan, roughly three-quarters of the country's population. The seller claims the data was obtained after breaching the state service eGov. The file, sized at 2.7 gigabytes, is being sold for 0.5 Bitcoin, equivalent to about $32,000. The database purportedly contains 47 million rows with passport details, phone numbers, email addresses, places of work, document scans, and passwords.

Cybersecurity experts express concerns that this database could be purchased by Ukrainian call centers, which have previously used similar data for fraudulent schemes. For instance, recently, scammers, mistaking Kazakhstan for Russia, convinced pensioners from Pavlodar to set off an explosion at a bank.

A NUR.KZ correspondent sent a request to the press service of the Ministry of Digital Development. The ministry confirmed they are aware of the circulating information about a possible leak of personal data of Kazakh citizens and its placement on the dark web. Currently, a technical verification of the published information is underway in conjunction with specialized services, including analysis of the provided data samples and identification of the possible source. As of now, there is no confirmed data regarding a breach of e-government information systems or that the database originated directly from eGov.

The ministry also noted that some of the information claimed in the publications does not match the structure and format of e-government data. In particular, eGov does not store scanned copies of passports in the claimed form, and digital documents have a different format. The dark web user's claim about the database's origin cannot be considered confirmation of an eGov breach. The technical verification is ongoing, and further information will be provided based on its results.

The Ministry of Digital Development recommends that citizens follow basic digital security measures: do not share SMS codes, passwords, or digital signature data with third parties, avoid clicking on suspicious links, and use different passwords for various services.