In 2026, public security authorities carried out the "Huwang-2026" special operation, focusing on key tasks in cybersecurity, data security, and information security. Leveraging the national cybersecurity and information notification mechanism, they systematically advanced the construction of cyberspace security protection and comprehensive governance systems. The operation involved concentrated crackdowns on prominent risk issues, discovery and rectification of vulnerabilities, and investigation of administrative cases involving failure to fulfill protection obligations, effectively safeguarding critical information infrastructure, important network systems, and data security.
Collaborating with relevant industry departments, public security authorities conducted targeted rectification efforts on issues such as illegal and non-compliant collection of personal information by mobile applications and inadequate implementation of data protection measures in key sectors. Over 7,900 network and data security risk inspections were carried out, with 38,000 security risks and vulnerabilities identified and rectified. Additionally, 652 mobile applications that illegally collected personal information were publicly exposed, and 38,000 administrative cases involving failure to fulfill cybersecurity, data security, or personal information protection obligations were investigated.
Case One: A Jiangsu Company Fails to Fulfill Data Security Protection Obligations. In November 2025, public security authorities in Suqian, Jiangsu, received a tip-off about an access vulnerability in the data interface of a service platform within their jurisdiction. An investigation revealed that the platform's developer and operator, a Jiangsu-based company, failed to implement data transmission and storage protection measures during development and operation, did not thoroughly rectify discovered security vulnerabilities, and an employee accessed and downloaded assessment data without authorization for analysis. The local public security authorities have since imposed administrative penalties on the company and supervised the destruction of retained personal information.
Case Two: A Unit in Wuhu, Anhui, Fails to Fulfill Cybersecurity Protection Obligations. In April 2026, public security authorities in Wuhu, Anhui, were notified of anomalies and security risks associated with an IP address within their jurisdiction. An investigation revealed that the IP address was used by a local unit for dedicated communication networking. Due to a vulnerability in the router using the IP address, and because the device also had management ports open, it was controlled by malicious software. As disposal was timely, no serious consequences occurred. The local public security authorities have ordered the unit to rectify the issues.
Case Three: A Credit Center in Nanchang, Jiangxi, Fails to Fulfill Cybersecurity Protection Obligations. In January 2026, public security authorities in Nanchang, Jiangxi, discovered that a local center's SMS platform was sending large volumes of illegal messages. An investigation revealed that an SMS interface in a mini-program operated by the center was exploited by criminals to send over 140,000 gambling-related illegal messages to more than 70,000 mobile numbers. However, the center failed to activate its emergency response plan or report the incident to relevant authorities as required. The local public security authorities have imposed administrative penalties on both the center and its responsible personnel.
Case Four: A Technology Company in Jinan, Shandong, Fails to Fulfill Data Security Protection Obligations. In June 2026, public security authorities in Jinan, Shandong, received a notification that stored data in the backend of a WeChat mini-program operated by a local technology company had been leaked. An investigation revealed that the company, as the developer and operator, conducted data processing activities through the mini-program but failed to establish security management systems, organize data security education and training, or implement technical and other necessary measures to ensure data security. The local public security authorities have imposed administrative penalties on the company.
Case Five: A Technology Company in Qingdao, Shandong, Fails to Fulfill Cybersecurity Protection Obligations. In April 2026, public security authorities in Qingdao, Shandong, discovered that a local technology company's platform had been illegally controlled by criminals to make fraudulent phone calls. An investigation revealed multiple violations during the company's operation of the platform: no firewall or intrusion detection systems were deployed, network logs were not retained as required, and administrative account vulnerabilities existed. These issues were exploited by criminals, leading to the platform being hacked and used as a tool for telecom fraud. The local public security authorities have imposed administrative penalties on the company.
Case Six: A Transport Group in Qinzhou, Guangxi, Fails to Fulfill Personal Information Protection Obligations. In July 2026, public security authorities in Qinzhou, Guangxi, discovered that a WeChat mini-program operated by a local transport group failed to fulfill personal information protection obligations. An investigation revealed multiple violations in the group's handling of personal information: it did not establish internal management systems or operational procedures, failed to implement security technical measures for stored user information, and did not regularly conduct security education and training for employees. The local public security authorities have imposed administrative penalties on the group.
Case Seven: A Tourism Development Company in Yibin, Sichuan, Fails to Fulfill Cybersecurity, Data Security, and Personal Information Protection Obligations. In July 2026, public security authorities in Yibin, Sichuan, received a tip-off about abnormal data transmission from a tourism development company's ticketing system in Xingwen County. An investigation revealed that a backdoor administrative account had been implanted on the company's cloud server for the ticketing system, resulting in large-scale data exports that went undetected for a long period. Further investigation found multiple violations: incomplete cybersecurity management systems, improper management of key shared terminals, inadequate protection measures, failure to establish relevant security management systems, failure to fulfill notification obligations when collecting, storing, and processing personal information, and failure to implement personal information protection measures. The local public security authorities have imposed administrative penalties on the company.
Case Eight: Liu in Kunming, Yunnan, Illegally Obtains Computer Information System Data and Controls Computer Information Systems. In April 2026, public security authorities in Xishan District, Kunming, Yunnan, received a report from a resident that a server of a certain brand in their home suffered severe network congestion and could not be accessed normally, suspected to be under cyberattack. An investigation revealed that the attacking IP address was the personal home broadband of Liu. In early February 2026, Liu learned of a high-risk vulnerability in that brand of server, obtained a large number of server IP addresses, and wrote automated attack scripts to illegally obtain information from other people's devices. The local public security authorities have imposed administrative penalties on Liu.
Case Nine: An Amusement Park in Gansu Fails to Fulfill Personal Information Protection Obligations. In July 2026, during a special law enforcement inspection on personal information protection, public security authorities in Gansu discovered that smart lockers and entrance gates operated and managed by a local amusement park only supported facial recognition authentication and did not provide alternative options. Further verification found that the amusement park, as a personal information processor, committed multiple violations: it failed to notify customers when collecting facial information, the collection lacked specific purposes and sufficient necessity, and security technical measures were not implemented. The local public security authorities have imposed administrative penalties on the company and supervised the destruction of improperly retained facial information.
Case Ten: A Technology Company in Ningxia Fails to Fulfill Data Security Protection Obligations. In July 2026, public security authorities in Ningxia discovered that sensitive data had been uploaded in full by a user in a public repository on a global open-source code hosting platform. An investigation revealed that in April 2025, Zhang, an employee of a Ningxia-based technology company, privately uploaded sensitive information from a system he was responsible for maintaining to his personal repository on the platform to facilitate internal collaboration and work coordination. This exposed the network architecture, security protection system, and internal personnel information of the system under Zhang's operation and maintenance. The local public security authorities have imposed administrative penalties on both the company and Zhang.
Comments