Data of 15 million Kazakhstanis on sale: the eGov breach is not confirmed
On 12 August 2026 a seller on a darknet forum offered a database that, by their own description, covers 15 million residents of Kazakhstan: passport details, phone numbers, emails, passwords, places of work and scans of documents. That is around three quarters of the country. The seller claims the data came out of eGov, the state services portal. The ministry responsible says nothing of the kind has been confirmed.
In short
- The file is described as 2.7 GB and 47 million rows, priced at 0.5 bitcoin, about 32 thousand dollars.
- The claim that it came from a hack of eGov is the seller's word and nothing else so far.
- The ministry points to a technical mismatch: eGov does not keep passport scans in the form described.
- A year ago a similar array turned out to be mostly old data pulled through legitimate accounts.
What is being sold
The listing surfaced through the Telegram channel Mash and was picked up by Kazakh outlets on 12 August. A user under the nickname shymzz13 put up a 2.7 GB file with roughly 47 million rows covering about 15 million people, and asked 0.5 bitcoin for the lot. The advertised fields are the ones that hurt: full passport data, phone numbers, email addresses, passwords, employment details and scanned documents.
Nobody outside the forum has seen the full array. What is public is the seller's description, a sample and the price. That distinction matters, because the market for stolen data rewards a good story as much as good data.
What the state says
The Ministry of Artificial Intelligence and Digital Development confirmed it is aware of the publications and is running a technical check together with other agencies. Its central point is not a denial of the leak as such, but a mismatch in the description.
eGov does not store passport scan copies in the claimed format, digital documents have a different structure.
Ministry of Artificial Intelligence and Digital Development of KazakhstanClaimed by the seller
- Data taken from eGov through a vulnerability
- 15 million people, 47 million rows
- Passwords and document scans inside
Confirmed so far
- The listing exists and the price is 0.5 bitcoin
- A technical check is under way
- No verified evidence of an eGov breach
Why a hack may turn out not to be a hack
Kazakhstan has been here before. In the summer of 2025 an array of 16.3 million records went around: names, national IDs, dates of birth, addresses, phone numbers, citizenship. The authorities checked it, and the deputy minister Doszhan Musaliev later described what they found. The likeliest path was not a break-in at all but access through legitimate accounts, with logins and passwords handed over or stolen, after which the data was simply downloaded. Most of the array, according to that check, had been taken back in 2022 and only partly refreshed later.
This is the normal shape of such stories. A fresh listing is often an old body of data, re-packaged, topped up and sold again under a louder headline. It changes the response: hunting for a hole in the portal is pointless if the door was opened with a valid key.
One entrance for everything
The uncomfortable part has nothing to do with any particular breach. A state portal is convenient exactly because it is single: one login for taxes, property, medicine, children's schools. The same property makes it a single point of failure. Whatever leaks from there is not a password you can change but the facts of a person, and those cannot be reissued.
Nor is this a local peculiarity. In 2021 Argentina's national ID registry lost data on tens of millions of citizens, and the thief also announced it with a sale listing. Wherever identity is centralised, the value of a single copy of the database grows with every new service plugged into it.
What a person can actually do
- Change the password on the state portal and on the mail attached to it, and do not reuse that password anywhere else.
- Turn on two factor authentication wherever it is offered, preferring an app over SMS: a phone number from such a base is the first thing used for a SIM swap.
- Treat calls and messages that already know your details as suspicious by default. Passport number and place of work in the caller's mouth are now cheap.
- Where a service accepts a scan of a document as proof, ask for a different method. A scan on file with a shop or a landlord is the next leak waiting to happen.
A VPN changes nothing here
Worth saying plainly, since data leaks and privacy tools get mentioned in one breath. A VPN protects traffic on the way: it hides the connection from the network and the provider. It has no effect on a database that already holds your passport details, because the copy is on the other side. It helps against interception and blocking, not against a state registry being copied.
• Данные 15 млн казахстанцев выставили на продажу в даркнете - K-News
• Взлом eGov и утечка данных 15 млн казахстанцев: министерство сделало заявление - Ак Жайык
• Утечка данных 15 млн казахстанцев: Минцифры сделало заявление о взломе eGov - Lada.kz
• Утечка данных 15 млн казахстанцев: в Министерстве ИИ сделали заявление - Azattyq Rýhy