Chinese Facial Recognition Database Exposes 2.5 Million People

Chinese Facial Recognition Database

An artificial intelligence company operating a facial recognition system in China recently left its database exposed online, leaving the personal information of some 2.5 million Chinese citizens vulnerable. Considering how much the Chinese government relies on facial recognition technology, this is a big deal—for both the Chinese government and Chinese citizens.

What Happened With This Chinese Facial Recognition Database?

So what happened? The database belongs to SenseNets Technology, Ltd, a company that develops artificial intelligence security software systems, including facial recognition, crowd analysis, and personal verification. Founded in 2015 and based in Shenzhen, China, SenseNets’ technology is used by police surveillance systems in many Chinese cities. SenseNets’ video tracking cameras monitor people and record their movements as data. As you might imagine, SenseNets has access to a lot of data, gathered from watching millions of people all day, every day. The big deal? That boatload of information was exposed to the public because the company failed to password protect it. The data was in plain text, and anyone nosing around could easily access it.

Victor Gevers, a Dutch cybersecurity researcher at the non-profit group, GDI.Foundation, discovered the open database online because, well, it’s what he does. Grevers discovered the problem in July of 2018 and warned the company about it, but the company didn’t reply. In February of 2019, Grevers publicly shared information about the breach on Twitter. Grevers’ tweets indicate the data has been viewed and in some cases copied by visitors to the access point. SenseNets has since blocked access to the database and as refrained from any comment on the occurrence.

As an aside, Grevers is also the person who discovered what is being called the “BreedReady” database this past weekend. This is an open database in China apparently developed to register the personal information of some 1.8 million women. The information in the database includes age, addresses, phone numbers, education, location, ID number, and what is being called a “BreedReady” status of these women. For a Communist country suffering from falling birthrates, an extreme shortage of women, this shouldn’t come as a surprise, but is nonetheless alarming.

What Kind of Information Was Exposed?

The database exposure included the gender, address, birthdate, and nationality of more than 2.5 million people in China. It also included each person’s employer and a photo. This type of private information is linked to the ID card number that Chinese residents are required to have. That ID number was also exposed in this Chinese facial recognition

How Does China Use Facial Recognition Technology?

In China, facial recognition technology is sophisticated and part of everyday life. The government watches everything and everyone, all day every day. Residents who go through the security checkpoint at the Shanghai Hongqiao International Airport have to get through the facial recognition step first. The subway system in Beijing is getting ready to use this technology, and police officers use special glasses that let them quickly recognize faces, to aid in the rapid identification of suspects. Schools in China may start using facial recognition to take attendance each day, and it’s even been considered to use the system to ensure the children are paying attention during class.

The Chinese are currently testing a very controversial social credit scoring system, designed to monitor unattractive or unhealthy behavior (e.g. frivolous spending, being wasteful, smoking where it’s not permitted, or not being a “good citizen.” This system is expected to roll out in 2020 and may preclude Chinese citizens with low social credit scores from traveling, getting a loan, a good job, or having educational opportunities.

Facial recognition technology and the artificial intelligence that fuels it is cool, without question, and can be used for much good. But when it’s left unsecured and unprotected, it poses extreme danger to the millions of people potentially impacted. Chinese citizens, while accustomed to being under constant surveillance, quite likely are less comfortable having their personal information available online. Unfortunately for them, there’s probably not much they can do about it.

Here in the U.S., we’re not unaffected by the potential dangers of facial recognition technology. As just one example, facial recognition on the devices we use every day is largely insecure. See the recent report of the Samsung Galaxy S10 facial recognition being fooled by a video of the phone owner for more on that. Also, note that the U.S. Customs are reported to be speeding up facial recognition adoption at airports, in spite of a myriad of security concerns. China is a few years ahead of us in terms of how they are publicly using AI and facial recognition, but I predict we’ll be seeing more and more of it in the not too distant future.

Futurum Research provides industry research and analysis. These columns are for educational purposes only and should not be considered in any way investment advice. 

Author Information

Shelly Kramer is a serial entrepreneur with a technology-centric focus. She has worked alongside some of the world’s largest brands to embrace disruption and spur innovation, understand and address the realities of the connected customer, and help navigate the process of digital transformation.

Related Insights
Can Zoom's Agent Architect Redefine the AI Agent Lifecycle for Enterprise CX
June 22, 2026

Can Zoom’s Agent Architect Redefine the AI Agent Lifecycle for Enterprise CX?

Keith Kirkpatrick, Vice President & Research Director, Enterprise Software & Di at Futurum, Zoom's Agent Architect and Performance Suite transform enterprise AI creation, deployment, and optimization with outcome-based pricing and...
Can Glean's Financial Services Push Make AI Assistants a Compliance Asset, Not a Risk?
June 18, 2026

Can Glean’s Financial Services Push Make AI Assistants a Compliance Asset, Not a Risk?

Glean's Financial Services expansion positions its AI Assistant as a compliance-first solution for regulated industries, tackling reliability and privacy concerns while competing against Microsoft and Google in enterprise AI deployment....
Agent Trust
June 16, 2026

Will Salesforce and Databricks Redefine AI Agent Trust or Deepen Platform Lock-In?

Keith Kirkpatrick, Vice President & Research Director, Enterprise Software & Di at Futurum, examines how Salesforce and Databricks are addressing enterprise demands for trustworthy AI agents while potentially deepening platform...
Zendesk's Beams Acquisition Signals a New Battlefront in Agentic AI for Employee Service
June 16, 2026

Zendesk’s Beams Acquisition Signals a New Battlefront in Agentic AI for Employee Service

Keith Kirkpatrick, Vice President & Research Director, Enterprise Software & Di at Futurum, explores how Zendesk's acquisition of Beams signals a strategic pivot toward agentic AI-powered employee service management, positioning...
Oracle's Outcome-Based Pricing Gambit: Rewriting the Rules of Cloud Economics
June 15, 2026

Oracle’s Outcome-Based Pricing Gambit: Rewriting the Rules of Cloud Economics

Keith Kirkpatrick, Vice President & Research Director, Enterprise Software & Di at Futurum, Oracle's shift to outcome-based pricing and AI-driven commercial models reshapes enterprise cloud procurement and vendor economics in...
Americans Want AI to Cure Cancer, But Trust in AI Companies Is Near Rock Bottom
June 15, 2026

Americans Want AI to Cure Cancer, But Trust in AI Companies Is Near Rock Bottom

Anthropic's Public Record survey shows 48% of Americans hope AI will cure diseases like cancer, yet only 15% trust AI companies to make key decisions. With 64% fearing job loss,...

Book a Demo

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.