UK Biobank resumes research after data-leak shutdown, introduces stricter security controls
After a data breach that forced a five-month closure, the UK Biobank is reopening to researchers with new security measures.
In April, the UK Biobank received an email from an anonymous researcher indicating that hundreds of thousands of participant records were listed for sale on Xianyu, an Alibaba-run marketplace. Collaboration with Alibaba and the governments of the United Kingdom and China led to the removal of the listings and the suspension of access for the involved Chinese institutions. The biobank spent nearly five months offline to develop an “airlock” that screens exported data and to adopt a reading-library model that limits downloads.
It will reopen to vetted researchers this month, while also imposing penalties on institutions that fail to delete data after authorized use. The incident has spurred similar security upgrades at 23andMe and highlighted ongoing tensions between data accessibility and participant privacy across global biorepositories.
Why it matters
The story shows how vulnerable large biomedical databases are and why stronger safeguards are needed to protect participants while enabling research.
In this story
