01Summary
The Xinjiang Police Files comprised a massive collection of unauthorized data exfiltrated from the Integrated Joint Operations Platform (IJOP) of the Xinjiang Public Security Bureau. The documents detailed the demographics of detainees, including mugshots of thousands of individuals, and outlined the rationale for detention, which included 'pre-crimes' such as visiting foreign websites or having relatives abroad. Furthermore, the files revealed brutal security protocols, such as Directive 44-B, which authorized guards to use lethal force against escapees. The leak provided a granular, internal view of the state's apparatus for control, confirming the systematic nature of the alleged internment and surveillance operations.
02Background
The leak emerged amid growing international concern regarding the treatment of ethnic minorities in the Xinjiang Uyghur Autonomous Region. Previous reports had already suggested mass detention, but the Xinjiang Police Files provided unprecedented, internal documentation, moving the discussion from anecdotal evidence to documented state policy.
03Key revelations
- 01The existence of a centralized database containing mugshots and personal data of detainees.
- 02The official state protocols authorizing lethal force ('Strike Hard') against escapees.
- 03The use of 'pre-crime' justifications for detention, such as online activity or family ties.
04Technical analysis
The data was sourced from the Integrated Joint Operations Platform (IJOP), suggesting a centralized, high-level government database. The metadata verification against satellite imagery provided a crucial layer of authenticity, linking the digital records to physical reality.
- Attack vector
- Unauthorized data exfiltration from a secure government network (IJOP)
- Attack method
- Data theft and leak
- Initial access
- Unauthorized access/Exfiltration
- Exfiltration
- Data transfer/Leak
- Malware type
- Data Exfiltration
Vulnerabilities exploited
- Insider access/System vulnerability
MITRE ATT&CK techniques
- T1041
05Threat actor
The perpetrator acted as an anonymous hacker, suggesting a highly motivated individual or small group focused on whistleblowing. Their actions demonstrate a sophisticated understanding of data exfiltration and the global media landscape to maximize the impact of the disclosed information.
Aliases
- Xinjiang_Hacker
MITRE groups
- T1566.001
Attribution sources
- Investigative Journalists
- Human Rights Organizations
06Victims and impact
Countries affected
- China
- Global
07Data exposed
Data types
- Mugshots
- Personal Identifying Information (PII)
- Detention Records
- Security Protocols
- Internal Memos
Notable documents
- Detainee Demographics Database
- Directive 44-B: Strike Hard Protocol
- Internal Party Memo on 'Breaking Lineage'
08Timeline
- 2022-05-22Leak of the initial batch of documents to international media.
- 2022-05-24Publication of key findings, including mugshots and security protocols.
09Key figures
- Uyghur MinorityVictim GroupUyghurMass detention and surveillance
10On the record
Break their lineage, break their roots, break their connections, and break their origins.
11Reaction and fallout
Public reaction
The leak triggered widespread international condemnation, leading to calls for sanctions and investigations by international bodies. Global human rights organizations used the data to lobby governments and the UN.
Political impact
It significantly heightened international scrutiny of China's human rights record, contributing to the passage of various legislative actions in Western nations regarding Xinjiang.
Geopolitical consequences
The leak strained diplomatic relations between Western nations and China, fueling debates over human rights accountability and international law enforcement.
12Legal
The documents have been used in various international human rights reports and legal advocacy efforts, though no specific international criminal prosecution has been confirmed based solely on this leak.
13Aftermath
Policy changes
- Increased international focus on human rights due diligence in supply chains.
Regulatory changes
- Calls for mandatory human rights impact assessments for foreign companies operating in Xinjiang.
Security improvements
- Increased global focus on securing critical infrastructure against state-sponsored espionage.
14Significance and legacy
Significance
This incident is a landmark example of investigative journalism utilizing leaked state intelligence to expose systemic human rights abuses. It provided verifiable, internal documentation that challenged the official narrative of the Chinese government, setting a precedent for using digital leaks in international human rights law.
Legacy
The leak has permanently altered the global discourse surrounding ethnic minority rights and state surveillance. It has fueled the development of new legal and policy frameworks aimed at holding states accountable for documented abuses.
15Disclosure and media
- Authentication
- Metadata verification against satellite imagery
Media partners
- The Guardian
- The New York Times
- BBC News
Publishing organisations
- Investigative Journalists
- Human Rights Watch
17Field notes
- 01The leak highlighted the use of 'pre-crime' justifications, demonstrating that suspicion, rather than actual criminal activity, was the primary basis for detention.
- 02The metadata verification process was crucial, linking the digital records to physical security features observed via satellite imagery.
18Resolution
The data remains in the public domain, serving as a permanent reference point for human rights documentation and international legal advocacy.
19Sources
Official documents
- Xinjiang Public Security Bureau Internal Memos
References
- [1]The Guardian Reporting
- [2]Human Rights Watch Reports
- [3]ICIJ Documentation









