mohrss.gov.cn ( Ministry of Human Resources and Social Security ) Listed by babuk2 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Ministry of Human Resources and Social Security website (mohrss.gov.cn) has been listed by the Babuk2 ransomware group, with internal files reported as exfiltrated. The listing appeared on 20 March 2025; the exact date of the intrusion is not established. Individuals are advised to check whether their data may have been exposed and to follow any official guidance issued by the ministry.
Ransomware groups continue to target government institutions worldwide, using data theft and public leak-site listings as leverage in double-extortion schemes. Against that backdrop, a listing published on March 20, 2025, placed the Chinese Ministry of Human Resources and Social Security, associated with the domain mohrss.gov.cn, among victims claimed by the babuk2 ransomware group. Public detail remains limited: the number of people affected is unknown, and the precise scope of any intrusion has not been independently confirmed. The incident matters because ministries of this type manage sensitive administrative and personal records that, if compromised, can affect citizens’ employment, benefits and identity security.
What is known so far rests on the group’s own claim that internal files were exfiltrated in a ransomware attack. No further technical indicators, ransom demand or official confirmation from the ministry have been made public in the available record.
Breaking down the breach
According to the reported listing, the babuk2 ransomware group named mohrss.gov.cn, the Ministry of Human Resources and Social Security, as a victim on March 20, 2025. The sole description of exposed material is that internal files were allegedly exfiltrated during a ransomware attack. No figure for the volume of data, no timeline of the intrusion, no indication of how access was obtained, and no count of affected individuals have been disclosed. The listing itself constitutes an unverified claim by the group; independent verification of the breach, its scale or its method is not present in the public facts.
Because timing, scale and technical method remain undisclosed, it is not possible to reconstruct the sequence of events beyond the group’s assertion that a ransomware attack occurred and that internal files left the organisation’s control.
Inside babuk2
Babuk2 is associated with the broader Babuk ransomware family, a group that has operated since at least 2021 and is documented for double-extortion tactics: encrypting systems while simultaneously stealing data and threatening to publish it on dedicated leak sites if payment is not made. Public reporting has linked Babuk-related actors to attacks on enterprises, government bodies and critical-infrastructure organisations across multiple countries. The group typically posts victim names, sample files or full archives on its leak infrastructure to increase pressure. In this case the group claims the Ministry of Human Resources and Social Security as a victim and asserts that internal files were taken; no additional statements by babuk2 about this specific organisation appear in the available record.
Like other ransomware operations of this type, babuk2’s model relies on the reputational and operational cost of data exposure rather than encryption alone. Prior public activity by Babuk-linked groups has included high-profile listings and occasional free releases of data when negotiations stalled, though each incident must be evaluated on its own evidence.
About Ministry of Human Resources and Social Security
The Ministry of Human Resources and Social Security is a national-level government body in China responsible for labour policy, employment services, social insurance, pensions and related administrative functions. Organisations of this kind routinely process large volumes of personal and employment-related records for citizens and employers. Their digital systems typically support benefit payments, workforce registration, unemployment support and social-security administration.
A breach affecting such a ministry is consequential because the data under its control often include identifiers, employment histories and benefit entitlements that are difficult for individuals to change. Even when the precise contents of a claimed exfiltration remain unconfirmed, the sector’s role as a central repository of citizen and workforce information elevates the potential impact of any successful ransomware operation.
What data was at risk
The available facts state only that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, databases or personal-data categories has been disclosed. Organisations performing human-resources and social-security functions commonly hold names, identification numbers, employment records, contribution histories, contact details and benefit-payment information. Whether any of those categories were among the files claimed by babuk2 is unconfirmed. The exact contents of the exfiltrated material therefore remain unknown.
What's at stake
For individuals whose records may have been involved, the concrete risks include potential misuse of personal identifiers for fraud, unauthorised access to benefit accounts, or long-term exposure of employment and social-security details. Because the number of people affected is unknown and the data types are not itemised, the actual scale of personal impact cannot yet be measured. For the ministry itself, the stakes include operational disruption if systems were encrypted, reputational damage from a public listing, and the administrative burden of investigating and containing any confirmed intrusion. In the wider threat landscape, successful claims against government ministries also serve as advertising for ransomware groups seeking further targets.
None of these outcomes is established as fact for this incident; they represent the ordinary consequences that follow when ransomware operators claim to have taken internal government files.
What to do if you're exposed
Anyone who has interacted with the Ministry of Human Resources and Social Security or who holds social-security or employment records managed by it should treat the listing as a prompt for caution rather than proof of personal compromise. Practical first steps include monitoring official benefit and employment accounts for unexpected activity, reviewing credit or identity-protection services if available in your jurisdiction, and changing passwords on any related online portals. Because the precise data involved remain unconfirmed, there is no public list of affected individuals to check against. Readers can run a free exposure scan of their email address to see whether that address has already appeared in other known breach datasets; such a scan does not confirm or rule out involvement in this specific incident but can surface earlier exposures that warrant attention. Stay alert for official statements from the ministry and avoid responding to unsolicited messages that claim to relate to the breach.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Intelligence Bureau of the Joint Staff Department of the Central Military Commission China Listed by babuk2 Ransomware GroupBangladesh Armed Forces (BangLadesh Army) Listed by babuk2 Ransomware GroupSaudi Arabian military and government internal center Listed by babuk2 Ransomware Groupnadra.gov.pk - NADRA official Of Pakistan Army & (Andhra Pradesh) Listed by babuk2 Ransomware GroupLatest breaches
Publicly posted by babuk2 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.