Skip to content

Medical Imaging Backup From Beijing's 301 Hospital Offered for Sale, With an Unverifiable Headline Claim

Breach Report China flagChina Healthcare / Medical Imaging Selling

Medical Imaging Backup From Beijing's 301 Hospital Offered for Sale, With an Unverifiable Headline Claim

A forum user posting as Knox is offering what they describe as backup data taken from the Chinese PLA General Hospital in Beijing, commonly known as 301 Hospital. The posted directory listing shows 13,096 files totalling 452.29GB, made up of compressed archives and DICOM medical imaging files dated between 2024 and July 2026. Archive names appear to carry patient surnames. The seller further claims the set includes scans belonging to Xi Jinping, and displays imaging whose header fields carry his name and a date of birth. Those fields are freely editable text and are not evidence of whose scan it is. The claim is unverified.

Volume452GB
Files13,096
Coverage2024 to 2026
ActorKnox

Post details

Target301 Hospital, PLA General
CountryChina flagChina
SectorMilitary teaching hospital
ListingSelling, serious buyers only
Volume452.29GB, 13,096 files
SourceClaimed imaging backup share
Observed
ActorKnox, forum owner

!Allegedly included

  • DICOM imaging studies
  • Compressed patient archives
  • Patient names in filenames
  • Internal patient identifiers
  • Dates of birth
  • Recorded patient sex
  • Study dates and times
  • Body region examined
  • Scan sequence parameters
  • Institution name fields
  • Backup directory structure
  • Studies from 2024 onward
  • Two top level directories
  • Claimed head of state scan

Screenshots

Potential impact

The severity here rests on the ordinary patients, not the marquee name. If a genuine imaging backup has left the hospital, it concerns thousands of people whose scans are inherently identifying, since imaging carries names, birth dates and internal identifiers in its metadata and, in the case of head studies, can be reconstructed into a recognisable face. Medical images cannot be reissued or invalidated, and Chinese patients have no practical route to compel deletion once material is circulating abroad. A military teaching hospital adds a second dimension, since its patient population includes serving personnel and officials, making the set attractive for intelligence purposes rather than fraud alone. The named claim is best treated as marketing: it raises the asking price and the attention the thread receives, and it is the element least susceptible to proof.

iStatus

Unverified

Two points deserve weight. First, the patient name in a DICOM file is an ordinary text field that anyone holding the file can rewrite, so imaging displaying a public figure's name proves nothing about the patient, and the sample is viewed through trial software that would not validate anything. Second, the thread carries a verified marker, but the poster is the forum's owner and administrator, so that badge reflects the seller's own platform rather than independent scrutiny. The directory listing is plausible and its timestamps are internally coherent, which supports the existence of an imaging archive without establishing where it came from. Dark Web Informer is not reproducing the imaging, the patient names, the identifiers, or the contact routes. The claim is unverified and the hospital has not publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest