Mi Account Passwords Compromised Claims Report, Old Information Says Xiaomi

Advertisement
By NDTV Correspondent | Updated: 30 October 2014 18:02 IST
A security researcher claims to have obtained usernames and passwords of Xiaomi Mi Account holders by using a zero-day exploit in Xiaomi's servers.

According to a report by The Hacker News, Taiwanese security researcher Chen Huang contacted the website and "provided partial database of a few thousands of Xiaomi users, which confirmed that the millions of Xiaomi Mi accounts has already been compromised."

Based on information publicly available, there's no way to confirm if the claims of the researcher are true. NDTV Gadgets made repeated attempts to contact Xiaomi India for a statement on the subject before this report was filed, but a response wasn't forthcoming. Xiaomi ultimately gave an email statement (reproduced below) saying the claims of the researcher using a zero-day data exploit on company's servers were a "hoax" and the username-passwords represented old user accounts that had since been migrated to the revamped Xiaomi Account integrated system.

The Hacker News report claims that Huang was supposed to present a paper on the subject at a security conference in Delhi, India next month, but he has since been removed from the list of speakers. The researcher was to "demonstrate how Xiaomi Phones have been sending device data and personal data of Xiaomi Phone user to Chinese Servers. The Researcher will also release Server Logs, Mi Account username, Emails and passwords of millions of Xiaomi users which have been obtained using a Zero Day flaw in the Xiaomi Servers."

Advertisement

The conference website still has Huang listed as one of the speakers, but the organisers reportedly told The Hacker News that "'Privacy-Alert: Exposing China-based XIAOMI Mobiles' session has been withheld till the time Xiaomi investigates the data breach and accusations made by the researcher. According to the paper, the vulnerability could have been utilised by anyone to convey a data and privacy breach."

Advertisement

Here is the email statement issued by Xiaomi on the report:

We have verified that the zero-day data breach allegation made by security researcher Chen Huang and the Ground Zero Summit organizing committee reported by The Hacker News on October 30, 2014 is a hoax. The zero-day vulnerability reported by the cyber security researcher, Chen Huang, is a deliberate falsehood, and Xiaomi is taking the necessary legal action against the parties involved.

Advertisement

To date, throughout Xiaomi's history, there has only been one incident in which a two-year-old user account file was leaked in May 2014. After conducting a comprehensive investigation, we concluded that file contained information from user accounts registered before August 2012 in an old version of the Xiaomi user forum website. That information became obsolete when, in September 2012, we launched the Xiaomi Account integrated system.

In response to the incident in May 2014, we immediately requested users to change their passwords. We also announced the incident publicly via social media and to our user forums on May 14, 2014.

Advertisement

Chen Huang has recently threatened to expose data from the old user account file during a session at the upcoming Ground Zero Summit 2014, falsely claiming it to be data compromised through an existing vulnerability. This is a grave accusation, as we take our users' privacy very seriously, and we will seek legal action against the involved parties.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Lenovo Idea Tab Plus Launched in India With 10,200mah Battery: Details
  2. Realme 16 Pro to Launch With Urban Wild Design in These Four Colourways
  3. OpenAI Says ChatGPT Will Soon Become an Operating System
  4. Oppo Find X9 Ultra Battery Capacity Teased By Company Executive
  5. Xiaomi's HyperOS 3 Update Is Rolling Out to These Phones, Tablets
  6. iOS 26.3 May Make It Easier to Switch to an Android Phone
  7. Dhruv64: India's First Homegrown 64-Bit Dual-Core Microprocessor Unveiled
  8. Honor Power 2 Key Features Leaked; Could Launch With a 10,080mAh Battery
  9. SBI YONO 2.0 Launch: State Bank of India Reportedly Targets 20 Crore Users
  10. Nothing Phone 3a Lite Review: The Best Mid-Range Design
  1. Google and ChatGPT Remain the Most Popular Services as Internet Traffic Grows by 19 Percent: Cloudflare
  2. HyperOS 3 Update Rolls Out to Xiaomi 14, Redmi Note 14 5G and More Devices With Android 16, New AI Features
  3. iOS 26.3 Beta 1 Reportedly Adds Transfer Tool for Switching to Android, Notification Forwarding for Wearables
  4. OpenAI Hires New Head of App Platform to Turn ChatGPT Into an Operating System
  5. Honor Power 2 Chipset, Display Specifications Tipped; Could Launch With 10,080mAh Battery
  6. Hollow Knight: Silksong's First Major Expansion, Sea of Sorrow, Announced; Launch Set for 2026
  7. Oppo Find X9 Ultra Battery Capacity Teased By Company Executive: Here's What We Know So Far
  8. Dhruv64: India’s First Homegrown 64-Bit Dual-Core Microprocessor Unveiled
  9. Disney CEO Says AI Deal With OpenAI Is Exclusive For Just One Year: Report
  10. Arasayyana Prema Prasanga Streaming Online: Know Where to Watch This Kannada Film
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.