Mi Account Passwords Compromised Claims Report, Old Information Says Xiaomi

Advertisement
By NDTV Correspondent | Updated: 30 October 2014 18:02 IST
A security researcher claims to have obtained usernames and passwords of Xiaomi Mi Account holders by using a zero-day exploit in Xiaomi's servers.

According to a report by The Hacker News, Taiwanese security researcher Chen Huang contacted the website and "provided partial database of a few thousands of Xiaomi users, which confirmed that the millions of Xiaomi Mi accounts has already been compromised."

Based on information publicly available, there's no way to confirm if the claims of the researcher are true. NDTV Gadgets made repeated attempts to contact Xiaomi India for a statement on the subject before this report was filed, but a response wasn't forthcoming. Xiaomi ultimately gave an email statement (reproduced below) saying the claims of the researcher using a zero-day data exploit on company's servers were a "hoax" and the username-passwords represented old user accounts that had since been migrated to the revamped Xiaomi Account integrated system.

The Hacker News report claims that Huang was supposed to present a paper on the subject at a security conference in Delhi, India next month, but he has since been removed from the list of speakers. The researcher was to "demonstrate how Xiaomi Phones have been sending device data and personal data of Xiaomi Phone user to Chinese Servers. The Researcher will also release Server Logs, Mi Account username, Emails and passwords of millions of Xiaomi users which have been obtained using a Zero Day flaw in the Xiaomi Servers."

Advertisement

The conference website still has Huang listed as one of the speakers, but the organisers reportedly told The Hacker News that "'Privacy-Alert: Exposing China-based XIAOMI Mobiles' session has been withheld till the time Xiaomi investigates the data breach and accusations made by the researcher. According to the paper, the vulnerability could have been utilised by anyone to convey a data and privacy breach."

Advertisement

Here is the email statement issued by Xiaomi on the report:

We have verified that the zero-day data breach allegation made by security researcher Chen Huang and the Ground Zero Summit organizing committee reported by The Hacker News on October 30, 2014 is a hoax. The zero-day vulnerability reported by the cyber security researcher, Chen Huang, is a deliberate falsehood, and Xiaomi is taking the necessary legal action against the parties involved.

Advertisement

To date, throughout Xiaomi's history, there has only been one incident in which a two-year-old user account file was leaked in May 2014. After conducting a comprehensive investigation, we concluded that file contained information from user accounts registered before August 2012 in an old version of the Xiaomi user forum website. That information became obsolete when, in September 2012, we launched the Xiaomi Account integrated system.

In response to the incident in May 2014, we immediately requested users to change their passwords. We also announced the incident publicly via social media and to our user forums on May 14, 2014.

Advertisement

Chen Huang has recently threatened to expose data from the old user account file during a session at the upcoming Ground Zero Summit 2014, falsely claiming it to be data compromised through an existing vulnerability. This is a grave accusation, as we take our users' privacy very seriously, and we will seek legal action against the involved parties.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme C83 5G Debuts in India With a 7,000mAh Battery at This Price
  2. Here's When the Poco C85x 5G Will be Launched in India
  3. OpenAI's GPT-5.4 AI Model Is Here, and It Can Use Your Computer
  4. OnePlus 15T Key Specifications Confirmed Ahead of Launch in China
  5. This AI Device Claims to Stop Microphones From Recording Your Voice
  6. Poco X8 Pro Max Visits Geekbench as Company Finally Confirms Chip Details
  7. Google Pixel 10a Review: More of the Same?
  1. Vivo X300 Max With Zeiss Cameras and Android 16 Spotted at MWC 2026, Could Launch Soon
  2. WhatsApp Update Introduces Support for Discovering Stickers While Typing Emoji: How It Works
  3. This AI-Powered Portable Device Claims to Detect Microphones and Jam Audio Recordings
  4. Poco X8 Pro Series Global Launch Date Leaked Ahead of Anticipated Debut: Expected Price, Specifications
  5. MacBook Neo Geekbench Scores Indicate It Performs on Par With iPhone 16 Pro Max
  6. Xiaomi Testing Experimental AI Agent Miclaw, Can Perform Complex Tasks Across Devices
  7. Dear Radhi OTT Release: Where to Watch the Tamil Thriller Online?
  8. With Love Now Streaming on Netflix: Know Everything About Plot, Cast, and More
  9. Kaattaan OTT Release Date Confirmed: When and Where to Watch Vijay Sethupathi Starrer Online?
  10. OnePlus 15T Display Size, Ultrasonic Fingerprint Sensor Confirmed; Geekbench Listing Hints at Chip, Memory
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.