Datasets from about 500,000 volunteers were taken off UK Biobank's research platform and listed for sale online — an episode the charity blames on "a few bad apples." The de-identified files did not include names or addresses, but UK Biobank has suspended platform access, banned the involved institutions and worked with UK and Chinese authorities to remove the listings while investigations continue.

What was exposed UK Biobank holds genetic, clinical and lifestyle information for about 500,000 volunteers. The datasets at the centre of the incident were de-identified — they did not contain names, addresses, phone numbers or direct contact details, Technology Minister Ian Murray told the House of Commons. A national newspaper investigation found files that appeared to include millions of hospital diagnoses and associated dates for more than 400,000 participants. While stripped of obvious identifiers, those files contained enough detail that a volunteer could potentially be traced when matched with month and year of birth and major surgical events. Data specialists warn that records of procedures, diagnosis dates and derived measurements can allow re-identification if combined with other online or administrative sources. Biobank’s chief executive, Professor Sir Rory Collins, has said the charity has no evidence that any participant has been re-identified. "We have never seen any evidence of any UK Biobank participant being re-identified by others," he said. How the leak happened Until late 2024, UK Biobank allowed approved researchers to download data to their own systems. That practice changed after parts of datasets repeatedly appeared publicly when people tried to share analysis code on public code repositories. Common factors reported in the incident include: - Journals and funders increasingly require researchers to publish the code used to analyse large datasets. - Some researchers have accidentally included sections of underlying datasets when uploading code to platforms such as GitHub. - Between July and December 2025 the charity issued around 80 legal notices to a major code-hosting service to have exposed material removed; the service complied, the newspaper reported. UK Biobank says it has introduced further training for all approved researchers and strengthened rules against sharing data outside its systems. Immediate response and enforcement Sir Rory told BBC Radio 4's Today programme he was "angry" and "upset" about the listings and that the institutions involved have been banned from the platform. He described the episode as the work of "a few bad apples" who took data off the platform and listed it for sale. The charity temporarily suspended all access to its online research platform while it implements extra controls to reduce the risk of further disclosures. That suspension has effectively put scientific work reliant on live access to UK Biobank on hold for now. Sir Rory said UK Biobank worked with both the UK government and the Chinese government to have the online listings removed before any transactions took place; the listings appeared on a large international e-commerce site and were taken down swiftly. Technology Minister Ian Murray told parliament the data did not include direct identifiers but could contain gender, age, month and year of birth, socioeconomic markers, lifestyle information and measurements derived from biological samples. Those categories were the types of fields made available to approved researchers for legitimate study. Implications for scientific research The pause puts major biomedical studies on hold and raises fresh questions about how large health databases are shared with researchers worldwide.

Related Articles

Sir Rory Collins said the incident involved "a few bad apples." The suspension has paused major biomedical studies while the charity tightens controls and investigations continue.

This article was created with AI assistance.