Uzbekistan’s Minister of Digital Technologies, Sherzod Shermatov, stated on February 12 that recent cyberattacks on several information systems resulted in the leakage of approximately 60,000 unique records, disputing earlier reports that data on up to 15 mn citizens had been exposed.
In early February, reports circulated that the information systems of four Uzbek organizations had been targeted in cyberattacks and that personal data of at least 15 mn citizens had allegedly been put up for sale on the Dark Web. Speaking to journalists, Shermatov said there was no evidence that information concerning 15 mn unique individuals was available online.
According to the minister, cyberattacks were carried out between January 27 and January 30 against the information systems of three state departments. He did not specify which agencies were affected. Shermatov confirmed that unauthorized access had occurred in some systems and that a portion of data had been leaked. However, he stated that the volume of leaked data amounted to about 60,000 unique records, not millions.
Shermatov explained that government information systems are required to undergo a three-stage cybersecurity certification process. He noted that in some cases departments deploy systems without completing certification procedures, which can increase vulnerability to breaches.
The minister said that law enforcement agencies would provide additional details regarding the type of data involved in the incident. He added that, in the ministry’s assessment, the leak would not result in significant harm to citizens. At the same time, he stated that measures would be taken in cases where financial damage could occur.
Addressing concerns about potential misuse of personal data, Shermatov noted that copies of passports and other documents are commonly shared with various institutions, including schools, hotels, and service providers. He said that safeguards are in place to prevent property seizure or financial fraud, even if such information is disclosed.
He also outlined measures aimed at preventing fraud. Payment companies are being connected to an anti-fraud system known as “Telekom anti-fraud.” According to the minister, if a bank or financial service provider is integrated into this system, fraudulent actors will not be able to withdraw funds even if they obtain SMS verification codes. Additionally, the OneID identification system has introduced a function allowing users to restrict the exchange of their personal data with other organizations.
Shermatov explained that the ministry addressed the issue publicly approximately 10 days after initial reports because the alleged listing offering data on 15 mn citizens had been removed from the Dark Web. He stated that such listings are subject to review by moderators and that, in this case, the post was returned by a moderator. He said the ministry decided to comment after confirming this development, in addition to conducting an internal review.
The State Cybersecurity Center earlier reported that studies were underway regarding the alleged data leak and that further information would be provided. Some foreign online forums had claimed that the government’s main authentication system, the OAuth server, had been compromised, potentially affecting multiple state and non-state systems. However, official agencies have denied that any data breaches were detected in their systems.
Amid public discussion on social media, several government bodies issued statements. The Statistics Committee, the Tax Committee, and the Ministry of Internal Affairs each stated that their information systems had not been hacked by external sources. The National Agency for Social Protection said that reports about leaked personal data concerned an outdated database that had previously been in operation and that measures were being taken to ensure the protection of citizens’ data.
Investigations into the cyberattacks are ongoing, and authorities have indicated that additional information will be released as it becomes available.








