Original caption
In China, there's a practice called “open the box,” and a Baidu executive's daughter showed the world how easy it is. February 2025. A girl gets into a K-pop argument on Weibo over the idol Zhang Wonyoung. She starts publishing strangers' private information in the comments: medical insurance card numbers, food delivery addresses, names of overseas schools, home addresses, national ID numbers, spending records. At least five people, laid out. When someone says this is a crime, she answers that she lives in Canada and the law back home can't reach her. That line ends her. Users turn the same tools on her and pull her own life apart. Among the documents that surface is an employment certificate. It belongs to her father, Xie Guangjun, a Senior Vice President at Baidu. Baidu runs an internal review with a notary and says the data didn't come from their servers. Her father apologizes, saying his daughter, in a fit of lost composure, reposted private information she found on an overseas site. The site was a Telegram bot fed by a social-engineering database outside the Great Firewall. You feed it one phone number, you get back a stitched-together file: linked accounts, household registration, hotel and property records. Access is even gamified. One investigation found you could open a box just by showing up daily: check in once, query once. The English word for this is doxxing. But doxxing implies a lone hacker and a grudge. This is a vending machine built on China’s existing national ID infrastructure. And a teenager weaponized it during a fight about a pop star.