37 comments

  • aiiotnoodle 2 hours ago
    I'm seriously at a point where I'm opposed to talking to my doctor because the information may be digitally recorded and leaked, going on a flight because my passport may be used to aqquire a loan by cybercriminals, comparing car insurance because my phone will be called by robocallers selling me things or verifying my ID with websites because it might be used to associate my information with whatever else I do online.

    I don't think, for a vast majority of cases, these companies I'm forced to interact with can be trusted with my data and it's having a real world negative impact. Even with the best intentions the information is somehow valuable to steal and I'm baffled how it's not secure.

    There should be some consequences for companies asking for things like SSN/National Insurance numbers on job adverts or retaining drivers licence photos after test driving a car, they just don't need the data anymore.

    • suslik 1 hour ago
      I am at a point where I simply stopped worrying and began to love the bomb. I did my best, I really did - degoogled before it was trendy, dropped all social media, built a homelab for complete data ownership, set up matrix messaging with family, and so on - but it feels like a wasted effort at this point.

      All my data is out there, one way or another, and a dedicated cybercriminal - or worse, a government entity - can obtain or exfiltrate it without issues. I know it, they know it, everyone knows it.

      The only thing I can change now is my reaction to this fact, and although the idea of off grid autarky is tempting, I am not there yet. I just don't want to stop living - flying abroad, going to doctors - I just accept that privacy in the current state of human condition is impossible, and move on with my life.

      • _the_inflator 16 minutes ago
        I agree.

        And most people on the behavioral side do too, but not at the cognitive level. EU is the best example with EU AI Act, strict data regulation as well as privacy rights, on the other hand demanding that Apple does serve the EU with AI.

        I have mainly one distinction: the state is the worst protector of your data and the most ruthless gatherer of all your details.

        Opposite to the open sourcing of your data in the end by the state are private companies who live by your data but do this for 20+ years - battle tested protection and hardening against malicious hackers.

        Security is their business while security for the state is a cost factor.

        Being at the mercy of some ignorant politician is not the best way to talk about data security.

        Berlin, Denmark - those are the known one. And there are many more to come.

        And regarding cognitive dissonance: politicians demanding high standards and punishing data loss ruthlessly on the one hand, giving oneself a pass on a hack is nothing to increase trust into the system.

        X got fined for a missing blue mark. Berlin? Denmark? Others?

        A second aspect is that the average guy doesn’t get that part of the whole spectrum must be the degooglers, the home server guys.

        So it is relatively easy to get data on them as well just by filtering out the other data.

        In other words: 95% not doing degoogling makes for a great small sample of 5%. Negating and interpolating other demographic and psychographic factors and you get a great way of gaining insights.

        And remember: being the one who is not using google when being around other guys who do - magic.

        So my idea is simple: what’s in it for me, and the state offers way lower value than Google and co.

        Pick your fate.

      • shit_game 1 hour ago
        >I simply stopped worrying and began to love the bomb

        This may apply to the consequences of ones data being subject to so many breaches and leaks and thefts, but it should not be the attitude one adopts towards the idea of ones data being taken and used by so many parties. At some level, my data is my personhood - it is my evidence of myself, and my record of myself, and my proof of myself. It encodes who I talk to, what I'm interested in, where I go, and what I do. My health, my finances, my habits, vices, schedule, family, friends, coworkers, beliefs. People more clever than myself use this data to advertise to me; people more powerful use this data to surveil me. When will people more malevolent use this data to persecute me?

        I should not have to love the bomb because the bomb will kill me.

      • gentlerain 1 hour ago
        The next frontier is to maintain 'limited privacy'.

        That's denying most culprits the opportunity to use the collected data against you.

        Like always on VPN, turning off personalization, ad guards and using open source products where possible.

        • arethuza 1 hour ago
          It's a bit like physical security of your house - could someone break into my house, not easily but it's a house not a bank vault. Keeping our gate closed and having a large dog (who is actually very friendly) about the place probably keeps the vast majority of possible thieves away.
        • TeMPOraL 1 hour ago
          That's still a bit on the obsessive side. The reasonable position is the same as it always has been in the real world too:

          - Don't volunteer your intimate details left and right;

          - Feel entitled to deny requests for unnecessary data (and advocate for such rights if you're in position to)

          - Otherwise don't sweat it, because you can't actually control what others know about you, you never could

      • ruszki 1 hour ago
        Similarly. My browser was carefully containerized, with a ton of anti fingerprinting measures, VPN, Linux, Librewolf, everything. Even on my phone, I restricted whatever possible. Then one day I went to the YouTube main page, and I saw that Google somehow got to know that I played Minecraft again after a decade. I gave up right there. I suffered to avoid this, and it was pointless. I knew at that point already that probably all my PI is public information anyway, but I wanted to restrict whatever possible, and no, everybody sells my data anyway, and it seems that avoiding fingerprinting is impossible without turning off the internet completely, and ditching smart phones.
        • neobrain 1 hour ago
          > Google somehow got to know that I played Minecraft again after a decade. [...] I knew at that point already that probably all my PI is public information anyway

          How are you jumping from Minecraft (probably one of the most watchtime-generating content types out there) being displayed on your main page to… your personal information being known to everyone?

          • close04 23 minutes ago
            Your data is still out there, just compartmentalized so each outside party only has a bit. It turns out that's a losing strategy when each outside party decides to cooperate with every other and pool/share/sell that data uniquely attached to you.
          • yieldcrv 50 minutes ago
            because it’s the same process of intermediaries accumulating, inferring and sharing data to each other

            intermediaries that will be compromised

            • neobrain 27 minutes ago
              > because it’s the same process of intermediaries accumulating, inferring and sharing data to each other

              Except that YouTube doesn't need any of that to recommend Minecraft videos to you. One mundane explanation that seems more likely is that it's the type of content that on average works best on people they don't yet have information on.

              Reminds me a little of these "phones listen to everything we say, otherwise I wouldn't have been shown this ad" anecdotes that don't hold up against empiric evidence.

        • sillyfluke 51 minutes ago
          >Then one day I went to the YouTube main page, and I saw that Google somehow got to know that I played Minecraft again after a decade

          Did you play minecraft on the same network? If so, I'm not sure why the results are surprising or why it would negate all your efforts. If someone else played minecraft on your network you would also see a minecraft video on your main page I would imagine.

      • hypfer 54 minutes ago
        These swings can be avoided by not doing stuff so hard but instead more effectively.

        For example, matrix sucks ass. It's terrible. Everything about it is a bad experience. Of course you'd want to eventually stop using it and go back to the previous life.

        But that is not the correct take-away.

        The correct take away is to include UX (and honesty to yourself about it) in the calculation and to not go all in on an unsustainable compromise, just to then snap back to doing the opposite ca 3 months later.

        Same as with loosing weight, really. If you replace 100% of the pleasure of eating with the "right" but unpleasant solutions, you will not be able to keep that diet going indefinitely.

      • thewizzardofnl 1 hour ago
        I think both are possible. To have a goal and to accept reality. I would not draw the conclusion that all privacy measures are meaningless. It is hard, but I think it is still worth working towards a goal of better privacy for citizens.
      • TeMPOraL 1 hour ago
        Evidence is pretty clear after decades of this: big data breaches are inconsequential for an average person.

        They happen all the time, nobody cares, criminals who want to target you will target you anyway, criminals who don't target don't care about you specifically, legitimate entities cannot use this data anyway, and legitimate scammers (marketing) will find different ways to get you to give them the data you need.

        At this point I thing privacy obsession is modern copium, a way for people to deal with the fact that we're all individually a speck of dust on the face of human civilization. It's about asserting, "I am not an NPC, I have this richness of experience", and then trying to hide it all in case the world wants to check.

      • sillyfluke 25 minutes ago
        >I just don't want to stop living - flying abroad, going to doctor

        Good, you're not throwing out the baby with the bathwater. I don't get why you think throwing out the bathwater itself was wasted effort though.

        The point is to get rid of things you can live without. If you're going to get rid of something but then spend every day thinking of its absence, then yes, that may be bridge too far. Otherwise, getting rid of it has some value.

        I don't see the harm of asking, "Do I need this entity's services enough to justify forking over this data" for every entity that you interact with. Everyone draws their line in the sand at a different place. Data hygiene is a good phrase for that reason, everybody's acceptable level of hygiene (or lack thereof) is different.

      • ionwake 1 hour ago
        I gave up when i realised Firefox had google analytics and noone even knew or cared. That was about 10 years ago now.
        • Kbelicius 1 hour ago
          Because it did not. Extensions page used them but nothing else.
          • ionwake 1 hour ago
            I love the bit where a programmer always proudly chimes in with this statement as if it means anything.

            You dont get it bro, its not a good vibe.

            And if I had bean in management I would have fired anyone involved with that decision.

            Why is it so often HN that I point something obvious out , like Rockstar having clearly failed management and a complete loss of control, but instead of agreement or silence I always get flak from some random user who just doesnt get it, and then a year later the company starts falling apart.

            Im just a guy who recognises patterns and im not even smart.

            • Kbelicius 1 hour ago
              > I love the bit where a programmer always proudly chimes in with this statement as if it means anything.

              So you knew that fierfox never came with google analytics but you decided to claim it anyway...

            • TeMPOraL 1 hour ago
              > Why is it so often HN that I point something obvious out

              Because many "obvious" things are just plausibly sounding bullshit. For example:

              > Rockstar having clearly failed management and a complete loss of control

              That's both very broad and generic, and completely unfalsifiable, and comes with nothing backing it up. It's just an unsubstantiated opinion. These things are fine when drinking in friends, or otherwise socializing by bonding over ramblings.

              If you want to convince someone of something, the standards of evidence (not to mention, clarity of thinking) are a bit higher.

            • bluebarbet 1 hour ago
              >the company starts falling apart.

              This site will start falling apart if we don't keep things civil.

            • wyre 31 minutes ago
              What? So 10 years ago you though 1+1=Firefox is using Google Analytics, something you can't prove, but is "obvious" and "recognizing patterns"

              I get wanting to be conspiratorial, but its not cool to go after others that challenge your conspiracy, even if its "obvious"

    • strideashort 2 hours ago
      I recently needed a lawyer on something that involved lots of highly sensitive PI.

      Sending my file over to lawyers in a semi-safe way has proved impossible.

      And in any case, i received an answer with lots of PI over a plain email…

      Absolutely maddening

      • master-lincoln 1 hour ago
        Why? I would assume encrypting and sending the key via a different channel would be sufficient. Or are lawyers still not technically apt to do so?
        • Telaneo 34 minutes ago
          If normal people aren't, I wouldn't expect lawyers to be either. If there's no happy path to encrypted communication, then it will not happen.
        • CrimsonRain 1 hour ago
          Then lawyer replies in plain email discussing those very things...
          • data-ottawa 38 minutes ago
            The lawyers I’ve used have always asked and used encrypted email. I don’t know if that’s regional, but it was taken very seriously here.
    • msdz 1 hour ago
      > There should be some consequences for companies […] retaining drivers licence photos after test driving a car, they just don't need the data anymore.

      I know it’s modern American tech tradition to make fun of the GDPR, but this is genuinely one of the things it stipulates: You’ll get at least a slap on the wrist, or potentially much worse, if you needlessly keep data around longer than necessary to do the task you had collected it for in the first place.

    • mdp2021 1 hour ago
      > where I'm opposed to talking to my doctor because the information may be digitally recorded and leaked

      Let me say "Hi mate, +1". State doctors? There are territories in which a pharmacological prescription is shared DB only now (where previously they could be on paper - a secret between you, the pen, the paper, the pharmacist and the gods). Private entities? Good luck finding one that does not require a privacy waiver as a condition for the visit. Searching for a medical dock (a dock for a doc), calling them to ask? "This is a recorded message. If you proceed with the call then you agree..." (Hang-up click).

    • chrisjj 22 minutes ago
      > I'm baffled how it's not secure.

      Our civilisation needs to face up to the fact the reason is simply: its stored on a connected computer.

    • amelius 2 hours ago
      I mean why does every hotel need to make a copy of my passport?
      • ElDji 2 hours ago
        It is a basic police requirements on most countries. Hotels must collect visitor id's and keep it for several weeks.
        • toyg 2 hours ago
          Yeah, it's old-school people control. This said, these days it could be done electronically, without the hotel storing physical information: at check-in, you put your passport in goverment-issued, (hopefully) tamper-proof machines, the hotel confirms length of stay, police server gets the info and that's it; early checkouts, the hotel must notify via some web portal. It would be relatively easy to implement.

          But nobody really cares enough to spend money modernising this sort of system.

          • rithdmc 1 hour ago
            I'm sure they're done electronically in some places: Your passport details are appended to the shared Google Spreadsheet...

            I'm only half joking: I used to work in payments, hotels didn't care about PCI. Full card numbers stored everywhere.

            • toyg 1 hour ago
              I know, and that's really the thing: nobody cares, not the government and certainly not the hotels.
              • rithdmc 1 hour ago
                I don't think my at-the-time employer cared much, either :)
          • GJim 1 hour ago
            > This said, these days it could be done electronically

            Are you 'avin a laugh mate?

            A photocopy of my passport is going nowhere and is shreadded afterwards. An electronic copy..... God lord.

            The GDPR also requires data deletion once you no longer need it; physical as well as electronic. This is common sense, and why some organisations don't do this is simply mind boglling.

            • toyg 1 hour ago
              The whole point is that the hotel would not even get a copy, the machine would just send hashes around and the hotel would only get an anonymous transaction ID to store. It would probably be even more secure than what you have today at the airport.

              If you think photocopies kept in some folder accessible to anyone working in the hotel, with a promise to delete it at some point, is "secure" in any way, I don't know what to tell you.

              • GJim 44 minutes ago
                Good lord!

                Rather a paper data breach exposed to a few hotel employees than eletronic data exposed to the entire planet!

                • tlb 35 minutes ago
                  When paper data is breached, the crooks don't steal the paper and put in their own locked file cabinet. They take pictures of the documents and sell the data on the dark web. So the end result is the same.
                  • mainecoder 5 minutes ago
                    the will need to take a picture everytime they are lazy but stealing all the people who ever stayed at that hotel is a simple copy past taking less than 10 minutes
          • carlosjobim 1 hour ago
            All these giant data leaks are coming from the government's "tamper proof" systems!
            • toyg 1 hour ago
              I know, and it's really the trade-off whenever this sort of system is centralized: you can better secure the leafs, but the central repository becomes an even juicier target.

              This said, the police already has a database with these info, and it likely is somehow already on the network, so adding an api (if done properly) would not dramatically alter the exposure profile.

      • Scaled 1 hour ago
        I just tell them they can look at it but not copy it and that's satisfied them, for now. Sometimes had to get a manager in, but never had them deny me fully. I'm sure sooner or later I'll run into a stubborn one and have to scramble for a day-of replacement hotel, and that just adds to my list of reasons to avoid travel.
      • Razengan 2 hours ago
        And why are politicians immune to all of this shit??

        Why can’t WE spy on them 24/7?

        • sparkling 2 hours ago
          Because you are a slave, Neo.
        • lynx97 2 hours ago
          If democracy really worked, and your desire to spy on politicians is shared by enough people, supposedly, you should be able to create your own party which has that explicit goal. Maybe find a few other goals, or you will end up like the pirates :-)

          I am writing this because I don't think democracy works as advertised.

    • TacticalCoder 56 minutes ago
      In France the french IRS leaked infos about the wealth of its citizens and evil thieves cross-checked it with leaks of people who ordered hardware wallet for cryptocurrencies and families are getting kidnapped and tortured. In a recent case three family members have been beaten over two days so that... 40 000 EUR could be stolen.

      That's the world we live in.

      "Police and thieves", collaborating one way or another (leaking data collected by big brother and then having big brother being very soft on crime is one way to collaborate with evil people), "to scare the nation with their guns and ammunition" (as in the reggae song).

      As much as I don't like the cryptocurrency ecosystem, I don't think facilitating and encouraging kidnapping and torture is the way to go.

      Shame on the french government.

      Two sides of the same coin.

      • Frieren 22 minutes ago
        > As much as I don't like the cryptocurrency ecosystem, I don't think facilitating and encouraging kidnapping and torture is the way to go.

        The cryptocurrency ecosystem is used to not only avoid taxation but to enable criminal activity. How many people are being held hostage and the ransom will be payed thanks to cryptocurrencies?

        I do not like the cryptocurrency ecosystem either. And I totally agree that it should be abolished. It is just a way to finance crime and terrorism.

    • Hamuko 2 hours ago
      I’m never going to a therapist after one company leaked all of the patient data / therapy notes for 33k patients.
      • lux44 1 hour ago
        It looks like you punish yourself unnecessarily, for things that are out of your control.
        • wyre 25 minutes ago
          Thanks, I got a good laugh out of this comment, but therapy is just a tool to mostly learn how to deal with things that are outside of your control.
        • childintime 43 minutes ago
          A therapist reads like the-rapist, in his case, and in many others. It's bandaid on a failing system, a failing society, and instead of fixing the system the victim has to pay the-rapist. Misaligned incentives all over again. To correct this therapy should be free, because the need for it shouldn't exist. Let the tech billionaires pay for it: if they cause the damage, they have to pay the bill. That'll teach them how to prioritize user satisfaction.

          > things that are out of your control

          That's because of corruption. A system that doesn't want to change because some tits can't be let go of. A well working system would render control back to you.

    • tokioyoyo 2 hours ago
      I said it before as well, but it’s because nothing “publicly really bad” happened despite the leaks and stolen information over the past decades. After Equifax breach, everyone got tired, because company survived, and whatever identity theft happens from time to time gets swept under the rug. It didn’t impact most people’s lives, despite leaking half of the US’s SSNs and etc. Then fatigue kicked in, and with subsequent leaks everything just mellowed down, so nobody cares.

      I’ve switched to operate with the idea that my information has already been leaked at some point. I should be generally ready to fix the problems if/when identity theft happens, rather than inconveniencing myself and figuring out the third party trust situation.

    • ratg13 2 hours ago
      This is just a general American complaint that has merit on its own, but has nothing to do with the article and is just derailing any discussion about the article itself and driving the conversation to your own personal concerns about something completely separate.

      In this case, the EU does have consequences for data breaches where proper protocols are not followed.

      Additionally, this is not private information .. most anyone can look this information up. ID numbers are not confidential information like SSNs are treated in the US.. they are just a number to tell person A from person B. You give this number to everyone without thinking about it because it's how every company you interact with identifies you.

      In this case a rogue company, or compromised company, used their access to contact the central database to download everyone's information.

      In my country we essentially use the same system, except for we still allow companies to download the whole database if they want to instead of making individual queries.

      In this case the access to their system was unauthorized, and under GDPR data breaches have to be reported within 72 hours. Companies can't make the decision on their own that it's not a big deal.

    • Zealotux 52 minutes ago
      [dead]
    • heresie-dabord 1 hour ago
      > I don't think [...] these companies [...] can be trusted with my data

      Abusing privacy is the lucrative norm. The laws won't help you and the government is busy with its corporate agenda.

      • hk__2 59 minutes ago
        There’s nothing lucrative in abusing privacy, and yes the government is busy but it has nothing to do with a "corporate agenda", any government or any country with more than a few millions of people is busy, agenda or not.
  • bryanrasmussen 0 minutes ago
  • gnull 2 hours ago
    In Sweden, to avoid this kind of malicious leaks, we leak the residents' data officially. https://hitta.se lets you look up personal numbers, names, addresses, birthdays and sometimes phone numbers of any resident. The residents are not asked for consent, the data goes there automatically (some of my friends had success with having it removed from hitta, but it comes back once you change residence address).

    It's quite convenient, when you meet a new friend, to go and check what neighbourhood they're from, who do they live with and where they lived before.

    What's the big deal, Danes? What do you have to hide?

    (The provocative tone is intentional as a joke, I'm not even a Swede, I just find the brotherly rivalry between Scandinavians amusing.)

    • aranelsurion 1 hour ago
      Are there no murderers, crazy ex-boy/girlfriends, targeted harrassment and spam calls in Sweden?

      Not that any other country does much better in this regard. Still it sounds a little wild to me that you can get this information without even needing to hit a shady forum and download some csv. Maybe lowers the bar too much.

      • Alpha3031 1 hour ago
        I've been told back in the day it was quite normal get a physical, dead-tree book with similar information sent out to you every year, until people decided that was a waste of paper.
        • consp 53 minutes ago
          It used to be illegal here to reverse look up a name matching to a phone number, since it was "owned" by the state telephone company and they didn't want that happening. But you were allowed to reverse look up the address of a number and then look up the person and match it to the number. So that magic happened under the hood. The trick was getting the residential information but since that wasn't a problem in the '90s I'm sure it is even less of an issue now.
      • lifeisloving 32 minutes ago
        When I lived Norway, my gf at the time would look up the license plates of cars that annoyed her and could see how much debt they had on the car to make fun of them. Scandinavians are oddly very open with this type of personal info.
        • embedding-shape 24 minutes ago
          I don't even see salary or what your debt is as "personal information" (am Swede not in Sweden), personal information is stuff that no one else would need to know. What people earn affects not just people around you and others in the workplace but also society at large, makes a ton of sense for that stuff to be public.

          Especially great that you can see what employees at competitors earn, what your peers at your workplace earn and what your boss earns. Become a hell of lot easier to ensure you're not exploited. Helps that Sweden has a really strong union-culture as well.

      • f646993e074382f 1 hour ago
        Yes, it is possible to have a protected identity.
        • fwn 1 hour ago
          It seems that you can have a protected address in Denmark as well. Apparently, the protected address is even a field in the current leak.
          • mrweasel 39 minutes ago
            I worked on systems that has this, it would be funny if it wasn't putting people at risk. You can see the address, and then as you say there is a field that indicated that this is a protected address, so don't leak it,... unlike the others with you're then completely fine to leak?
      • embedding-shape 35 minutes ago
        > Are there no murderers, crazy ex-boy/girlfriends, targeted harrassment and spam calls in Sweden?

        Of course, contrary to popular belief, Sweden is not a perfect country without violence and shit people!

        It seems to be somewhat respected overall though, but I'm sure it'll eventually disappear. For the people who are stalked and what not, it's relatively easy to apply and get "protected identity" if you're affected by those things, and then eventually all those 3rd party websites remove the stale data.

        Personally I solved this problem for myself by moving away from the country.

      • tuwtuwtuwtuw 1 hour ago
        There are. You can get a protected identity if you have that issue.

        The current system has been in place around 1770. There's some pushback against it the last few years.

    • mrweasel 1 hour ago
      I have been advocating for Denmark to do the same for 15+ years. The fact that your social security number can be used for anything on it's own is a disaster. Mostly it can't anymore, because you have to do electronic signing with MitID, but it's still considered secret. If you own a home in Denmark, address information is already public, but a little hard to lookup.

      The problem with this leak mostly going to be those with hidden addresses or secret phone numbers. Last time something similar happened was when it was shown that you could pretty much just guess a persons social CPR number if you had their birthday. Normally you could narrow it down to 6 or 8 possible numbers then use the phone companies websites, pretend to create a new account, enter the CPR number and check if you guessed correctly. Because the demo was done with politicians, then phone companies no longer ask for CPR upfront.

      • sigmoid10 1 hour ago
        >Because the demo was done with politicians

        I feel like this should be the default. Responsible disclosure to the affected company, followed immediately by disclosure to every politician in the dataset. Once we start collecting high profile cases this way instead of waiting X days for a faceless corporation to release a fix, companies will think twice about their security and the data they collect if that could make them end up on the shit list of the local government.

      • groomlake 1 hour ago

          The review conducted shows that the unauthorized access does not include the names and addresses of individuals who have chosen to register with name and address protection.
        
        From the source
    • sajithdilshan 2 hours ago
      I was actually surprised when I heard about this for the first time. Also I've heard that even the salaries of people are publically available. That's really cool.
      • Gravityloss 1 hour ago
        This probably improves economic efficiency a lot. Want to build something and remember meeting a relevant expert 3 years ago at a party? Easy to find that person and start doing business...
        • dist-epoch 1 hour ago
          Yes, it's great for businesses, you can search for the cheapest labor, and helps you avoid paying someone much more than they previously earned.
          • embedding-shape 33 minutes ago
            And private individuals as well, as you can see what your colleagues earn without having to ask anyone, and can even see what your boss earns, or what the competitor to your current workplace earns! I have to say salary negotiations are a lot more straightforward (and fun) in Sweden as an employee than other places I've worked.

            Overall the benefits for employees seems way broader than the benefits for the companies.

      • Boltgolt 1 hour ago
        You do have to request them and the person you requested them for will know you did so
        • kassner 57 minutes ago
          It will be registered if you ask Skatteverket directly, but if you go via a company (i.e.: Eniro), the subject does not get to know it.
          • ahoka 17 minutes ago
            I think this is the worst part about it. Some company making a profit selling my data should be illegal.
    • mingusrude 1 hour ago
      Personal numbers are not available from hitta.se.
      • Hikikomori 1 hour ago
        Not in full as it doesn't have the last 4 partly random digits, though personal numbers aren't that useful even if it was the full one.
  • bryanrasmussen 11 minutes ago
    Just to note - the population of Denmark is 6,032,304.

    So essentially the whole population's data has leaked. Furthermore, the notice says mv, which is abbreviation for etc. So it says "name, address, cvr number" etc.

    That etc. is funny because the Danish government has a thing called NemID which you use to log into pretty much any online service, including banking, and you can install it on your phone, and when you lose it though you can verify by calling up and giving personal information to verify it is you.

    Now there are a bunch of things about this system that are contemptibly stupid and annoying that I won't go into here because of my blood pressure. But now I wonder if the mv. of the personal data covers stuff you could conceivably be using to get a new NemID.

    on edit: the really young have not had their data leaked, probably, and the excess of course covers people who used to live in Denmark and left.

    • ulrikrasmussen 5 minutes ago
      I think you mean MitID, but yes. I have tried going through the process of getting a new MitID at the citizen service desk, and the questions I am asked to verify that it is me are almost all family related. If the leaked data reveals things like parent/child and spouse relationships then that process is cooked.
  • madsohm 7 minutes ago
    I see this as a good thing. It means that we'll (hopefully) get stricter security revolving around using these numbers. It'll no longer be enough just to yap out a 10 digit number to "verify" you are who you say you are. We already have a (albeit heavily critiqued) national 2FA system in place (MitID).

    We'll have to start treating the CPR number as just a username, instead of a password. It should never have been "secret" in the first place.

  • m12k 48 minutes ago
    This comes only a few days after a data breach was reported at the Technical University of Denmark [1], exposing the personal records of current and past students, faculty and staff. That included their CPR numbers (government id at the central person registry), that could for example be used to look up their official place of residence. All in all, it seems likely that someone just got the table they needed to join on the first breach.

    [1] https://www.dtu.dk/english/newsarchive/2026/10/cyberattack-o...

  • ntoskrnl_exe 2 hours ago
    Just that easily all the private conversations of everybody in the EU can leak if Denmark succeeds at outlawing E2E encryption with its Chat Control proposal.

    Not trying to downplay the situation, but I hope this will be eye opening to the responsible people.

    • Proof 1 hour ago
      Unfortunately, for the people who strongly believe that Chat Control is the way, they will use these types of events as further evidence as to why spying on everyone is the best deterrent.
    • raxxorraxor 1 hour ago
      I heavily doubt these people are open to self-criticism in any way. They have their program and are set to implement it.
  • clan 3 hours ago
    For those not getting the scope of this. The following has been compromised for all living danish citizens and foreign nationals which have had recidence. And quite a few dead ones as well.

    - Social security number

    - Age

    - Sex

    - Family relations

    - Physical address

    - Protected addresses

    - Sex change

    This is a country with quite good health records. Unfortunately also previous problems with proper non-reversible anonymisation of said data when used for research.

    • vasusai 2 hours ago
      Where did you get that from? All I saw was: names, addresses and CPR numbers.

      Additionally it was via third party access granted to private companies.

      https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfatt...

      • Mashimo 2 hours ago
        CPR number contains Age and Sex. It's date of birt DD MM YY. Plus four digits where you can read the sex from. I think it's even vs uneven numbers.
        • mrweasel 1 hour ago
          It's honestly worse. DDMMYYY (the last Y is from a lookup table to know if it's 18YY, 19YY or 20YY). If a person is born before October 2007 you can even do a checksum using the last digits to verify that the number is "correct" (not necessarily in use). And yes, last digit is an even number for women, and uneven for men.
          • jjgreen 39 minutes ago
            .. decimal place for interestingly gendered?
    • kasperni 2 hours ago
      Nobody knows exactly what was accessed. What you have listed is what the register contains, not what was accessed. People with "Protected addresses" have specifically not been compromised.
    • deanc 58 minutes ago
      In Finland, this would be enough to get you through the security checks at pretty much any institute via phone, possibly excluding banks.
    • wodenokoto 2 hours ago
      I think it is worth mentioning that age and sex is encoded in the social security number.

      There are exceptions where the encoded birth date will be wrong (like immigrants with unknown birth dates) or dates where there are more people than the 4 digits that encode checksum validation and gender can handle.

      • consp 50 minutes ago
        I learned a few days ago from a friend, when the other leak at the university was reported in the Danish media, that the "random" part is only 4 digits and as a bonus is sequential. So if you register in the country as foreign citizens together with your partner those are likely sequential.

        Then again, in my country some municipalities handed out numbers starting with your birth year....

      • vintermann 1 hour ago
        A good time to remember that cramming data into your identifiers will come back to bite you... It hasn't really been necessary since databases replaced library catalogs anyway.
        • brabel 54 minutes ago
          I think they do this to make it easier to remember your number. It’s really not private data in the Nordics as others mentioned, even your address and phone number and , on request, salary can be easily found out legally.
    • delamon 2 hours ago
      They say that persons with protected address had not been leaked.
      • toyg 2 hours ago
        What's a protected address, witness relocation programs...?
        • LarsKrimi 1 hour ago
          When you change your address you can click a checkbox saying you want a protected name/address. This means that companies that have you as customers/clients won't be able to get the new address, mail won't be redirected, etc

          I did it accidentally during my last move and it was a pain in the behind

          And it expires after a year by default so it feels rather pointless

        • Mashimo 1 hour ago
          You can just apply for protected address. I did that once, because I did not want that my .dk domains whois would show my name and address.

          I managed to get protected address, it's just to log in somewhere and request it. I can't remember the details, but it made for example banking _slightly_ more annoying. They would call me so they can send me a letter. Also makes it harder for people who know your name to look up your address.

          Never managed to get my name removed from my domain whois and at some point removed protected address again. In theory, if I share one of my other .com domains on the internet, an attacker could reverse DNS the IP, find my DK domain and thus get my full name and address.

  • Roark66 12 minutes ago
    You know, recently a medical SaaS provider's system was hacked here in Poland as well. Medical records of 20mln people covering pre 2024 back leaked. The attackers claim to have got it via a vulnerability that any company could've had. Fine.

    But inside that network the security was a joke. Basically developers used real non anonymised archival data uploaded to s3 all devs had access to, to test the software. Data containing all the private stuff mentioned.

    Absolute peak of incompetence. It wouldn't be hard to anonymised the data even just by hashing the names and certain other records or replace them with dummy data.

    But what annoyed me the most is there is no info about huge fine for the company. No article written by the company explaining what internal failures they will fix to prevent it happening in future.

    Nothing.

    Those things have to be prosecuted and punished. Otherwise no one has any incentive to keep the systems secure.

  • Quothling 2 hours ago
    As someone who spend a decade in the Danish public sector, among other things working in groups on national architecture. I'd say that we reap what we sow. IT and digitalisation is not taken very serious in our public sector. In most places it's placed under something, and until recently it didn't have it's own ministry. Right now it's even a shared ministry, and there is little focus on cyber security. What has arrived in recent years is solely based on the thread of hybrid attacks from Russia.

    Compare this to the ministry of transportation, which has full resources. This is despite the fact that most people in this country spend less time commuting than they do working on a computer. Not that transportation isn't important, but maybe digitalisation is as well?

    My personal CPR has been leaked a couple of times though. Hilariously the first time it was leaked when a couple of unencrypted laptops were stolen from the biggest IT union in the country. We have a system in place where you can flag your CPR as having been leaked. Though I suppose now we might as well consider every one of them to be leaked. In theory a CPR on it's own was never meant to give any sort of authority or access, but again, this wasn't the practice in a lot of place. So I guess this leak may be a blessing in disguise in that sense as well, as it'll highten security because of broken trust.

    • Mashimo 2 hours ago
      > IT and digitalisation is not taken very serious in our public sector.

      I think I get what you are trying to say, but just for other people reading this: Denmark is one of the "best" / advanced countries when it comes to IT and digitalisation in public sector in Europe.

      • Quothling 1 hour ago
        Maybe 10 years ago, but other nations have caught up. Italy has their Sistema di Interscambio. Germany and France have taken digital sovereignty serious. Spain is big on open source (and ruby for some reason). Estonia has been miles ahead for more than 10 years. It's true that we have some ease of use systems compared to most of Europe, but we also have a lot of horror stories.

        That being said it's not like us being shit at cyber security doesn't mean other countries aren't also shit. Look at Australia getting hacked by AI. I know it's all the rage to blame OpenAI, but really, shouldn't Australia count itself fortunate it wasn't an enemy nation state? Or that their lacking security got exposed before it was.

        • mrweasel 1 hour ago
          You're conflating two different things here. What Denmarks excels at it implementing public IT solutions that makes processes smoother, like patient records, medical perscriptions, digital signature, a nation-wide digital identity, things like that. Digital sovereignty isn't part of this, and Denmark isn't particularly good at it, nor is it really valued that highly. Same for cyber security, I'd say that it's down to dumb luck that it's not worse. There is a city, Randers, they can't send email to the domain anders.dk (Anders being a pretty normal Danish name). Why? Because the butterfingered public employees in Randers could stop sending personal information about citizen to anders.dk, which has a catch-all email. They simply forgot the "r". The problem is the lax attitude to emailing sensitive information, probably via a Microsoft run Exchange server, but rather than fixing that, they just blocked the anders.dk domain.
        • Mashimo 54 minutes ago
          Mhh, I don't know. In Germany they proudly proclaimed their BAföG / Student loans (SU in Denmark) is now digital. But what was digital was just the client side, on the government agency side they still would print out the applications. And because they where used to people sending in paper, they had to hire more people to help with the printing. AHHHHH. That is the state of German digitalisation.

          There are things I wish I could change in Denmark, mainly the power sockets and number system (Base 20 what the heck?) but Denmark is on a good course when it comes to IT understanding. Both the broader society and government implementations.

          Yes yes, Estonia is better. But Denmark is still doing good.

      • porsager 48 minutes ago
        Another Dane here, and that is absolutely not true. Where's your source to back up this claim? (I'll show you mine if you show me yours)
      • KingMob 1 hour ago
        Can't speak for the Danish govt in general, but you should look up the history of the property tax scandal and the projects that tried to fix it. I was part of the third attempt to rectify the problem at SKAT.
        • Mashimo 52 minutes ago
          Or how there still are over 200 people working fulltime on the corona mink .. "event"

          That said, compared to other countries the tax / SKAT is also quite decent.

  • hn_submit 14 minutes ago
    I demand our representatives come up with legislation that puts hefty fines on data breaches.

    Companies are opting for higher profits by not investing in securing private data entrusted to them. We need to make the balance tip the other way.

    As long as there aren't any financial or criminal penalties companies will not care about data being pilfered.

  • archixe 2 hours ago
    The article mentions that they accessed the information through a Danish company whose access has been revoked now. I find it really surprising that a company could access these records without any limitations on which info or how many records they can pull.
    • haute_cuisine 26 minutes ago
      Claude, calculate salaries, make no mistakes. (they probably forgot the last part)

      I wonder if company used some kind of automation that decided it needs all CPRs for whatever it was doing.

  • jakub_g 2 hours ago
    In the past few months, there were several huge data leaks also:

    - in Poland (from private medical companies used by doctors) with estimated 20M affected people (half of population)

    - in France (from tax office), 678k people affected

    With AI getting more capable, and with Russia escalating things, I unfortunately expect more to come.

    • adlotsof 46 minutes ago
      - Germany, Berlin: personal information of civil servants, secret information about civil protection, emergency communication systems of the german gouvernment, overall 6 TB data
    • 233mhz 2 hours ago
      Gun ownership records were leaked in france recently too, including identity and address.
  • KingOfCoders 2 hours ago
    If people don't go to jail, there will be no change.
    • Gareth321 48 minutes ago
      The EU would rather destroy our right to privacy than hold criminals accountable. If I sound bitter it's because I have become very bitter over the last decade. The EU appears very effective at picking on individuals and people who can't fight back, and absolutely toothless when it comes to taking on more powerful interests. There are very few cases of the EU tangibly improving my life over the last decade, and countless examples of making it worse.
      • KingOfCoders 7 minutes ago
        "and absolutely toothless when it comes to taking on more powerful interests. "

        Like Google and Apple?

        "and countless examples of making it worse."

        Which would those be? I would be interested to know.

    • raxxorraxor 1 hour ago
      Problem is that the EU will even go further here and tries to implement that everyone is forced to id themselves despite the regular problems.
    • TacticalCoder 55 minutes ago
      > If people don't go to jail, there will be no change.

      The EU being the EU, it's those criticizing the leak by governments of public data that are going to be sent to jail.

      • KingOfCoders 6 minutes ago
        "it's those criticizing the leak by governments"

        If this is a general trend in the EU, what people went to jail for criticizing the leaks?

      • nhma 4 minutes ago
        Oh no, the evil EU police will throw us all in EU jails!
  • hoppp 42 minutes ago
    Probably everyone in Denmark got breached. That sucks but 2FA identity verification already exists to access personal info
  • cimi_ 1 hour ago
    Denmark's population is 6 million [0], where does the diff of 2.8M come from? :)

    [0] https://www.dst.dk/en/Statistik/emner/borgere/befolkning/bef...

  • eric4smith 50 minutes ago
    Wait... wait wait... I thought the EU "protection" laws was supposed to prevent all of this?
  • clan 3 hours ago
    CPR is the national register of all people (Central Person Register).

    CPR is the administrator. There is more information in the linked press release from the ministry:

    https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfatt...

    This is a huge headline story in Denmark today and I choose to link danish content as they are the primary source.

    The only current english language sources are paywalled:

    https://www.thelocal.dk/20261005/hackers-get-personal-info-o...

    https://www.bloomberg.com/news/articles/2026-10-05/denmark-d...

    Non-paywalled but major danish news outlet (National Brodcaster):

    https://www.dr.dk/nyheder/indland/live-uvedkommende-har-haft...

    • lode 2 hours ago
      Another non-paywalled English article from a Danish source: https://cphpost.dk/2026-10-05/life-in-denmark/cpr-data-breac...
    • WA 1 hour ago
      Will they be fined? (Probably not)

      Will Danes be compensated for the hassle, this causes them? (Probably not)

      Will Danes be hassled with GDPR-compliance in every business, school etc. even though the state can't keep records safe? (Probably yes)

  • goreyee 15 minutes ago
    Almost said the n-word reading that danish title...
  • drchaim 1 hour ago
    yeah, a this rate, we can assume all digital information will be public at some point.
    • chrisjj 12 minutes ago
      And unofficially - giving free rein to malicious misinformants everywhere.

      Not long now before people get extorted for correction of doctored leaked sensitive personal details.

  • hastily3114 2 hours ago
    As someone who works with CPR data in Denmark, this does not surprise me at all. Private companies access the data through an API, and anyone who works at such a company can look up CPR data as they please.
  • _s_a_m_ 11 minutes ago
    so more data breached than people live in Denmark..
  • ionwake 1 hour ago
    Just so everyone understands the numbers thats basically everyone in Denmark.
    • Ekaros 1 hour ago
      Everyone in Denmark dead or alive... I wonder how many years or decades it takes to clean up the dead from there.
      • ionwake 1 hour ago
        You are right lol, damn!
  • rimliu 1 hour ago
    And guess who are pushing for the Chat Control.
  • amelius 1 hour ago
    "Something is rotten in the state of Denmark"
  • nephihaha 1 hour ago
    Isn't that more than the current population of Denmark? Who were the other exposed people?
    • KingMob 1 hour ago
      Foreign residents and dead people, apparently.
  • LarsKrimi 2 hours ago
    Altman at it again?
  • rvz 2 hours ago
    Let me guess, the Danish government will find a way to prove that GDPR doesn't apply to them.

    But this is incredibly bad.

    • shiandow 2 hours ago
      It does apply but they were allowed to have this data and GDPR does very little to protect it in that case.
  • derin-picment 2 hours ago
    [flagged]
  • Wittie 1 hour ago
    [flagged]
  • alexx-devv 1 hour ago
    [dead]
  • aaron695 2 hours ago
    [dead]
  • mistermaster1 1 hour ago
    [dead]
  • johnwalker67 3 hours ago
    I am so done, my cpr is leaked oh no. Like I don't
    • clan 3 hours ago
      This is were security meets the real world. The number is not secret but people have been taught to keep it confidential. And when you know the last 4 digits social engineering har become a lot easier.
      • Ekaros 3 hours ago
        On positive side maybe now there is no reason to use it for authentication anymore. When it was always unsuitable for that reason.
        • clan 2 hours ago
          I used to agree.

          But since then I have experienced how scared mugglers get when they get a threatning mail with the only legitimacy of naming and old leaked password.

          This will be easy to exploit on a scale.

          Scammers used to prey on the weakest hence the many Nigerian Princes. But as they get more sophisticated and move up the chain they start to look more and more legitimate.

    • aDyslecticCrow 2 hours ago
      CPR isn't the problem, the rest of it is.
  • thiagoperes 2 hours ago
    it feels this will keep happening specifically to Europe for three reasons: a) most countries took an anti-AI approach b) they reject frontier models in favor or "Sovereign" solutions c) they're replacing software with weaker/more vulnerable options

    public servant engineers are token poor and will be out of the latest defense tools

    • Mashimo 2 hours ago
      I don't think this is AI related at all. What makes you say that?
      • chrisjj 10 minutes ago
        Scorned AIs taking revenge? :)
    • sunbum 20 minutes ago
      The data got leaked by a private company.