public servant engineers are token poor and will be out of the latest defense tools
I don't think, for a vast majority of cases, these companies I'm forced to interact with can be trusted with my data and it's having a real world negative impact. Even with the best intentions the information is somehow valuable to steal and I'm baffled how it's not secure.
There should be some consequences for companies asking for things like SSN/National Insurance numbers on job adverts or retaining drivers licence photos after test driving a car, they just don't need the data anymore.
All my data is out there, one way or another, and a dedicated cybercriminal - or worse, a government entity - can obtain or exfiltrate it without issues. I know it, they know it, everyone knows it.
The only thing I can change now is my reaction to this fact, and although the idea of off grid autarky is tempting, I am not there yet. I just don't want to stop living - flying abroad, going to doctors - I just accept that privacy in the current state of human condition is impossible, and move on with my life.
This may apply to the consequences of ones data being subject to so many breaches and leaks and thefts, but it should not be the attitude one adopts towards the idea of ones data being taken and used by so many parties. At some level, my data is my personhood - it is my evidence of myself, and my record of myself, and my proof of myself. It encodes who I talk to, what I'm interested in, where I go, and what I do. My health, my finances, my habits, vices, schedule, family, friends, coworkers, beliefs. People more clever than myself use this data to advertise to me; people more powerful use this data to surveil me. When will people more malevolent use this data to persecute me?
I should not have to love the bomb because the bomb will kill me.
That's denying most culprits the opportunity to use the collected data against you.
Like always on VPN, turning off personalization, ad guards and using open source products where possible.
They happen all the time, nobody cares, criminals who want to target you will target you anyway, criminals who don't target don't care about you specifically, legitimate entities cannot use this data anyway, and legitimate scammers (marketing) will find different ways to get you to give them the data you need.
At this point I thing privacy obsession is modern copium, a way for people to deal with the fact that we're all individually a speck of dust on the face of human civilization. It's about asserting, "I am not an NPC, I have this richness of experience", and then trying to hide it all in case the world wants to check.
Sending my file over to lawyers in a semi-safe way has proved impossible.
And in any case, i received an answer with lots of PI over a plain email…
Absolutely maddening
That's the world we live in.
"Police and thieves", collaborating one way or another (leaking data collected by big brother and then having big brother being very soft on crime is one way to collaborate with evil people), "to scare the nation with their guns and ammunition" (as in the reggae song).
As much as I don't like the cryptocurrency ecosystem, I don't think facilitating and encouraging kidnapping and torture is the way to go.
Shame on the french government.
Two sides of the same coin.
I know it’s modern American tech tradition to make fun of the GDPR, but this is genuinely one of the things it stipulates: You’ll get at least a slap on the wrist, or potentially much worse, if you needlessly keep data around longer than necessary to do the task you had collected it for in the first place.
I’ve switched to operate with the idea that my information has already been leaked at some point. I should be generally ready to fix the problems if/when identity theft happens, rather than inconveniencing myself and figuring out the third party trust situation.
Abusing privacy is the lucrative norm. The laws won't help you and the government is busy with its corporate agenda.
Let me say "Hi mate, +1". State doctors? There are territories in which a pharmacological prescription is shared DB only now (where previously they could be on paper - a secret between you, the pen, the paper, the pharmacist and the gods). Private entities? Good luck finding one that does not require a privacy waiver as a condition for the visit. Searching for a medical dock (a dock for a doc), calling them to ask? "This is a recorded message. If you proceed with the call then you agree..." (Hang-up click).
Why can’t WE spy on them 24/7?
In this case, the EU does have consequences for data breaches where proper protocols are not followed.
Additionally, this is not private information .. most anyone can look this information up. ID numbers are not confidential information like SSNs are treated in the US.. they are just a number to tell person A from person B. You give this number to everyone without thinking about it because it's how every company you interact with identifies you.
In this case a rogue company, or compromised company, used their access to contact the central database to download everyone's information.
In my country we essentially use the same system, except for we still allow companies to download the whole database if they want to instead of making individual queries.
In this case the access to their system was unauthorized, and under GDPR data breaches have to be reported within 72 hours. Companies can't make the decision on their own that it's not a big deal.
It's quite convenient, when you meet a new friend, to go and check what neighbourhood they're from, who do they live with and where they lived before.
What's the big deal, Danes? What do you have to hide?
(The provocative tone is intentional as a joke, I'm not even a Swede, I just find the brotherly rivalry between Scandinavians amusing.)
- Social security number
- Age
- Sex
- Family relations
- Physical address
- Protected addresses
- Sex change
This is a country with quite good health records. Unfortunately also previous problems with proper non-reversible anonymisation of said data when used for research.
Additionally it was via third party access granted to private companies.
https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfatt...
There are exceptions where the encoded birth date will be wrong (like immigrants with unknown birth dates) or dates where there are more people than the 4 digits that encode checksum validation and gender can handle.
Not trying to downplay the situation, but I hope this will be eye opening to the responsible people.
Compare this to the ministry of transportation, which has full resources. This is despite the fact that most people in this country spend less time commuting than they do working on a computer. Not that transportation isn't important, but maybe digitalisation is as well?
My personal CPR has been leaked a couple of times though. Hilariously the first time it was leaked when a couple of unencrypted laptops were stolen from the biggest IT union in the country. We have a system in place where you can flag your CPR as having been leaked. Though I suppose now we might as well consider every one of them to be leaked. In theory a CPR on it's own was never meant to give any sort of authority or access, but again, this wasn't the practice in a lot of place. So I guess this leak may be a blessing in disguise in that sense as well, as it'll highten security because of broken trust.
I think I get what you are trying to say, but just for other people reading this: Denmark is one of the "best" / advanced countries when it comes to IT and digitalisation in public sector in Europe.
That being said it's not like us being shit at cyber security doesn't mean other countries aren't also shit. Look at Australia getting hacked by AI. I know it's all the rage to blame OpenAI, but really, shouldn't Australia count itself fortunate it wasn't an enemy nation state? Or that their lacking security got exposed before it was.
- in Poland (from private medical companies used by doctors) with estimated 20M affected people (half of population)
- in France (from tax office), 678k people affected
With AI getting more capable, and with Russia escalating things, I unfortunately expect more to come.
[0] https://www.dst.dk/en/Statistik/emner/borgere/befolkning/bef...
[0] https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfatt...
CPR is the administrator. There is more information in the linked press release from the ministry:
https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfatt...
This is a huge headline story in Denmark today and I choose to link danish content as they are the primary source.
The only current english language sources are paywalled:
https://www.thelocal.dk/20261005/hackers-get-personal-info-o...
https://www.bloomberg.com/news/articles/2026-10-05/denmark-d...
Non-paywalled but major danish news outlet (National Brodcaster):
https://www.dr.dk/nyheder/indland/live-uvedkommende-har-haft...
Will Danes be compensated for the hassle, this causes them? (Probably not)
Will Danes be hassled with GDPR-compliance in every business, school etc. even though the state can't keep records safe? (Probably yes)
But this is incredibly bad.
Not that any other country does much better in this regard. Still it sounds a little wild to me that you can get this information without even needing to hit a shady forum and download some csv. Maybe lowers the bar too much.
The current system has been in place around 1770. There's some pushback against it the last few years.
The problem with this leak mostly going to be those with hidden addresses or secret phone numbers. Last time something similar happened was when it was shown that you could pretty much just guess a persons social CPR number if you had their birthday. Normally you could narrow it down to 6 or 8 possible numbers then use the phone companies websites, pretend to create a new account, enter the CPR number and check if you guessed correctly. Because the demo was done with politicians, then phone companies no longer ask for CPR upfront.
The review conducted shows that the unauthorized access does not include the names and addresses of individuals who have chosen to register with name and address protection.
From the sourceI feel like this should be the default. Responsible disclosure to the affected company, followed immediately by disclosure to every politician in the dataset. Once we start collecting high profile cases this way instead of waiting X days for a faceless corporation to release a fix, companies will think twice about their security and the data they collect if that could make them end up on the shit list of the local government.
- Don't volunteer your intimate details left and right;
- Feel entitled to deny requests for unnecessary data (and advocate for such rights if you're in position to)
- Otherwise don't sweat it, because you can't actually control what others know about you, you never could
How are you jumping from Minecraft (probably one of the most watchtime-generating content types out there) being displayed on your main page to… your personal information being known to everyone?
I did it accidentally during my last move and it was a pain in the behind
And it expires after a year by default so it feels rather pointless
I managed to get protected address, it's just to log in somewhere and request it. I can't remember the details, but it made for example banking _slightly_ more annoying. They would call me so they can send me a letter. Also makes it harder for people who know your name to look up your address.
Never managed to get my name removed from my domain whois and at some point removed protected address again. In theory, if I share one of my other .com domains on the internet, an attacker could reverse DNS the IP, find my DK domain and thus get my full name and address.
But since then I have experienced how scared mugglers get when they get a threatning mail with the only legitimacy of naming and old leaked password.
This will be easy to exploit on a scale.
Scammers used to prey on the weakest hence the many Nigerian Princes. But as they get more sophisticated and move up the chain they start to look more and more legitimate.
I am writing this because I don't think democracy works as advertised.
A relative killed herself after her therapist was hacked[1] and the data was leaked. If that is inconsequential, I do not know what isn't.
You dont get it bro, its not a good vibe.
And if I had bean in management I would have fired anyone involved with that decision.
Why is it so often HN that I point something obvious out , like Rockstar having clearly failed management and a complete loss of control, but instead of agreement or silence I always get flak from some random user who just doesnt get it, and then a year later the company starts falling apart.
Im just a guy who recognises patterns and im not even smart.
So you knew that fierfox never came with google analytics but you decided to claim it anyway...
This site will start falling apart if we don't keep things civil.
Because many "obvious" things are just plausibly sounding bullshit. For example:
> Rockstar having clearly failed management and a complete loss of control
That's both very broad and generic, and completely unfalsifiable, and comes with nothing backing it up. It's just an unsubstantiated opinion. These things are fine when drinking in friends, or otherwise socializing by bonding over ramblings.
If you want to convince someone of something, the standards of evidence (not to mention, clarity of thinking) are a bit higher.
But nobody really cares enough to spend money modernising this sort of system.
I'm only half joking: I used to work in payments, hotels didn't care about PCI. Full card numbers stored everywhere.
Are you 'avin a laugh mate?
A photocopy of my passport is going nowhere and is shreadded afterwards. An electronic copy..... God lord.
The GDPR also requires data deletion once you no longer need it; physical as well as electronic. This is common sense, and why some organisations don't do this is simply mind boglling.
If you think photocopies kept in some folder accessible to anyone working in the hotel, with a promise to delete it at some point, is "secure" in any way, I don't know what to tell you.
This said, the police already has a database with these info, and it likely is somehow already on the network, so adding an api (if done properly) would not dramatically alter the exposure profile.