← NMBS

2018 — NMBS: Data stored on a non-secure server, making it…

2018 1.5M records affected Share on X

Technical writeup

Dec 2018. Data stored on a non-secure server, making it possible to access names, gender, DOB, email and postal address data of customers externally by means of a simple search engine query. Most of the data belong to customers in Belgium, France and the UK, including thousands of Commission and Parliament employees. Caused, the NMBS said, by a data worker “clicking on the wrong button”.

Root cause

Accidentally published

References