I don't think, for a vast majority of cases, these companies I'm forced to interact with can be trusted with my data and it's having a real world negative impact. Even with the best intentions the information is somehow valuable to steal and I'm baffled how it's not secure.
There should be some consequences for companies asking for things like SSN/National Insurance numbers on job adverts or retaining drivers licence photos after test driving a car, they just don't need the data anymore.
All my data is out there, one way or another, and a dedicated cybercriminal - or worse, a government entity - can obtain or exfiltrate it without issues. I know it, they know it, everyone knows it.
The only thing I can change now is my reaction to this fact, and although the idea of off grid autarky is tempting, I am not there yet. I just don't want to stop living - flying abroad, going to doctors - I just accept that privacy in the current state of human condition is impossible, and move on with my life.
This may apply to the consequences of ones data being subject to so many breaches and leaks and thefts, but it should not be the attitude one adopts towards the idea of ones data being taken and used by so many parties. At some level, my data is my personhood - it is my evidence of myself, and my record of myself, and my proof of myself. It encodes who I talk to, what I'm interested in, where I go, and what I do. My health, my finances, my habits, vices, schedule, family, friends, coworkers, beliefs. People more clever than myself use this data to advertise to me; people more powerful use this data to surveil me. When will people more malevolent use this data to persecute me?
I should not have to love the bomb because the bomb will kill me.
And most people on the behavioral side do too, but not at the cognitive level. EU is the best example with EU AI Act, strict data regulation as well as privacy rights, on the other hand demanding that Apple does serve the EU with AI.
I have mainly one distinction: the state is the worst protector of your data and the most ruthless gatherer of all your details.
Opposite to the open sourcing of your data in the end by the state are private companies who live by your data but do this for 20+ years - battle tested protection and hardening against malicious hackers.
Security is their business while security for the state is a cost factor.
Being at the mercy of some ignorant politician is not the best way to talk about data security.
Berlin, Denmark - those are the known one. And there are many more to come.
And regarding cognitive dissonance: politicians demanding high standards and punishing data loss ruthlessly on the one hand, giving oneself a pass on a hack is nothing to increase trust into the system.
X got fined for a missing blue mark. Berlin? Denmark? Others?
A second aspect is that the average guy doesn’t get that part of the whole spectrum must be the degooglers, the home server guys.
So it is relatively easy to get data on them as well just by filtering out the other data.
In other words: 95% not doing degoogling makes for a great small sample of 5%. Negating and interpolating other demographic and psychographic factors and you get a great way of gaining insights.
And remember: being the one who is not using google when being around other guys who do - magic.
So my idea is simple: what’s in it for me, and the state offers way lower value than Google and co.
Pick your fate.
How many state data breaches vs corporate data breaches? There are hundreds of state entities with my data (probably thousands), and yet private companies with my data have been hacked more times.
We need to stop using the same phone numbers and rotate them constantly. Ideally back to something like fi that masks your "real" isp account phone number. They need to stop being a 2fa and especially stop being able to identify a person. Or the 2fa needs to treat them as more temporary.
And now some banks are doing instant voice recognition. I don't pick up my phone for any number I don't know anymore.
There are situations in many a person's life that if revealed to the public would have life-altering consequences.
Rather than the world give up, we should have better tools and laws to flood the internet with spurious personal data.
For example, matrix sucks ass. It's terrible. Everything about it is a bad experience. Of course you'd want to eventually stop using it and go back to the previous life.
But that is not the correct take-away.
The correct take away is to include UX (and honesty to yourself about it) in the calculation and to not go all in on an unsustainable compromise, just to then snap back to doing the opposite ca 3 months later.
Same as with loosing weight, really. If you replace 100% of the pleasure of eating with the "right" but unpleasant solutions, you will not be able to keep that diet going indefinitely.
That's denying most culprits the opportunity to use the collected data against you.
Like always on VPN, turning off personalization, ad guards and using open source products where possible.
- Don't volunteer your intimate details left and right;
- Feel entitled to deny requests for unnecessary data (and advocate for such rights if you're in position to)
- Otherwise don't sweat it, because you can't actually control what others know about you, you never could
How are you jumping from Minecraft (probably one of the most watchtime-generating content types out there) being displayed on your main page to… your personal information being known to everyone?
intermediaries that will be compromised
Except that YouTube doesn't need any of that to recommend Minecraft videos to you. One mundane explanation that seems more likely is that it's the type of content that on average works best on people they don't yet have information on.
Reminds me a little of these "phones listen to everything we say, otherwise I wouldn't have been shown this ad" anecdotes that don't hold up against empiric evidence.
Doesn't that just make your browser very unique?
Did you play minecraft on the same network? If so, I'm not sure why the results are surprising or why it would negate all your efforts. If someone else played minecraft on your network you would also see a minecraft video on your main page I would imagine.
1. I don't want to love it. I hate it. You can learn to live with things you hate though, and not have it impact your day to day life or mental health though.
2. Its still a bomb. Until we find out how we can de-value the data, it will have an incentive to be stolen.
One thought here that I don't personally agree with, but might be important regardless:
Imagine a society without secrets or privacy at all for example.
I don't personally like the sounds of it, but it is sort of where we're headed at the moment, and if the fundamental reality is that obtaining data is much more easy than defending it, then perhaps we need to come to terms with a world without privacy, and how to create the best version of that unconstrained world.
Again, I don't like the sounds of this, but I'm curious to read more about it. Can someone give a philosophical pitch of why GDPR style regs on personal and company data are so important?
That depends. One thing is following precautions, another the Principles. Precautions may have a limit ("due diligence done, I'll stop there"), Principles do not.
Remember also that many phenomena occur because the individuals in the masses have not said "no". Acceptance enabled them. So the acceptance of some ill conceived systems is criminal - it is what lets them exist.
They happen all the time, nobody cares, criminals who want to target you will target you anyway, criminals who don't target don't care about you specifically, legitimate entities cannot use this data anyway, and legitimate scammers (marketing) will find different ways to get you to give them the data you need.
At this point I thing privacy obsession is modern copium, a way for people to deal with the fact that we're all individually a speck of dust on the face of human civilization. It's about asserting, "I am not an NPC, I have this richness of experience", and then trying to hide it all in case the world wants to check.
A relative killed herself after her therapist was hacked[1] and the data was leaked. If that is inconsequential, I do not know what isn't.
Good, you're not throwing out the baby with the bathwater. I don't get why you think throwing out the bathwater itself was wasted effort though.
The point is to get rid of things you can live without. If you're going to get rid of something but then spend every day thinking of its absence, then yes, that may be bridge too far. Otherwise, getting rid of it has some value.
I don't see the harm of asking, "Do I need this entity's services enough to justify forking over this data" for every entity that you interact with. Everyone draws their line in the sand at a different place. Data hygiene is a good phrase for that reason, everybody's acceptable level of hygiene (or lack thereof) is different.
You dont get it bro, its not a good vibe.
And if I had bean in management I would have fired anyone involved with that decision.
Why is it so often HN that I point something obvious out , like Rockstar having clearly failed management and a complete loss of control, but instead of agreement or silence I always get flak from some random user who just doesnt get it, and then a year later the company starts falling apart.
Im just a guy who recognises patterns and im not even smart.
So you knew that fierfox never came with google analytics but you decided to claim it anyway...
Because many "obvious" things are just plausibly sounding bullshit. For example:
> Rockstar having clearly failed management and a complete loss of control
That's both very broad and generic, and completely unfalsifiable, and comes with nothing backing it up. It's just an unsubstantiated opinion. These things are fine when drinking in friends, or otherwise socializing by bonding over ramblings.
If you want to convince someone of something, the standards of evidence (not to mention, clarity of thinking) are a bit higher.
This site will start falling apart if we don't keep things civil.
Oh, I love the bit where a programmer always proudly chimes in with this statement as if it means anything.
I get wanting to be conspiratorial, but its not cool to go after others that challenge your conspiracy, even if its "obvious"
And then add on that fact that my doctor recently started using some kind of AI voice transcription app that listened to our entire conversation. Except that it hallucinated details I absolutely did not say, which are now in that doctor's records and I'm sure will be taken at face value in the future.
It's maddening.
Sending my file over to lawyers in a semi-safe way has proved impossible.
And in any case, i received an answer with lots of PI over a plain email…
Absolutely maddening
I know it’s modern American tech tradition to make fun of the GDPR, but this is genuinely one of the things it stipulates: You’ll get at least a slap on the wrist, or potentially much worse, if you needlessly keep data around longer than necessary to do the task you had collected it for in the first place.
In the US, you can freeze your credit, making this impossible (even for yourself).
Let me say "Hi mate, +1". State doctors? There are territories in which a pharmacological prescription is shared DB only now (where previously they could be on paper - a secret between you, the pen, the paper, the pharmacist and the gods). Private entities? Good luck finding one that does not require a privacy waiver as a condition for the visit. Searching for a medical dock (a dock for a doc), calling them to ask? "This is a recorded message. If you proceed with the call then you agree..." (Hang-up click).
Excuse me?
If you weren't paying with cash whoever paid for the prescription (govt, insurance) has a record of it. The pharmacy that filled the prescription has a record of it as well as the doctor who wrote it.
How can you presume we do not pay with cash?! How can you remotely suppose one sane mind would not use cash for all sensitive private transactions - books, medicines, preferential (profiling) products etc.?
We use cash in general because nobody in Dignity would accept their own daily matters to be recorded and given to multiple untrusted parties¹, not to mention potentially retrievable by even more untrusted parties - of course the matter is much more evident for all transactions over confidential items!
(¹EU here: 12 public-hybrid-private DBs as per the PSD2 legislation.)
Thats the wording of GDPR.. that you should delete data after you dont need it anymore for the original purpose..
Unfortunately, it seems noone is enforcing it enough.
> things that are out of your control
That's because of corruption. A system that doesn't want to change because some tits can't be let go of. A well working system would render control back to you.
But nobody really cares enough to spend money modernising this sort of system.
I'm only half joking: I used to work in payments, hotels didn't care about PCI. Full card numbers stored everywhere.
Are you 'avin a laugh mate?
A photocopy of my passport is going nowhere and is shreadded afterwards. An electronic copy..... God lord.
The GDPR also requires data deletion once you no longer need it; physical as well as electronic. This is common sense, and why some organisations don't do this is simply mind boglling.
If you think photocopies kept in some folder accessible to anyone working in the hotel, with a promise to delete it at some point, is "secure" in any way, I don't know what to tell you.
Rather a paper data breach exposed to a few hotel employees than eletronic data exposed to the entire planet!
This said, the police already has a database with these info, and it likely is somehow already on the network, so adding an api (if done properly) would not dramatically alter the exposure profile.
I was asked for my passport in a Premier Inn this summer because they thought I was a foreigner but when I pointed out that I was a UK citizen they dropped the requirement.
In Europe it was mostly Italy and Poland that wanted to see my passport.
Why can’t WE spy on them 24/7?
I am writing this because I don't think democracy works as advertised.
That's the world we live in.
"Police and thieves", collaborating one way or another (leaking data collected by big brother and then having big brother being very soft on crime is one way to collaborate with evil people), "to scare the nation with their guns and ammunition" (as in the reggae song).
As much as I don't like the cryptocurrency ecosystem, I don't think facilitating and encouraging kidnapping and torture is the way to go.
Shame on the french government.
Two sides of the same coin.
The cryptocurrency ecosystem is used to not only avoid taxation but to enable criminal activity. How many people are being held hostage and the ransom will be payed thanks to cryptocurrencies?
I do not like the cryptocurrency ecosystem either. And I totally agree that it should be abolished. It is just a way to finance crime and terrorism.
Our civilisation needs to face up to the fact the reason is simply: its stored on a connected computer.
I’ve switched to operate with the idea that my information has already been leaked at some point. I should be generally ready to fix the problems if/when identity theft happens, rather than inconveniencing myself and figuring out the third party trust situation.
In this case, the EU does have consequences for data breaches where proper protocols are not followed.
Additionally, this is not private information .. most anyone can look this information up. ID numbers are not confidential information like SSNs are treated in the US.. they are just a number to tell person A from person B. You give this number to everyone without thinking about it because it's how every company you interact with identifies you.
In this case a rogue company, or compromised company, used their access to contact the central database to download everyone's information.
In my country we essentially use the same system, except for we still allow companies to download the whole database if they want to instead of making individual queries.
In this case the access to their system was unauthorized, and under GDPR data breaches have to be reported within 72 hours. Companies can't make the decision on their own that it's not a big deal.
Abusing privacy is the lucrative norm. The laws won't help you and the government is busy with its corporate agenda.
It's quite convenient, when you meet a new friend, to go and check what neighbourhood they're from, who do they live with and where they lived before.
What's the big deal, Danes? What do you have to hide?
(The provocative tone is intentional as a joke, I'm not even a Swede, I just find the brotherly rivalry between Scandinavians amusing.)
And since everyone's name, address and phone number was in the phone book (At least for their city) people didn't find it weird when it popped up online. Sure, to do the same thing for the whole country you'd need dozens of phonebooks for different areas, but it was just the same information.
Which makes me wonder: weren't there phonebooks in US cities and in other countries before? Were they incomplete/opt-in?
The key thing about the Swedish phonebooks were that they were opt-out, so people were basically all in the phone book. So even before the internet, it was just very natural that your name, address and phone number was public. "Getting someone's number" as in moves and TV wasn't a thing. You could just call anyone if you knew their name.
Not that any other country does much better in this regard. Still it sounds a little wild to me that you can get this information without even needing to hit a shady forum and download some csv. Maybe lowers the bar too much.
The owner just thanked me, and said was going to have a chat with the driver. Never saw that car speeding nearby again.
The debt information is there so that when the owner sells the car the buyer can check to see if they actually really do own it outright.
Especially great that you can see what employees at competitors earn, what your peers at your workplace earn and what your boss earns. Become a hell of lot easier to ensure you're not exploited. Helps that Sweden has a really strong union-culture as well.
In a high trust culture I get this. But what about if you're in a low trust culture with quite some "not so orderly behavior" (if you will).
The current system has been in place around 1770. There's some pushback against it the last few years.
Of course, contrary to popular belief, Sweden is not a perfect country without violence and shit people!
It seems to be somewhat respected overall though, but I'm sure it'll eventually disappear. For the people who are stalked and what not, it's relatively easy to apply and get "protected identity" if you're affected by those things, and then eventually all those 3rd party websites remove the stale data.
Personally I solved this problem for myself by moving away from the country.
Quite drastic to move away from a country for just this. Did you only do it for just this? Or was this simply one of the factors why you moved away?
Overall the benefits for employees seems way broader than the benefits for the companies.
The problem with this leak mostly going to be those with hidden addresses or secret phone numbers. Last time something similar happened was when it was shown that you could pretty much just guess a persons social CPR number if you had their birthday. Normally you could narrow it down to 6 or 8 possible numbers then use the phone companies websites, pretend to create a new account, enter the CPR number and check if you guessed correctly. Because the demo was done with politicians, then phone companies no longer ask for CPR upfront.
I feel like this should be the default. Responsible disclosure to the affected company, followed immediately by disclosure to every politician in the dataset. Once we start collecting high profile cases this way instead of waiting X days for a faceless corporation to release a fix, companies will think twice about their security and the data they collect if that could make them end up on the shit list of the local government.
The review conducted shows that the unauthorized access does not include the names and addresses of individuals who have chosen to register with name and address protection.
From the sourceNot trying to downplay the situation, but I hope this will be eye opening to the responsible people.
Don't hold your breath.
- Social security number
- Age
- Sex
- Family relations
- Physical address
- Protected addresses
- Sex change
This is a country with quite good health records. Unfortunately also previous problems with proper non-reversible anonymisation of said data when used for research.
AFAIK those with protected addresses has not had their address compromised. But ID and name still is.
And with the rest exposed it is now trivial to see what adresses are "interesting".
I did it accidentally during my last move and it was a pain in the behind
And it expires after a year by default so it feels rather pointless
I managed to get protected address, it's just to log in somewhere and request it. I can't remember the details, but it made for example banking _slightly_ more annoying. They would call me so they can send me a letter. Also makes it harder for people who know your name to look up your address.
Never managed to get my name removed from my domain whois and at some point removed protected address again. In theory, if I share one of my other .com domains on the internet, an attacker could reverse DNS the IP, find my DK domain and thus get my full name and address.
There are exceptions where the encoded birth date will be wrong (like immigrants with unknown birth dates) or dates where there are more people than the 4 digits that encode checksum validation and gender can handle.
Then again, in my country some municipalities handed out numbers starting with your birth year....
Gender is encoded in the CPR number.
There is some interesting details that may require you to change your name, if you want the last digit changed. That means if you're name is Kurt, you can't have a CPR number ending in an even number, because Kurt is only an approved name for men. If your name is Kim, Storm, Charlie, Orla, Lykke or some other unisex name it's not a problem.
Compare this to the ministry of transportation, which has full resources. This is despite the fact that most people in this country spend less time commuting than they do working on a computer. Not that transportation isn't important, but maybe digitalisation is as well?
My personal CPR has been leaked a couple of times though. Hilariously the first time it was leaked when a couple of unencrypted laptops were stolen from the biggest IT union in the country. We have a system in place where you can flag your CPR as having been leaked. Though I suppose now we might as well consider every one of them to be leaked. In theory a CPR on it's own was never meant to give any sort of authority or access, but again, this wasn't the practice in a lot of place. So I guess this leak may be a blessing in disguise in that sense as well, as it'll highten security because of broken trust.
I think I get what you are trying to say, but just for other people reading this: Denmark is one of the "best" / advanced countries when it comes to IT and digitalisation in public sector in Europe.
That being said it's not like us being shit at cyber security doesn't mean other countries aren't also shit. Look at Australia getting hacked by AI. I know it's all the rage to blame OpenAI, but really, shouldn't Australia count itself fortunate it wasn't an enemy nation state? Or that their lacking security got exposed before it was.
As far as Randers cyber security goes. I imagine it'd be "fun" to do an right of access to documents, on the amount of unique visits their Microsoft Defender has registered to chatgpt.com and claude.ai.
There are things I wish I could change in Denmark, mainly the power sockets and number system (Base 20 what the heck?) but Denmark is on a good course when it comes to IT understanding. Both the broader society and government implementations.
Yes yes, Estonia is better. But Denmark is still doing good.
As all security professionals know, people dont care about security, until they are hurt, and often even after that. Lost privacy doesnt hurt if you dont think too much about it.
What we are also seeing is that governments/administrations dont care about security (with exceptions). They really want to go ahead in the digitalization dimension, but not so much in the security dimension.
Feel. Having lived in Denmark and Germany. And working for the public sector.
MitID is just chefs kiss how many other countries can you log in to your bank, student loan, and local municipality with the same sso. Country wide app for local transportation tickets of different types. EPJ / Elektronisk Patient Journal has it's fault, but compared to other countries[2] yet again not that bad.
Shit man, even something simple has going to the doctor for blood tests. I think you can get the results on the same day via app. Maybe next day. In Germany[1] you have to wait a few days, then the Dr. calls you with the results and then you can ask him if he can mail it to you.
What in Denmark actually requires you to get physically to the municipality? Weddings? Even divorces work online. Compare that to Germany, Austria, Italy etc.
Why do you think Denmark is not one of the leading countries in digitalization?
[1] Probably dependens on location / Bundesland.
[2] https://de.wikipedia.org/wiki/Elektronische_Patientenakte_(Deutschland)
Edit: Just looked at some real benchmarks. One from EU where they put DK at 7th out of EU27 https://composite-indicators.jrc.ec.europa.eu/explorer/indic...
And one UN E-Government Survey from 2024 where they rank first. https://publicadministration.un.org/egovkb/en-us/Reports/UN-... (I just looked at an overview)I can't say how accurate these lists are. But they match my observations. Nordics lead.
That said, compared to other countries the tax / SKAT is also quite decent.
We'll have to start treating the CPR number as just a username, instead of a password. It should never have been "secret" in the first place.
Any agree, it should be only a username and MitID is the verifier(password) and without both, it should simply be impossible to create any kind of binding contracts like loans etc. anything else is simply sloppy policy from the government. but again no politician understands IT, neither does the majority in EU about the implications of chat control...
It will take a whole new approach to confidential information to really make a difference. I think we need to go the SSI way, and I think at some point we will.
But inside that network the security was a joke. Basically developers used real non anonymised archival data uploaded to s3 all devs had access to, to test the software. Data containing all the private stuff mentioned.
Absolute peak of incompetence. It wouldn't be hard to anonymised the data even just by hashing the names and certain other records or replace them with dummy data.
But what annoyed me the most is there is no info about huge fine for the company. No article written by the company explaining what internal failures they will fix to prevent it happening in future.
Nothing.
Those things have to be prosecuted and punished. Otherwise no one has any incentive to keep the systems secure.
[1] https://www.dtu.dk/english/newsarchive/2026/10/cyberattack-o...
So essentially the whole population's data has leaked. Furthermore, the notice says mv, which is abbreviation for etc. So it says "name, address, cvr number" etc.
That etc. is funny because the Danish government has a thing called NemID which you use to log into pretty much any online service, including banking, and you can install it on your phone, and when you lose it though you can verify by calling up and giving personal information to verify it is you.
Now there are a bunch of things about this system that are contemptibly stupid and annoying that I won't go into here because of my blood pressure. But now I wonder if the mv. of the personal data covers stuff you could conceivably be using to get a new NemID.
on edit: the really young have not had their data leaked, probably, and the excess of course covers people who used to live in Denmark and left.
Companies are opting for higher profits by not investing in securing private data entrusted to them. We need to make the balance tip the other way.
As long as there aren't any financial or criminal penalties companies will not care about data being pilfered.
I wonder if company used some kind of automation that decided it needs all CPRs for whatever it was doing.
- in Poland (from private medical companies used by doctors) with estimated 20M affected people (half of population)
- in France (from tax office), 678k people affected
With AI getting more capable, and with Russia escalating things, I unfortunately expect more to come.
https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...
I do not think we will ever go back to the wild west, but it is also hard to think a future that follows this very tendency.
Before we had natural disasters to worry about and now we have those + cyber ones.
Like Google and Apple?
"and countless examples of making it worse."
Which would those be? I would be interested to know.
Yes, like Google and Apple. If you would take a look at my submission history, you'll see exactly one. It was me celebrating the passing of the Digital Markets Act more than four years ago. This Act clearly lays out requirements for gatekeepers like Apple. I summarise these requirements in a comment in the submission:
* Install any software
* Install any App Store and choose to make it default
* Use third party payment providers and choose to make them default
* Use any voice assistant and choose to make it default
* User any browser and browser engine and choose to make it default
* Use any messaging app and choose to make it default
* Make core messaging functionality interoperable. They lay out concrete examples like file transfer
* Use existing hardware and software features without competitive prejudice. E.g. NFC
* Not preference their services. This includes CTAs in settings to encourage users to subscribe to Gatekeeper services, and ranking their own services above others in selection and advertising portals
To date, Apple has implemented only a handful of these, and they have done so with malicious intent. For example, they have made the creation and distribution of third party app stores to onerous that very few companies have navigated the gauntlet and actually used it. Third party browser engines are now technically supported, but so poorly that not even Google has endeavoured to create an iOS browser engine. The worst example is app distribution. The DMA requires gatekeepers to facilitate free distribution. Apple has failed to cmoply with this for four years, and has repeatedly appealed when admonished. The Commission has been sitting on their most recent "review" for over a year now, without any updates.
The net result of all of this is that Apple has retained almost all of their duopolistic market power, and has implemented almost none of the DMA requirements. They have given us the middle finger and our legislators have gone to sleep.
> Which would those be? I would be interested to know.
I'll give you me perspective as a Danish citizen.
The EU imposed working-time recording requirements, so now I have to log my working hours every week. I'm a full time employee and I work longer and shorter weeks. Now I have to waste time each week logging my hours. My company has to waste time each week logging hours and reporting them to the government and the EU.
The EU required bottle caps to remain attached to most plastic drinks containers, so now I have to wrestle with an attached cap every time I drink from one.
The EU banned ordinary disposable plastic cutlery, plates and straws, removing products I previously had the choice to buy.
The EU introduced rules requiring consent for many non-essential cookies, helping turn everyday web browsing into an endless series of cookie banners.
The EU introduced "Strong Customer Authentication" requirements, so routine online payments and banking increasingly require additional authentication steps.
The EU abolished the €22 VAT exemption on low-value imports, making even tiny purchases from outside the EU subject to VAT. This one in particular sucks because the company or local tax authorities impose huge minimum fees, making small cross-border purchases far too expensive now.
The EU imposed expanded producer-responsibility rules on packaging, adding recycling fees, reporting requirements and compliance costs that ultimately feed into the prices I pay.
The EU passed even more extensive packaging regulations covering recyclability, recycled content, packaging minimisation and reuse, adding another layer of costs and restrictions to ordinary products.
The EU imposed increasingly strict CO2 targets on car manufacturers, financially penalising manufacturers whose fleets exceed them and increasing the pressure to make petrol and diesel cars more expensive or stop selling them.
The EU created ETS2, which from 2028 will add a carbon price to road fuels and home heating, creating another cost that fuel and energy suppliers can pass on to me.
The EU imposed sustainable aviation fuel mandates and tighter carbon rules on airlines, increasing the regulatory cost of flying.
The EU brought shipping into its carbon-pricing system and introduced FuelEU Maritime, leading shipping companies to add explicit EU environmental surcharges that feed into the cost of goods I buy.
The EU imposed Ecodesign restrictions on appliances, including maximum power limits for products such as vacuum cleaners, reducing the range of products I am allowed to buy.
The EU passed a minimum-wage directive despite Denmark already having its own collective-bargaining model, forcing Denmark to fight the EU in court to protect a labour-market system that was already working without a statutory minimum wage.
The EU being the EU, it's those criticizing the leak by governments of public data that are going to be sent to jail.
If this is a general trend in the EU, what people went to jail for criticizing the leaks?
CPR is the administrator. There is more information in the linked press release from the ministry:
https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfatt...
This is a huge headline story in Denmark today and I choose to link danish content as they are the primary source.
The only current english language sources are paywalled:
https://www.thelocal.dk/20261005/hackers-get-personal-info-o...
https://www.bloomberg.com/news/articles/2026-10-05/denmark-d...
Non-paywalled but major danish news outlet (National Brodcaster):
https://www.dr.dk/nyheder/indland/live-uvedkommende-har-haft...
Will Danes be compensated for the hassle, this causes them? (Probably not)
Will Danes be hassled with GDPR-compliance in every business, school etc. even though the state can't keep records safe? (Probably yes)
[0] https://www.dst.dk/en/Statistik/emner/borgere/befolkning/bef...
[0] https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfatt...
https://cphpost.dk/2026-10-05/life-in-denmark/cpr-data-breac...
Basically any company can access to an API that lets you look up CPR(~SSN) numbers, and a lot of companies have access.
What has most likely happened is such an integration has been abused - we do not yet know whether it's by mistake or by some malicious third party. It wouldn't surprise me in the slightest if this is just the result of someone's Claude agent telling them that they can improve lookup times if they just enumerate every CPR number and cache them, for example - but we don't know yet.
The 2FA verification system in place now has not had any reported breaches but is nevertheless an absolute joke. I use GrapheneOS on my personal phone which cannot use the government 2FA due to the arbitrary Android integrity API. I therefore use my old phone on which it works perfectly. The catch is that it hasn't been updated in over three years lol.
When the ministry responsible for the 2FA system was asked to allow it to be run on degoogled OSes, they refused saying it would be too costly to develop for "other systems". The responsible authority doesn't even know degoogled Android is still Android. And you expect these people to protect your private information and health records.
It was also leaked some time back that the Danish government let the NSA spy on every citizen in the country for literally nothing in return. Unconstitutional? Yes.
Yeah, it's probably easy to bypass too, if they are not actively maintaining it there are definitely holes in the system.
I think bad and expensive government software systems are a global norm, still the Danish system is more private than the Swedish where all it takes is a name and everyone's home address can be searched for.
It really is a nothing burger this data has been leak multiple times, and is easy for any bad actor to get their hands on at any time should they need to.
But since then I have experienced how scared mugglers get when they get a threatning mail with the only legitimacy of naming and old leaked password.
This will be easy to exploit on a scale.
Scammers used to prey on the weakest hence the many Nigerian Princes. But as they get more sophisticated and move up the chain they start to look more and more legitimate.
public servant engineers are token poor and will be out of the latest defense tools