8 ms·
Five million Danish ID numbers sent to Chinese firm by mistake
- runesoerensen 10y agoThis is ridiculous. It's not just Danish personal identification numbers, but ID numbers and health records for everyone who have lived in Denmark from 2010 through 2012. Quick recap since it's in Danish: A danish health authority, SSI, accidentally mailed two CDs containing unencrypted CPR-numbers and health records for 5.28m residents to the Chinese Visa Application Office. The Chinese delivered the letter to the intended recipient, Statistics Denmark, another danish government authority. The bubble cushioned mailer containing the CDs had been opened, but regardless the issue of course is the extremely reckless handling of very sensitive information. Edit: Article reporting on this in English http://www.thelocal.dk/20160720/five-million-danish-id-numbers-sent-to-chinese-firm-by-mistake http://www.thelocal.dk/20160720/five-million-danish-id-numbe... Edit 2: The specification and structure of the data that was sent with these CDs. https://twitter.com/christianpanton/status/755742230044966912 https://twitter.com/christianpanton/status/75574223004496691... (also in Danish, but this seems to include almost everything; the carelessness in handling this data appears to have been surpassed only by the extent and completeness of it)
- tixzdk 10y agoAnd the letter, which was sent as priority mail, had been opened when they went to retrieve it...
- hooph00p 10y agoNow they must assume that information is compromised and take action.
- danielweber 10y agoWhich is what? Give every Dane a new health record?
- OJFord 10y agoI read that to mean _legal_ action. IANAL, and can't profess to any knowledge whatsoever of Danish law, but opening a package clearly addressed to someone else without permission may be reasonable grounds for litigation. Though to the question "what good will that do", you're right, it's not like new health records can be issued. Depending on the details of what was shared and what ties them to an individual though, I suppose it might be possible to issue new IDs.
- erk__ 10y agoThey wrote that they do not belive that there was a compromise of the data.
- danieldk 10y agoSo? An unencrypted CD was accessible for a time period to a third party. It's good security practice to consider the data to be compromised. Especially a powerful, malicious actor will put in effort to make it appear that this is not the case. If anything, this requires a severe audit of the security practices of the affected organisations. Moreover, I think citizens of Denmark are entitled to know what information about their personal health records is leaked.
- Svip 10y agoCorrection: SSI sent a letter containing two unencrypted CDs containing CPR-numbers and health records for 5.28 residents in Danish municipals between 2010 and 2012 to the Danish statistics agency (Statistics Denmark). Post Danmark (postal service) accidentally delivered the letter to Chinese Visa Application Centre instead. When the employee responsible for receiving the letter noticed the mistake upon opening, the employee turned the letter with the two CDs to Statistics Denmark. According to the employee's story, this was done immediately. And the investigation team says they have no reason to doubt the validity of her story. To sum up: The investigation team believe that the Chinese Visa Application Centre never actually saw the contents on the CDs. SSI sent the data unencrypted, and the postal service delivered the letter to the wrong recipient. Edit: Changed wording from blaming the postal service.
- throwanem 10y agoHow long does a modern machine need to copy off the contents of a couple of CDs? Were the discs in tamper-evident packages?
- Svip 10y agoNo long, I'd imagine. But again there is little to no way to figure out for sure whether the Chinese government has this information. The story really highlights the careless handling of data, because the chances of the Chinese government (or any other third part) getting access to these data is way too high.
- pilif 10y ago> But again there is little to no way to figure out for sure whether the Chinese government has this information assume they have it.
- seszett 10y agoLet's assume they have it. What kind of interest would you say the Chinese government has in the health records of a few million Danish residents? I don't know, maybe it's really important, but then maybe it's not that critical after all.
- silvestrov 10y ago> 5.28m residents Denmark has a population of 5.7m residents, so this is almost all Danes.
- Freak_NL 10y agoThis happens more than you think, although not usually at this scale and this high up in the chain. When a care institution needs to communicate with one of their vendors handling health records about a problem with a specific person's record, most IT-workers at those institutions tend to just mail all details they feel are relevant to the issue without even considering encryption or the necessity of sending all that data over the wire. The use of physical post here was probably a good thing all things considered! They could just as easy have used WeTransfer or some other cloud solution — when it comes to security best practices people are very good at downplaying the potential risk, even when legislation does acknowledge it and forbids such treatment of sensitive personal information.
- danielweber 10y ago> most IT-workers at those institutions tend to just mail all details they feel are relevant to the issue Not necessarily disbelieving you, but why do you say this? Every place I've worked or contracted at with PII, I've had to sit through training about not doing this, and management provided tools for proper handling. I don't mean to say that because there are policies that no one ever breaks them. I've also encountered places where what was encouraged on the ground was different than what was listed in policy.
- Freak_NL 10y agoI work for a SaaS vendor of health care record software. From what I have seen care institutions (as opposed to hospitals) do not have the experience or staff in-house to facilitate proper security procedures. The problem as I see it lies not in the routine operations that have a high degree of visibility in the organisation and tend to have strict policies surrounding them because they are anticipated, but in the exceptions, such as key users or the IT support responsible for the service they use reporting issues to the vendor.
- return0 10y agoThat's like the entire Danish population. Also, who sends CDs these days?
- sctb 10y agoThanks, we updated the link from https://www.datatilsynet.dk/afgoerelser/afgoerelsen/artikel/anbefalet-brev-afleveret-til-en-forkert-modtager/ https://www.datatilsynet.dk/afgoerelser/afgoerelsen/artikel/....
- flexie 10y agoJust to give some perspective: These are the confidential ID numbers and health records, including for example psychiatric information, of more than 90 percent of the Danish population. It's not legal, but many organisations still trust you are, who you say you are, if you provide name and the ID number. You can still call some banks in Denmark and get information on the account balance if you state name, account number and the ID number. Same with the tax authorities and some public authorities. The health records are likely to include information that can be used to blackmail our politicians, business people etc. since just about everybody in Denmark uses the public health care system.
- bertil 10y agoAre ID numbers confidential in Denmark? They (personnumer) seem fairly widely shared in Sweden and Finland.
- flexie 10y agoThey are confidential in Denmark, or rather they were supposed to be.
- slau 10y agoConsidering everyone and their cousin has your CPR number over here, I fail to see how it could be seen as confidential. My landlord has my CPR, my company has my CPR, my network operator has my CPR, and my language school has my CPR. Not knowing my CPR has never been a problem, but knowing it has never been an advantage. It's a unique ID as a citizen, but that's as far as it goes. Every time I call my bank, I have to give the amount of cash available on my account for them to "authenticate" me, or tell them when was the last time I logged on to the website.
- kwhitefoot 10y agoThey used to be regarded as confidential here in Norway but that has been rather de-emphasised in recent years. But you won't get anywhere asking for information from a bank if you only have the account and personnummer because all the banks here require two factor authentication, as far as I know.
- Symbiote 10y agoGoogle Translate gives me, "Data Protection Agency takes no further action". Is that true? No-one is fined or prosecuted for this? Or even sacked?
- runesoerensen 10y agoYes that's true - The Data Protection Agency see no reason to take any further action in this case. Their assessment is that there is a low likelihood of an actual leak (based on a written statement from the Chinese employee who opened the letter). And the SSI has promised to send such information encrypted going forward.
- adrianratnapala 10y agoIf I were a senior official at the Chinese foreign service, and I heard that one of my employees got such a CD and just gave it back to the Danes without notifying higher-ups, then I would want that employee's head. On the other hand, if I were a senior official in the Danish foreign service, then I would find my life a lot easier if no one was kicking up a fuss about the Chinese.
- mads 10y agoI know that visa office. I am not so concerned about them. That package could have been delivered anywhere. What I mean is that it is private company handling incoming paper work just like any other company in that building. It happens to be doing paper work for the Chinese embassy. I am more concerned about who put that information on those CD's and why did those people have access to that information. That information should be treated like a radioactive piece of material.
- dsfyu404ed 10y agoAnd you'd likely get it, along with the heads of his/her immediate family.
- roywiggins 10y agoSending this sort of data through the mail unencrypted shouldn't be legal to start with, imho. It's just a matter of time before it ends up in the wrong person's hands by accident.
- danielweber 10y agoTo save other people the google search, population of Denmark is 5.6 million.
- atemerev 10y agoGood thing I only got mine in 2013! My data should be safe then. Or so they say.
- rascul 10y agoHere is the Google translated version https://translate.google.com/translate?sl=auto&tl=en&js=y&prev=_t&hl=en&ie=UTF-8&u=https%3A%2F%2Fwww.datatilsynet.dk%2Fafgoerelser%2Fafgoerelsen%2Fartikel%2Fanbefalet-brev-afleveret-til-en-forkert-modtager%2F&edit-text=&act=url https://translate.google.com/translate?sl=auto&tl=en&js=y&pr...
- Angostura 10y agoSo, to summarise - burning it to CD is actually fine, but they should have used an in-house courier.
- deleted 10y ago[deleted]
- mseebach 10y agoNo, not really, and I said as much.
- stonemetal 10y agoNot Danish so I don't know their laws, but in the US not encrypting the disk would be a violation of HIPAA. In-house courier would work but isn't necessary. FedEx at least, I am sure the others do too, provide services for transporting secure information. Though you have to make use of them, you don't just drop it off with the regular shipping as seems to have been done here.
- pbhjpbhj 10y agoHow much effort is it to encrypt the contents first, virtually none. Items get dropped, go missing, etc. - given the importance of the data then they should have both encrypted (one-time pad, used a secure side-channel to pass the key at the point when it was required) and used a trusted delivery system.
- dang 10y agoPlease don't be uncharitable in HN comments; i.e. please don't choose a weak interpretation of what someone said in order to make it look bad. We detached this subthread from https://news.ycombinator.com/item?id=12128662 https://news.ycombinator.com/item?id=12128662 and marked it off-topic.
- pbhjpbhj 10y agoThe story from the Chinese Visa Application Office (CVAO) is that an employee opened the letter "by mistake": >"It said that it was contacted by an employee of the Chinese Visa Application Centre who said she opened the letter addressed to Statistics Denmark “by mistake” but then delivered the package to the statistics agency." (TheLocal, linked above, http://www.thelocal.dk/20160720/five-million-danish-id-numbers-sent-to-chinese-firm-by-mistake http://www.thelocal.dk/20160720/five-million-danish-id-numbe...). // Having worked as a civil servant I find this unlikely if it were properly addressed. In the office I worked at all mail came in via a mail room who checked and registered it and directed it to relevant personnel. Presumably the CVAO receive a lot of mail, they must have a dedicated system for recording [because we're talking about legal documents and receipt dates therefore are important to record] and directing that mail. So a piece of mail comes in for "Statistics Denmark", now what happens? What I'd expect is it's sent to a mail-room manager to handle. They can then either redirect the mail unopened or forward it to some other personnel. I really can't see them just opening things "by accident" at all. They have a choice to honestly redirect unopened or to actually open it. Now, the opening may have been an individual's simple curiosity, for sure. Interested in any other analysis particularly with reference to how mail receipt is handled in other country's civil service locations. I expect things have moved on somewhat, something like 'tag with barcode, photograph and the computer records the article' is probably the current workflow?
- kayone 10y agowell, the Danish mail service who's one of its main purposes is to read and process the mailing address correctly failed. And they most likely have _many_ more processes and safeguards than any office mailroom.
- tomjen3 10y agoI am a Dane. I have twice received mail incorrectly sent to my current address. One was sent to somebody with a different name, to an address that was close to but not the same as my previous address, the other was to a person who may have lived here but was not the previous occupant. This does not include the letters that should have gone to my neighbors but was put in the wrong letter box. While I naturally assume this is deliberate I won't rule out that this is just complete incompetence.
- kilre 10y agoThe Danmark Statistik office in Copenhagen is 250m away from the Chinese Visa Application Service Center, just for context. I don't see why the Chinese employee had to open the package in order to figure out it was not meant for them. When the package was adressed for someone else isn't that quite obvious when you have a first look at the package?
- mads 10y agoAs a Danish person living in China, I don't know how to feel about this. In some weird way, I think it was a good thing this got delivered to the China visa office and not next door to them, in which case we would probably never have heard about this mistake and for sure it wouldn't be top post here. There is a good headline to be found in this story, as I have just discovered when browsing the Danish news. If this information is handled so recklessly and so nonchalant, it makes me wonder what other people within Denmark also have access to this information. Students, secretaries, interns? Can I register as a scientist and get access? Who exactly has access to my information? I would like to know the answer to this question. I know that visa office and have been there many times. It is not a Chinese government run operation but a private company handling the incoming paper work for visa applications, which get submitted for review at the Chinese run Chinese embassy :P
- neximo64 10y agoAbsolute incompetence.
- Zekio 10y agoThe Danish personal identification numbers are useless for identifying someone since we pretty much give them out to anyone who asks for it, and they can be calculated using some methods, which have been done to some politicians just to show the flaws in the system behind them.
- runesoerensen 10y agoSeems more like this make CPR numbers useless for identity verification, but even easier to identify someone with.
- ksk 10y agoI wonder if this would have been a story if a country other than China was involved. Of course, the information was carelessly handled but then again worse things have happened.. like sending a missile to the wrong address. The bias in the article is interesting, with the author of the article putting the words 'by mistake' in quotes to signal that the mere act of opening the package is suspicious. Over the years I have blindly opened plenty of mailed packages only to realize that it was actually addressed to someone else.
- mads 10y agoYeah, it is not that big of a deal. Wrong address.. Happens all the time.. As a Danish person, I am really interested in the process of packaging these CD's. Who burned them? Who was in the room? Who collected that data? Was it an intern? Maybe a secretary? That is some really personal information. Maybe I can register as a researcher and get access? I dont know, but I want to find out. Maybe there is a really sophisticated social engineering attack hiding in this story....
- sidek 10y agoWorse, at least according to Google Maps, it is only a 17 minute drive or 28 minute bus ride between Statistics Denmark and the Serum Institute. At such a small distance, if such large amounts of confidential information must be delivered, I feel that it ought to be hand-delivered.
- plesner 10y agoThese things keep happening in Denmark but the thing is, very few people actually care here. Avoiding mistakes of this caliber isn't rocket science but it does take a little effort and awareness and as long as nobody cares there is no motivation to make that effort. In that sense this is just giving people what they're asking for. They're not asking for security so they're not getting it.
- ben_jones 10y agoDisclaimer: I 100% believe in the idiom "don't attribute to malice what could equally be caused by ignorance". But I think all those involved should have permanent monitoring on their bank accounts and living status incase a suspiciously large wire were to come from a Chinese entity. This is happening way to often not to become a source of plausible deniability to future criminals. "It was an accident officer I swear!". Sympathies to all those effected by this incident.
- 1337biz 10y agoJust came here to ask what do you guys' think about centralized health care records? It seems impossible to prevent these kinds of "stupid" mistakes from happening. My doctor still works mostly on a paper based system, so in the worst kind of situation just his patients data are lost. Are there any alternatives that prevent those kinds of leaks - esp. considering that even the NSA got out-Snowdened.