Wednesday 8 May 2019, Poradnik bezpieczeństwa

Data of Gdańsk citizens in the wrong hands

Lost24

The city of Gdańsk, in order to encourage its residents to fill in their income tax, has organized a lottery. Over 18,000 people participated in the lottery, with one of the prizes being a hybrid car.


In order to participate in the lottery, you had to fill in a form where you were asked to fill in the details such as your name, social security number, phone number along with your e-mail address and the place where you have submitted the tax return.


However, one of participants of the competition has discovered a glaring error, the contest website pitwgdansku.pl enabled third parties the access to the data of the participants. The error was reported to the company responsible for the website – PlayPrint as well as to the Trojmiasto.pl portal.


Following the report, the configuration of the website was changed and an additional level of security was introduced. However, the breach that occurred could have allowed third parties the access to sensitive data of people who registered by April 27 3:00 AM.


According to PlayPrint, participants of the lottery were informed by SMS about the detected threat, and the violation was reported to the Office of Personal Data Protection.