MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
At online retailer Allekabels.nl, the entire database containing data of approximately 3.6 million customers, including passwords, was leaked — the largest Dutch password data breach to date. The lesson: always report a data breach quickly and completely, and do not downplay the scale. Concealing information or providing insufficient information to affected parties can give the Dutch Data Protection Authority grounds for a thorough investigation and hefty fines.
It seems to be raining data breaches: there was the major data leak at car companies and the fine for Booking.com. Now it is Allekabels.nl's turn — and contrary to initial claims, it involves not 5,000, but about 3.6 million people.
3.6 million customers affected
The entire database is said to have been leaked: private data and passwords of some 3.6 million customers. It is the largest Dutch data leak involving passwords. The data leak at car companies involved more than 7 million people, but no passwords were leaked there.
The stolen data was offered on a hacker forum for around 15,000 euros. In addition to encrypted passwords, this involves dates of birth, phone numbers, addresses, and names — including those of customers who ordered through intermediaries such as Amazon or bol.com. Even bank account numbers of more than 100,000 customers were traded.
Phishing has already started
For criminals, such data is worth its weight in gold: with your name, address, and account number, they can impersonate your bank. That this is happening is evident from customers who created a unique email address specifically for Allekabels (such as [email protected]) and are now receiving phishing emails on it that can only be traced back to this leak.
Unclear communication
According to RTL editor Daniël Verlaan, who was in contact with the hacker, the database had already been hacked in August 2020. The hacker reportedly emailed the company without receiving a response; however, the leak was patched. Allekabels initially called the story new and denied it. Moreover, the company—which initially spoke of 5,000 people—appears to be well aware of the scale: by its own account, it only informed customers with unique email addresses because, according to Allekabels, the data had been stolen by an employee. The AP will investigate whether that is a coincidence.
High fines possible
The AP has requested documents and Allekabels must cooperate with the investigation. Providing insufficient information or downplaying a data breach is a serious violation. By comparison, Booking.com was fined €475,000 for late notification to over 4,000 affected individuals. The advice: always take prompt action in the event of a data breach and do not conceal the extent of the damage.
Frequently Asked Questions
Do I need to inform all affected customers in the event of a data breach?
In the event of a high-risk data breach, you must inform the affected parties without delay. Informing only a portion or concealing the extent may lead to enforcement action.
Does a leak via an employee also count as a data breach?
Yes. Whether data is leaked through an external hack or by a (malicious) employee, it remains a data breach with reporting and disclosure obligations.
What risks do I run if I downplay a data breach?
A thorough investigation by the AP and potentially heavy fines, plus reputational damage. Acting quickly and fully is always wiser.
Ensure that you respond properly to a data breach
The privacy experts at MKB Juristen help you handle a data breach correctly and on time. View our expertise in privacy and data protection or schedule a free intake consultation .