Menu
Browse

Cyber Incident Victim: Gemeente Ede

Date:

Jul 2016

Location:

Netherlands

Summary

A municipal website vulnerability exposed personal data of approximately 3,700 residents through an insecure contact form database, allowing unauthorized access to names, email addresses, and occasionally social security numbers voluntarily entered by users. The breach was discovered during routine security checks when personnel also identified unauthorized page redirections to external commercial content. Following the incident, external specialists resolved the technical flaws while the municipality notified affected individuals and implemented warnings advising against submitting sensitive information via the form.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On July 8, 2016, a digital security staff member at the Municipality of Ede discovered a security vulnerability during a routine check of the municipal website. The vulnerability allowed unauthorized individuals to access a database linked to an online contact form where residents could submit questions or request contact from municipal services. This form required residents to enter their names and email addresses, though some users voluntarily added their social security numbers despite no official request for this sensitive information. Approximately 3,700 residents' personal data was compromised through this unauthorized access. The security personnel also identified that certain pages on the municipal website had been redirected to external pages promoting diet pills, indicating additional unauthorized modifications to the site infrastructure.

Cyber Incident Image

The municipality immediately engaged an external security agency to remediate the vulnerability and remove the malicious redirects following the discovery. Officials confirmed the breach impacted only the contact form's linked database and found no evidence of broader system compromise. All affected residents received direct email notifications detailing the incident and the specific nature of the exposed data. As a preventive measure, the municipality added prominent warnings on the contact form page advising residents against submitting sensitive personal information. No financial data or passwords were confirmed to be involved in the breach, though the exposure of voluntarily provided social security numbers created potential identity theft risks for an unspecified subset of individuals. The incident prompted internal reviews of website security protocols but did not result in public reports of subsequent misuse of the leaked data.

Sources
Sources available to members
1 source