On-Prem

Storage

Hundreds of Dutch medical records bought for pocket change at flea market

15GB of sensitive files traced back to former software biz


Typically shoppers can expect to find tie-dye t-shirts, broken lamps and old disco records at flea markets, now it seems storage drives filled with huge volumes of sensitive data can be added to that list.

Robert Polet, a 62-year-old techie and apparent bargain hunter from Breda, a city in the southern part of the Netherlands, inadvertently happened upon a 15GB trove of sensitive medical records after picking up a quintet of 500GB hard drives for €5 ($5.21) each.

And where exactly was this cybercriminal goldmine? At a flea market next to Weelde airbase, obviously.

He told broadcaster Omroep Brabant, which first reported the story (translated from Dutch): "A few weeks ago, I came back from Turnhout in Belgium. I was on my way home but stopped at Weelde [airfield] because I really had to go to the toilet. There was a flea market next to the airbase. I went to have a look and bought five hard drives of 500GB each for €5 each..."

Polet is a lifelong computer nerd and has worked with them for 30 years. "It's my passion and my life," he told the paper. When he's not at his day job working as a driver for people with disabilities, he's tinkering with tech "often for free, sometimes for a pack of tobacco."

He's also a keen photographer, which is why he decided to scoop up the flea market HDDs at a low price – more storage for his snaps and drone footage. 

After hooking them up when he returned home, Polet found medical data on the HDDs, including the Dutch equivalent of Social Security Numbers, dates of birth, home addresses, medication details, and other GP and pharmacy data. The records were from 2011-2019 and pertain mainly to individuals around the Utrecht, Houten, and Delft regions.

"That was quite a shock," he said. "I thought 'How could something like this happen'? My sister or I could easily have been among them."

Polet drove back to the flea market after making his discovery and bought the remaining ten hard drives from the same individual. "Luckily they were still there," he said.

The natural question to ask next is how the data came to be at a flea market, and to what organization did it belong?

Polet only looked at a small portion of the files – he examined just two of the total 15 disks – but that was enough to deduce the affected healthcare organization was an unidentified one based in Utrecht.

It told Polet the data originated from Nortade ICT Solutions, which used to be based in Breda before going out of business. An associated website has lapsed, The Reg notes. It was an IT company developing software for, you guessed it, the healthcare sector.

Dutch law mandates that storage devices like HDDs that contain medical data must be erased by a professional, and the erasure must be certified.

"The normal procedure is to have them destroyed by a professional company, but that costs money, and by selling the hard drives off the company would have brought in a small amount of cash," said Malwarebytes offering its take on things.

It added there are multiple ways of securely erasing disk data, from overwriting it with random data (single or multiple passes) to invoking the secure erase command in the firmware (where available), all the way to physically chopping up the disk and burning each piece.

Malwarebytes also said individuals should be sure to request their data be erased from public records.

"In the Dutch case, it's remarkable and painful that such a company would have this type of information stored on their drives," it said. 

"First of all, the software provider had no right to store this information. Secondly, even with a legitimate reason to store them, the data should have been encrypted, and of course, the hard drives should have been decommissioned responsibly."

But even the most vigilant to their personal data protection would be unlikely to request the data be erased since it's often used to deliver healthcare services without undue friction. ®

Send us news
40 Comments

Nutanix stops being so opinionated about where data must dwell

Shifts data services to containers and goes back to the future with Pure Storage tie-in

Uncle Sam pulls $2.4B Leidos deal to support CISA after rival alleges foul play

Nightwing claims insider intel helped secure lucrative CISA work but US says decision is unrelated

'We still have embeds in CISA': CTO of Brit cyber agency talks post-Trump relationship with US counterpart

Both agencies seem unbothered despite tech world's clear concerns for US infoseccers

IT chiefs of UK's massive health service urge vendors to make public security pledge

Enormous org has been hit by ransomware again and again, on multiple fronts, over the past year

Eeek! p0wned Alabama hit by unspecified 'cybersecurity event'

PLUS: Euro-cops take down investment scammers; Fancy Bear returns to Ukraine; and more

Good luck to Atos' 7th CEO and its latest biz transformation

We suspect Philippe Salle will need it, not to mention staff and customers

FreeBSD fans rally round zVault upstart

Community fork picks up where TrueNAS CORE left off

Britain's cyber agents and industry clash over how to tackle shoddy software

Providers argue that if end users prioritized security, they'd get it

Everyone's deploying AI, but no one's securing it – what could go wrong?

Crickets as senior security folk asked about risks at NCSC conference

Nextcloud cries foul over Google Play Store app rejection

Claims policy change is really just a way to squeeze out competition

DOGE worker's old creds found exposed in infostealer malware dumps

PLUS: Celsius scammer sent to slammer; Death-by-hacking victim warns you're never safe; and more

Judge allows Delta's lawsuit against CrowdStrike to proceed with millions in damages on the line

CS remains hopeful damages will be limited to seven figures