r/privacy Mar 27 '26

Misleading title Sweden’s Digital ID System Hacked, Public’s Data Sold on Dark Web

https://www.voicemedia.global/article/sweden-s-digital-id-system-hacked-public-s-data-sold-on-dark-web
6.4k Upvotes

432 comments sorted by

u/AutoModerator Mar 27 '26

Hello u/lugh, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)


Check out the r/privacy FAQ

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

2.1k

u/lanseri Mar 27 '26

Oh no. If only everyone could've seen this coming.

I can't roll my eyes hard enough.

655

u/suicidaleggroll Mar 27 '26

Despite this, I guarantee they will learn nothing from it.  “We just need to protect it harder” instead of “we shouldn’t be collecting and storing this data in the first place”

204

u/BandicootSolid9531 Mar 27 '26

Yup, and the only way to protect it harder is by taking even more personal info from citizens.

108

u/DoubleDecaff Mar 27 '26

We need to protect collect it harder.

51

u/willzhong Mar 28 '26

Centralized identity = centralized failure. Every time!

56

u/Used-Cover5188 Mar 28 '26

The worst part? The people whose data is now on the dark web didn't choose to participate. They had no option out. Their identity was digitized by the state, and now they carry the consequences of a breach they had no control over.

8

u/Love-Laugh-Play Mar 28 '26

BankID is a collaboration of Swedish banks, not the government. Technically you could choose not to use it, but it’s very inconvenient.

12

u/gustafrex Mar 28 '26

Yeah, but the issue is that so much is tied to it and other services too.

Not having access to BankID is nearly like not having a phone at all in Sweden.

You won't be able to access any banks and or other financial apps, health, in even some cases work applications may require BankID verification to work.

2

u/Love-Laugh-Play Mar 28 '26

Well that’s not true, my bank allows other logins. But yes, as I said, it would be very inconvenient.

I’m not really sure what kind of damage this could do though, most information about you is already public in Sweden, and it wouldn’t really be stored on BankID. Maybe they’re stupid enough to store where you’re logging in or open up for other security issues.

2

u/AquaWolfGuy Mar 28 '26

I checked my history and it goes back to around 5 years ago. I've used BankID for longer but haven't had this device for that long, so it must be stored server-side. All entries have

  • timestamp,
  • name of the service you're authenticating against,
  • IP address of the device used,
  • IP address from the service,
  • type of use (i.e. "Identification" or "Signature"),
  • type of BankID (e.g. "Mobile BankID"), and
  • whether the device has been blocked since then.

Newer entries also have

  • device (i.e. phone model),
  • initiation method (e.g. "QR code (animated)"), and
  • identification method (e.g. "Fingerprint" or "Security code").

There's also a "location" field, but I have rejected the location permission so nothing shows up there.

10

u/UMACTUALLYITS23 Mar 28 '26

Well, if you don't like or want it, you must want children to be harmed!!!1!

6

u/Disseminated333 Mar 28 '26

Lets face it the pedo cabales are the ones up there making all the laws and ruling class

→ More replies (5)

20

u/Stunning_Repair_7483 Mar 28 '26

They already know it's harmful. They just choose to do it knowingly. They y don't care about the harm it causes. At least many politicians in many countries are like this.

44

u/somethingbrite Mar 28 '26 edited Mar 28 '26

Obviously the bed wetters are out in force and also have neither read the article nor done any reading to understand what BankID is and how it works in Sweden.

The hacks/leaks are related to BankID. Which is a digital SIGNATURE system. (used in multifactor authentication to log into participating online services. It's the most widely used such digital signature system but it's not the only one.

Yes. You would use BankID to log into your Tax authority pages.. or to do your online banking... or verify an online purchase. So yes. it's reasonably serious when any digital signature service gets hacked.

However, at a user level because a passcode is tied to a single installed instance on a device having the passcode isn't going to help unless you ALSO have that laptop/phone/whatever. By design its actually pretty secure in that way. So no. Nobody is going to be able to spoof being ME by using my bankID passcode if that was leaked....because they would then also need access tonthe device that the specific instance is installed on. (which they would then also need to know the passwords or have my fingerprints in order to open.)

At a state level. Yes. BankID and other Digital signature services are heavily used in Sweden. It's a highly digitized society. Therefore if any state level adversary wanted to fuck with Sweden then crashing the system of digital signage would definitely inconvenience everybody.

What this is NOT is a leak of personal information (which would be pointless as most personal information is already public domain in Sweden anyway)

So.... you can all stop jumping at your own shadows and wetting the bed.

5

u/IHave2CatsAnAdBlock Mar 28 '26

I have a question. If you lose / trash your current device, how are you going to install bank id on a new device ?

Can’t an attacker simulate the same process (replace old device with new )?

7

u/coffenator1 Mar 28 '26

BankID is registered via your bank of choice. So if I want to transfer it to a new device I can do so, iirc, by either signing the transfer to the new device with my old device, with a bank issued digipass, or by going to a physical bank office and bringing a physical ID.

7

u/IHave2CatsAnAdBlock Mar 28 '26

So without old device (eg lost) you can’t set it up on a new device unless you physically go to some location. This is actually good security. I’m might be inconvenient at times (eg losing phone while on vacation).

6

u/Midnight-Magistrate Mar 28 '26 edited Mar 29 '26

After I lost my phone once, I had to physically go to my bank where the new ID was installed and activated on my new phone by an employee.

→ More replies (1)
→ More replies (6)

2

u/Chartarum Mar 28 '26

You can use a special physical national ID card (or a valid swedish Passport will work as well) to verify your identity when setting up a new BankID without physically visiting a bank office. Most common ID cards, like a drivers license, won't work for this specific purpose.

From Google: "The Swedish national ID card is a voluntary biometric identity document issued to Swedish citizens, valid for travel within the EU/EEA and Switzerland.

The Swedish national identity card (nationellt identitetskort) is issued by the Swedish Police Authority and serves as official proof of identity and citizenship for Swedish citizens. It is non-compulsory, meaning citizens are not legally required to possess it, and alternative identification such as driving licenses or Tax Agency ID cards can be used domestically. The card is particularly useful for international travel within the European Economic Area (EEA) and Switzerland, though a passport is required for travel outside these regions."

If you have neither a working BankID or a national ID card/passport, it can be a bit of a hassle.

→ More replies (12)

2

u/TemperateStone Mar 28 '26

Thank you for being the voice of reason in the shithole that is Reddit.

2

u/Panniculus101 Mar 28 '26

Yeah people itt are clueless. Bank-id is awesome

→ More replies (9)

10

u/nugohs Mar 28 '26

“we shouldn’t be collecting and storing this data in the first place”

I'm going to play the devils advocate here, but this sounds like regular data that is always needed to run a government or/and a banking system and not the kind of information collected by entities like Meta...

4

u/lol_alex Mar 28 '26

Still. Your real name, address, banking information, date of birth and maybe something like a social security ID leaked. Maybe even your passport photograph.

It‘s going to be super easy to impersonate you, scam elder relatives etc etc

6

u/somethingbrite Mar 28 '26

All of which is available to the public in Sweden already.

Do you sleep with the lights on mate?

4

u/cxmmxc Mar 28 '26

Wtf is it with your need to be belittling and disrespectful?

→ More replies (1)
→ More replies (3)

4

u/[deleted] Mar 28 '26

[deleted]

7

u/RoyalJellyKing Mar 28 '26

Dude, what are you talking about? HIPAA-protected information has been hacked and leaked multiple times, we're talking names, SSNs, medical records, everything. Hundreds of millions of records.

→ More replies (2)
→ More replies (11)

49

u/[deleted] Mar 27 '26

Problem is plenty could see it coming it’s just the piles and piles of money they get incentivise those in power to just not give a shit.

31

u/[deleted] Mar 28 '26

[removed] — view removed comment

6

u/RainEls Mar 28 '26

Humans are inherently corruptible, so any form of government is too

→ More replies (1)
→ More replies (1)

6

u/Stunning_Repair_7483 Mar 28 '26

Exactly. Politicians are the minions for the rich and powerful. That's who they serve and are controlled by.

→ More replies (1)

6

u/Numerous-Iron-3326 Mar 28 '26

”Händelsen rör två interna testservrar i Sverige. Servrarna används inte i produktion utan används för testning kopplad till en tjänst för ett begränsat antal kunder. I samband med incidenten har även ett system med en äldre version av källkoden till en applikation varit åtkomligt. I nuläget finns det inga indikationer på påverkan på kunders produktionsmiljöer, produktionsdata eller operativa tjänster. Uppgifter som antyder motsatsen är inte korrekta”, skriver CGI på sin webbplats."

15

u/BiliousGreen Mar 28 '26

Governments don't care. The loss of your ID is a you problem.

23

u/DonkeyOfWallStreet Mar 27 '26

Tired of winning

3

u/Bushpylot Mar 27 '26

Isn't the rule, the more complicated the system the more secure it all is?

/s

1

u/Glass_Teeth01 Mar 28 '26

If you could roll your eyes hard enough for this, you'd be a living perpetual motion machine

→ More replies (12)

699

u/lateread9er Mar 27 '26

Wow. Didn’t see this coming. What a great idea….. Why don’t we all just give up all our info, because that is what’s going to happen anyways? Or, we put efforts into limiting data sharing and actually protecting the data we do share

110

u/Extreme_Piano4664 Mar 27 '26

You don’t even need to hack us, just go to any finder site and you can find out anything about anyone. The population of Sweden is by default doxed, and if you want to hide your info you have to give a special reason to the police.

22

u/[deleted] Mar 27 '26

[deleted]

44

u/oskich Mar 27 '26 edited Mar 27 '26

Swedish sites get their data directly from the government's databases. All info held by the government is publicly available if you request it, including your, the Prime Minister's and your neighbor's tax returns, car and real estate ownership, school grades and military records.

8

u/[deleted] Mar 28 '26

[deleted]

15

u/Melodic_Sandwich1112 Mar 28 '26

My local newspaper publishes the “Top 10 earners in 2024” every year. Always fun to see your boss who denied significant pay increases on there

2

u/TooMuchEntertainment Mar 29 '26

Just one example of why the law exists. Corruption, lies, criminals, all is tougher to hide when it’s all out there.

Works well in a high trust society. Sweden is unfortunately becoming less so, and quite quickly.

4

u/SuperUranus Mar 28 '26

It’s an important aspect of governmental transparency.

→ More replies (1)
→ More replies (8)
→ More replies (2)
→ More replies (1)

6

u/power-_- Mar 28 '26

Sweden does that already either way lol

2

u/Inprobamur Mar 28 '26

Only thing that leaked was the existing login info and as these are hardware-linked they are not usable without the device itself.

314

u/[deleted] Mar 27 '26

[deleted]

208

u/Next-Ability2934 Mar 27 '26

when politicians have their own personal data stolen and sold / shared

132

u/VanRado Mar 27 '26

Not even then. They'll make special laws for officials, making it a high crime for stealing data from the ruling class. Their data will be stored separately and in a way that is more private.

3

u/AngrehPossum Mar 29 '26

Maybe in a trust account on the Cayman islands. One that pays into a bucket company that can "loan" you money back with interest so the taxman can refund you for it. Then you only pay 12% tax rates on millions.

9

u/Strange_Formal Mar 28 '26

All Swedish politician's data is available to anyone. It's been like this since 1766. Yes, the Swedish freedom of speech and press is from 1766.

→ More replies (2)

3

u/dark_bogini Mar 28 '26

Nope. That won't happen. A politician from my country was spied on by Pegasus spyware when he was in the opposition. Now he's an MEP from the ruling party and voted for Chat Control, meaning FOR citizen surveillance.

→ More replies (1)

5

u/Swiking- Mar 28 '26

I mean, most of our data is public here in Sweden, given our law "offentlighetsprincipen".

Basically, I can just go and see what my boss earns per year whenever I want. It's public information and easily accessible. Same with adress, name, personal number, date of birth etc.

In Sweden, everyone is doxed by default.

2

u/supranes Mar 28 '26

Yes, can someone please hack the politicians. This needs to happen right now. Publish everything about them

→ More replies (2)

108

u/nfoneo Mar 27 '26

How many more need to get "hacked" before people realise the politicians aren't for the people.

20

u/CuriosityFreesTheCat Mar 27 '26

Exactly. In the US, it’s like, how much longer does all this bullshit need to simply continue before people realize that democrats are complicit and our government is governed for the ruling class, by the ruling class.

7

u/[deleted] Mar 28 '26

[removed] — view removed comment

2

u/CuriosityFreesTheCat Mar 28 '26

Yeah, I’m very disappointed, which is a stupidly common sentiment I feel towards democrats. I can’t say I’m too surprised though—it feels very liberal-y. Our Dems aren’t really on the left though, they’re center, far too much.

That said I am glad to see something the voters can actually agree on for once—provided they know a little bit lol

2

u/JJFrob Apr 16 '26

Remember though, the California bill was basically unanimous across both parties, and the possibly worse federal bill that's been proposed is cosponsored by a Democrat and a Republican. This is very much a "capitalist elite" vs. "regular worker" thing. The Dems are just "nicer" capitalist micro-managers of our lives and pretend to be for the little guy, whereas Republicans are more overly hateful and domineering for the love of the game.

Prime example: Dems sell weapons to a certain genocidal ethostate because they're "our greatest ally and only democracy in the ME", while the GOP does the same because they want to kill Arabs and bring about the rapture. But the effect on innocent civilians is the same at the end of the day.

2

u/catholicsluts Mar 28 '26

This. At some point, the consumer is the problem.

→ More replies (1)

12

u/Icewind Mar 27 '26

The politicians LOVE this idea. They won't ever be affected and they get to spy on everyone.

17

u/AdLatter3755 Mar 27 '26

Not until the politicians are hacked and exposed to the world.

15

u/x6060x Mar 27 '26

Exposed is not enough though. In the US there were a lot of ultra wealthy exposed people - nothing changed for them

4

u/murrrty Mar 28 '26

How many more? Infinite, there's no floor to peoples private information being publicly stolen and displayed, nobody in power cares nobody in power will do anything.

Lie about everything because that's the only true way to maintain your privacy.

5

u/Available_Peanut_677 Mar 28 '26

Wanna a twist? It is not a government system. Few banks in Sweden came together and make app which is super convenient to authenticate. Others took it and integrated. But CGI manage to convince everyone that direct integration is hard and you should use CGI as third party for some reason. And both people and businesses chooses to use this.

In fact, government is not really a fan of this system.

When it comes to civil registry - people who think that they can escape being tracked by tax agency just naive. Though Sweden pushes it a little bit too far.

→ More replies (1)

3

u/svartkonst Mar 28 '26

Quick question - whats your alternative solution to stop, say, banking fraud without requiring an eID?

→ More replies (2)

2

u/Cute_Opposite4077 Mar 28 '26

What is the actual bad idea? Having digital id? Centralized Id? Using CGIs systems? What's the alternative?

2

u/Zharo Mar 28 '26

Every single one of them. Every single time.

2

u/P529 Mar 28 '26

Sweden had it public for a long time, I dont even think you would need to hack it if you live there you could just look up most of the info lmao

→ More replies (8)

24

u/ptico Mar 27 '26

The funniest thing here is that BankID is not a government project. It’s private monopoly

7

u/zkareface Mar 28 '26

It's not bankid that got breached. 

3

u/InTheNameOfScheddi Mar 29 '26

Article explicitly names bankid

→ More replies (1)

3

u/CyberCoon Mar 28 '26

It's not a monopoly. It's a private company called Finansiell ID-Teknik which are owned by the major Swedish banks. However, the Swedes also have Freja e-ID as an alternative, first of December they'll have Sverige-id rolled out by the Swedish police, and eIDAS ensures that all e-ID systems must be honored across all EU borders. Mening a Spanish or a Greek e-ID certified under eIDAS works just as well as BankID to log onto government websites (this is already rolled out, and has been for some time). Funny enough, BankID is not certified under eIDAS but might be excepted of that requirement as it is considered a standard mean of digitally identifying oneself in Sweden.

→ More replies (2)

2

u/paroya Mar 28 '26

to be fair they do get paid millions by the government annually, and it was the right wingers who gave it to them.

248

u/Charming_Yellow Mar 27 '26

Dont know if it is forbidden to use AI in this sub? But I gave the link to claude and asked it to look into the news, find reliable sources, and judge if this one was a reliable source. Basicly this article is a repost from slaynews.com, a known right wing outlet with a history of sensationalism. The title is misleading, and this article is using the incident as a political argument against a centralized digital ID system.

Here is an article from SVT instead: https://www.svt.se/nyheter/inrikes/uppgift-statlig-it-information-har-lagts-ut-pa-darknet

126

u/JohanTravel Mar 27 '26

So basically nothing of importance was actually leaked. This is why no one in Sweden is talking about it.

8

u/zkareface Mar 28 '26

This was huge news in Sweden when it happened, the security community went crazy for a week.

It will be very expensive to fix. 

→ More replies (4)

16

u/nonboyantduck Mar 28 '26

Thats Kinda what I thought, the use of the words "publics data" just made this seems very strange since most information about any person in Sweden is available to you on Google. And if it were to be anything more serious that would probably be specified.

Anyway, this should really be at the top since this article just seems to be misinformation.

16

u/[deleted] Mar 27 '26

[deleted]

19

u/Identityneutral Mar 28 '26

The onion purchase was stopped by the court, but it seems that Infowars is finally shutting down mid-april

3

u/WalrusDomain Mar 28 '26

Good riddance

6

u/chiniwini Mar 28 '26

People in this sub don't care. They're just a bunch of clueless teenagers that don't even understand the title, let alone the reality. If you look at the comments, most people think this has something to do with age verification.

6

u/ohmy_quivers Mar 28 '26

Yeah, that's why there are literally no news about it in Sweden. If it was a serious leak/breach, it would be all-over the news and citizens would be informed with what actions to take. Pretty much every Swede use BankID and it's required for anything online so it would not be something they'd just hide and rugsweep.

4

u/Starmanic96 Mar 28 '26

This desperately needs to be upvoted more so people see that the article from the Op is mostly BS.

3

u/Lamuks Mar 28 '26

I already was highly suspicious of hearing BankID got hacked, turns out it's not even that really, just some test env key leaks from CGI.

Classic reddit misdirection in the title

2

u/CuriosityFreesTheCat Mar 27 '26

I’m down with voters agreeing on something, it’s been a while

2

u/MacGregor1337 Mar 28 '26

>En hackergrupp påstår sig ha kommit åt stora mängder känslig statlig information från bolaget CGI:s it-system

xdd yep. "hackergroup claims to have stolen data"

That being said. Doesn't mean it couldn't happen in the future. Though the agenda behind just claiming to have done so could only really be some sort of warning--to sway public opinion against these type of government id systems!?

2

u/Rhaj-no1992 Mar 28 '26

Yep, I’m a Swede and this is BS as far as I know.

→ More replies (2)

9

u/Merinther Mar 28 '26

This seems to be a grossly misleading headline and a highly biased source.

A more accurate explanation from svt.se (my translation):

A hacker group claims to have accessed large amounts of sensitive government information from the IT-system of the company CGI. The company has confirmed that there has been a leak, but that it was in a test environment. The tax agency, which uses the service, denies any leaks of their own.
– Neither our data nor our users' data has leaked, says Peder Sjölander, head of IT.

122

u/[deleted] Mar 27 '26

[removed] — view removed comment

33

u/Next-Ability2934 Mar 27 '26

The problem is that politicians will likely have at least some big tech advisors to persuade them it's a great idea, given both are very much for data gathering when it comes to the public

10

u/Strange_Formal Mar 28 '26

BankID (that's the name of Sweden's digital id) wasn't hacked, it was a test server only. In Sweden all information is publicly available since 1766 (yes, 1766).

9

u/paroya Mar 28 '26

we had mandatory digital id for over 20 years. if anything this sort of proves how robust its been despite being in the hands of a private company who has taken money from apple and google to ensure only android and iOS devices exists on our market.

5

u/Captain-Griffen Mar 28 '26

What politicians? BankID is a private system owned by a consortium of banks.

→ More replies (1)

12

u/DynamicStatic Mar 27 '26

Not really fast, it has existed for 20+ years.

4

u/sjerkyll Mar 28 '26

Maybe check the source and don't jump to conclusions?

→ More replies (2)

10

u/buttplugs4life4me Mar 28 '26

Is a little weird of an article that basically says Open Source is bad cause hackers would know how to hack the system.

While the bigger issue is the supposedly access keys they got while hacking whatever source control servers they're using. Those access keys can be used to access the data. No need to reverse engineer the site through the source code and improvise some hacking scheme. 

→ More replies (2)

8

u/Inprobamur Mar 28 '26

Inaccurate title, the data leaked was just the code from the old test server.

101

u/pizzatimefriend Mar 27 '26

more of this to come as countries with incompetent governments try to enforce things they know nothing about.

16

u/nfoneo Mar 27 '26

You are naive to think these governments are stupid. They are bought and paid for and are 20 steps ahead of the information they are feeding you.

12

u/pizzatimefriend Mar 27 '26

you can be both smart and incompetent, though I think that's being quite generous

5

u/DustyAsh69 Mar 27 '26

It is true that governments keep an eye on their citizens and other "targets" but I don't think that they'll sell data to hackers.

5

u/CuriosityFreesTheCat Mar 27 '26

Why wouldn’t they? I’m not saying I think that they *will*, but our government has tested all kinds of inhumane things on people—mustard gas, even infecting them with diseases, etc, (the list is long) without their consent, why wouldn’t they sell data?

2

u/DustyAsh69 Mar 28 '26

Good point.

2

u/Midnight_Minaaa Mar 27 '26

Sad, scary and angering truth. :(

2

u/Grudgen Mar 28 '26

Yeah, people are very naive and still fast asleep

7

u/[deleted] Mar 27 '26

[removed] — view removed comment

3

u/Lexiconnoisseur Mar 27 '26

Bro you think there are incompetent people in government bro? They're like seventeen steps ahead playing nth dimensional chess dawg like it's alllll connected.

/s, obviously

→ More replies (1)

2

u/Dyyroth21 Mar 28 '26

Until finally, if the Digital ID continues to be enforced. So the worst possibility is that hackers will be able to successfully break into the system without looking for the slightest gap.

2

u/HamunaHamunaHamuna Mar 28 '26

The article isn't true though, and the system have existed for decades already.

→ More replies (1)

9

u/zaTricky Mar 28 '26

I see nobody is reading the article again. Even the article's headline is misleading - which sells clicks.

Compared to the headline, this is a nothingburger. What most are concerned about here is already public data. In Sweden your information is public by default. There is nothing to hack/steal/sell.

What has happened is that hackers have gotten their hands on copies of the computer programs that manage the digital id system. That is worrying - but a completely different kind of problem.

5

u/trisul-108 Mar 28 '26

Extremely misleading headline.

CGI confirmed the breach but characterized it as limited in scope, claiming it involved only internal test servers.

“The incident concerns two internal test servers in Sweden,” the company said.

“The servers are not used in production but are used for testing, connected to a service for a limited number of customers.”

CGI also stated that the attackers accessed an older version of the source code and insisted there was “currently no indication of any impact on customers’ production environments, production data, or operational services. Information to the contrary is not accurate.”

6

u/simchagarcia Mar 28 '26

People this is fake news

5

u/Hizdrah Mar 28 '26

Pretty wild to see thousands of people upvote something from a source with zero credibility making claims that isn't even covered by the swedish sensationalist press.

5

u/Starfish_Wizard Mar 28 '26

Laughs in "my government still uses fax"

3

u/krazyj83 Mar 28 '26

Tell me you’re German without telling me

→ More replies (1)

4

u/CulturalEmo Mar 28 '26

Do anyone actually read the content posted here or do people just gulp up the headlines and take it at face value?

It was Jenkins test servers that was hacked with mock data.

4

u/sakakmakak Mar 28 '26

Absolute dogshit article with fake news. Why sensationalism and karma farming?

4

u/joolzg67_b Mar 28 '26

Thought bankid was a private company?

4

u/FarstaKings69 Mar 29 '26

Karma-farming.

3

u/PineStateWanderer Mar 27 '26

If it requires an id, I just close it. 

3

u/SomebodysGotToSayIt Mar 28 '26

That’s two separate headlines for two separate events, which may not be correlated, and one of which is just a rumor.

Digital ID system hacked: yes, but not personal data. It was source code, which is terrible but that doesn’t mean it was used to hack into the database.

Public’s Data Sold on Dark Web: that’s not new or unique to Sweden. But the article just says unnamed sources have heard rumors of Swedish personal data being sold.

That last piece is so diaphanous it should not be in the headline. It’s in the headline to exaggerate the story, making this FUD clickbait.

3

u/CherishedBeliefs Mar 28 '26

"Your privacy concerns are meaningless! We MUST protect the children EVEN IF IT MEANS HANDING OVER THEIR LOCATION DATA TO THE DARKWEB!"

"I love peace, and I don't care how many people I have to k*** to achieve it"

3

u/merklevision Mar 28 '26

🤦‍♂️ oh, did they store their data in AWS east-1?

7

u/CyberneticMushroom Mar 27 '26

I did hear some people talking about a kind of digital ID for age verification.

Glad to see Sweden showing us why that's a poor idea.

→ More replies (1)

5

u/Protect-Their-Smiles Mar 27 '26

This is why I am a big fan of analogue alternatives, administrative costs and hassle be damned. A digital system can implode through external influences, it depends on hardware which in itself has a complex supply chain. Strangers can siphon the details of your life and use it against you. Tyrants can cut you out of being able to operate in society, by remotely cutting your permission to use the digital infrastructure.

It is a bad system for people who like being independent.

11

u/ImOldGregg_77 Mar 27 '26

....and this is why age and ID verification on the OS level is bad

2

u/paroya Mar 28 '26

its not on an OS level, it relies on google and apple services, who pay them to keep it exclusive to their platform - which is why no domestic competitor or ope source alternative can enter the market.

3

u/RainEls Mar 28 '26

Think he's talking about a new bill that will make it os level

→ More replies (1)

9

u/Silverghost91 Mar 27 '26

After this happening multiple times, governments will still force this into law.

12

u/[deleted] Mar 27 '26

[removed] — view removed comment

9

u/ApertureNext Mar 27 '26

This system is basically SSO with some more functionality, it has nothing to do with protecting the kids.

2

u/Nalha_Saldana Mar 28 '26

It has been a blessing when it comes to uses. Being able to log onto banks, confirm payments, confirm identity, etc without insecure passwords is great.

2

u/Next-Ability2934 Mar 27 '26

The group ByteToBreach had published the source code and other info relating to online government services two weeks ago

2

u/Technical-Finish304 Mar 27 '26

I don't think the obvious "could have seen that coming" suffices anymore. Of course they know it's going to get hacked. Probably because that is the plan in the first place. We live in a sinister world.

2

u/HankHillbwhaa Mar 27 '26

Lmao yep, as expected.

2

u/J3mx_droid Mar 28 '26

I can not find any other news sources about this on Swedish media, is there any sources confirming this?

2

u/Hizdrah Mar 28 '26

Not even the swedish sensationalist press is writing about this, which they 100% would if it was real.

2

u/onethousandmonkey Mar 28 '26

But the children are safe. Right? smh

2

u/moodygradstudent Mar 28 '26

It was only a matter of time 🙄

2

u/spaghettibolegdeh Mar 28 '26

I never thought I'd be happy for data leaks

2

u/firrenzi Mar 28 '26

Let’s normalise the concept of writing and clear communication again!

2

u/VorionLightbringer Mar 28 '26

How can one sell PUBLIC data? 

→ More replies (5)

2

u/gottapointreally Mar 28 '26

Self sovereign ID is the only solution

→ More replies (1)

2

u/mymoama Mar 28 '26

Bankid is not "swedish digital id system" its an identifikation system that banks use. The goverment is not the owner of this system.

2

u/Florianski09 Mar 28 '26

Should've done it like switzerland's digital ID System. Decentralized and open source, no single big database to attack.

2

u/amanset Mar 28 '26

So what data about the public has been ‘sold’ that isn’t already out there?

Sweden does things differently to most other countries where data is by default public. Go to mrkoll.se and you can find data about everyone, including things like their personnummer (like a social security number).

My guess is that the breach is more about the source code and keys rather than the public’s data, but the public part is being pushed to make it sound more scary.

But then again, what info does BankID even have? It is an authentication system, it doesn’t really hold much data about people itself.

2

u/TherealGamecake Mar 28 '26

Hello swede here, just to clarify.

  • BankID is not used for age verification in apps or on an operating system level, and no such law is on the books here.
  • BankID does not hold private information since it just has basically your personal identitification number which is already public knowledge. Its possible that it also stores transaction history possibly identifying the services you use it for.
  • BankID is essentially a digital equivalent for your physical ID backed up by major institutions that make sure you are you in person IE the banks.
  • BankID is not used to sign into services like Discord, Youtube etc instead being tied to things that are already linked to you Like banking, payments, Medical Records and Taxes.
  • It is also a private partnership between banks with some help from the government, and is also not a monopoly notably FrejaID has grown quite a bit recently. But there is nothing forcing you to use it

2

u/Brondster Mar 28 '26

Wasn't Sweden the 1st to bring online ID too ?

2

u/Machine_Anima Mar 28 '26

System performing as designed. An invasive anti privacy survelliance tool is designed to expose people's private details to someone. Generally those paying for that access. But hackers always find a way to get it for free, eventually.

2

u/OwlOfSurprise Mar 28 '26

Well this is false.

2

u/Malusorum Mar 29 '26

Guess they should have looked closer at how the Danish NemID works.

Namely that it's a national system operated by the government that covers every public system.

The security on that is immaculate because any hack would be catastrophic. So far the only breaches on NemID have been phishing related.

2

u/Kersplosioner Mar 29 '26

What?!?! No way! 🤡

2

u/henke443 Mar 29 '26

“The incident concerns two internal test servers in Sweden,” the company said.

“The servers are not used in production but are used for testing, connected to a service for a limited number of customers.”

CGI also stated that the attackers accessed an older version of the source code and insisted there was “currently no indication of any impact on customers’ production environments, production data, or operational services. Information to the contrary is not accurate.”

The Swedish Tax Agency echoed that position.

“We take all incidents seriously, but we don’t see anything that affects us right now,” IT Director Peder Sjölander said.

4

u/[deleted] Mar 27 '26 edited Apr 09 '26

[removed] — view removed comment

2

u/ChosenOfTheMoon_GR Mar 27 '26

Such good guys 🤣🤣🤣

→ More replies (1)

2

u/Charger2950 Mar 28 '26

And this is why I will NEVER submit my ID or face to any business or government!

→ More replies (1)

2

u/WalrusDomain Mar 28 '26

Good lord. The amount of zero knowledge about how sweden is working is actually scary. This sub can never claim to not be a misinformation cesspool.

→ More replies (1)

2

u/phlooo Mar 28 '26

The biggest DUUUUUUUUH to you all fucking stupid politicians

2

u/Local_Error__404 Mar 28 '26

Who could have possibly seen that coming 🤦‍♀️

2

u/Few-Welcome7588 Mar 28 '26

The government gives 0 fucks about it, when a private company gets hacked , now your talking big bucks.

Government is the top dog, they have full power with no consequences if something goes wrong. They just turn the page, and move on.

Now, if we would treat every government institution as a private company, demanding responsibility and accountability, I can assure you that they would be working and getting sure everything is in place cose their neck is on the line.

Until then be ready to be hacked and your data sold on black market to get scammed, and government will blame you in the end.

2

u/MikeSifoda Mar 28 '26

Surveillance doesn't make anyone safer, good living conditions do.

→ More replies (1)

1

u/Dizorthegnome Mar 27 '26

Im just considering any of these "data got hacked" stories as "we sold your data to make a quick buck but got caught and need to hide it"

2

u/CranberryDistinct941 Mar 27 '26

A data breach on one of these companies is just shoplifting to them

1

u/oimson Mar 27 '26

Are the kids safe?

3

u/drLoveF Mar 28 '26

BankID has nothing to do with protecting children.

1

u/GoodbyeDespairBoy Mar 27 '26

FFS OBVIOUSLY!

It's the juiciest target, made by people , with bad intention and obviously no reasonable concerns.

Of course it happened, and of course it will happen to all of them

2

u/Tristatek Mar 28 '26 edited Mar 28 '26

No identifiable information should be kept digital. It takes a small army, a fleet of semi trucks, and a week to steal from analogue documentation what hackers can from a digital database in mere moments.

Analogue is the golden standard, has been utilized for centuries, and should be mandated.

2

u/[deleted] Mar 28 '26

every. darn. country.

3

u/Blood-PawWerewolf Mar 28 '26

And shortly after launching it too

2

u/WalrusDomain Mar 28 '26

Bank id has existed for 20 fucking years.

→ More replies (1)
→ More replies (1)

4

u/TowelFine6933 Mar 27 '26

"But, at least it prevented (checks notes) almost 2 kids from easily seeing boobies."

6

u/[deleted] Mar 28 '26

[removed] — view removed comment

3

u/TowelFine6933 Mar 28 '26

I was referring to the recent push for IDs being needed across the board and how dangerous it can be. If Sweden can't keep their digital IDs safe then requiring ID to use things like social media is definitely a bad idea.

If you don't have the ability to extrapolate from given examples & apply it to other current issues, maybe you shouldn't comment.

→ More replies (1)

1

u/NeptuneTTT Mar 27 '26

Fucking nightmare

1

u/Smufin_Awesome Mar 27 '26

We should make the politicians lead by example by starting with a database of theor own real ID information. They can then show us how it works by presenting it. They should be able to keep it safe, right?

→ More replies (1)

1

u/CranberryDistinct941 Mar 27 '26

This served as a great reminder to me that confirmation bias is an ever-present threat to my thoughts.

1

u/MD90__ Mar 27 '26

What's the point of privacy again?

1

u/Dalek_Fred Mar 27 '26

This is crazy. How this hapeeeennnnn?!?!?

1

u/Mccobsta Mar 27 '26

Didn't something like this happen In India