Ссылка
click to show
click to show
Slovenian Food Safety, Veterinary and Plant Protection Administration - Data breach (850.000+ users' data in the wild)
Summary
The Slovenian Food Safety, Veterinary and Plant Protection Administration announced on the 29th of October 2025 that it's servers were accessed by hackers. The administration reports that they have taken immediate action to correct the vulnerability.
Over 850.000 citizens' names, surnames, addresses, social security numbers and tax IDs were accessed and considered leaked.
Quotes
Quote
The Food Safety, Veterinary and Plant Protection Administration was informed on the 29th of October 2025 that there was unauthorized access to stored data through a website used to provide information on chemicals, used by farmers for spraying crops. The site vulnerability was used to gain access to data of 873.201 citizens and their personal data (names, surnames, addresses, social security numbers and tax IDs), that were in the register operated by The Ministry of Agriculture, Forestry and Food and the bodies within the Ministry (the Agency for Agricultural Markets and Rural Development, the Administration for Food Safety, Veterinary and Plant Safety, the Inspectorate for Agriculture, Forestry, Hunting and Fisheries) or have been subject to inspections in the field of agriculture.
This includes, but is not limited to, livestock registers, farm registers, recipients of agricultural subsidies, pet registers, etc. This is data of taxpayers who are entered in the Register of Entities on the basis of the Agriculture Act and related laws and bylaws.
Individuals are advised not to share additional personal information by phone or email unless they are 100% sure who they are talking to. If they detect an attempt at such abuse, they should immediately notify the police.
The Food Safety, Veterinary and Plant Protection Administration immediately informed the competent SIGOV-CERT team as the competent team for responding to cyber incidents in public administration bodies at the state and local level (an organizational unit of the Office of the Government of the Republic of Slovenia for Information Security) and the Information Commissioner of the unauthorized access, and filed a report with the police.
My thoughts
Such gross negligence of personal data of the people of a country should be punished severely. The country of Slovenia has a little over 2,100,000 population and a little less than half of it's citizens' personal data is now in the wild. I honestly wouldn't be surprised if the government was still using old software for critical data storage. The site used to access the data is the same for at least 15 years. And as a farmer myself, I am honestly