TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

2.7M medical calls breached in Sweden

185 pointsby skekaeeewwover 6 years ago

15 comments

Sverigevaderover 6 years ago
On my machine Google translate seems to &quot;boot-loop&quot; that site because of the cookie settings so I&#x27;ll just do this:<p>Files were stored on a server using HTTPS but requiring no credentials. <a href="http:&#x2F;&#x2F;188.92.248.19:443&#x2F;medicall&#x2F;" rel="nofollow">http:&#x2F;&#x2F;188.92.248.19:443&#x2F;medicall&#x2F;</a> Part of the calls were saved as .mp3s with the customers phone number as file name. CEO when confronted wouldn&#x27;t believe it and hung up when the reporter asked if he could play one of the tapes.<p>The articles states that the server was a NAS (nas.applion.se).<p>All files have been available since 2013.<p>When calling 1177, there&#x27;s no need to identify yourself with your personal identity number. You can if you want to if your medical history is of significance to your call.<p>Source: Am swede and this article... <a href="https:&#x2F;&#x2F;computersweden.idg.se&#x2F;2.2683&#x2F;1.714787&#x2F;inspelade-samtal-1177-vardguiden-oskyddade-internet" rel="nofollow">https:&#x2F;&#x2F;computersweden.idg.se&#x2F;2.2683&#x2F;1.714787&#x2F;inspelade-samt...</a><p>And I want you guys to hear it from me before you hear it on the streets... I once called 1177 wanting to order a new pair of knees because one of mine hurt. The nurse who answered had a good laugh.
评论 #19194198 未加载
评论 #19192561 未加载
评论 #19195004 未加载
评论 #19192768 未加载
testplzignoreover 6 years ago
There are quite a few hosts responding on port 80 in the 188.92.248.0&#x2F;21 subnet, including versions of httpd and php over a decade old. I wouldn&#x27;t be surprised if there are more things unsecured. Yikes.
评论 #19195126 未加载
评论 #19192862 未加载
liquidiseover 6 years ago
Let&#x27;s talk legal ramifications.<p>The cause of technical breaches falls onto a sliding scale in my mind. That scale goes from pure technical negligence to overbearing technical complexity.<p>This breach seems like pure negligence. In a surgery this wouldn&#x27;t be &quot;complications&quot;, it would be malpractice. Does GDPR protect those breached here? What recourse do these people have?<p>We really need to change the narrative around data. It should be a liability. Unlike other disruptions software drives, this will need to be driven by governments.
评论 #19193594 未加载
jdmoreiraover 6 years ago
Either me, my girlfriend or both of us are in those phone calls.<p>I feel absolutely betrayed by the state. I always knew that Sweden&#x27;s obsession with medical data collection would back-fire but audio recordings? That&#x27;s just too much.<p>I hope everyone involved gets sued into oblivion!
评论 #19192298 未加载
评论 #19217350 未加载
评论 #19192270 未加载
taplandover 6 years ago
Yep. My calls with personal identification number are absolutely in there, with list of 10+ medications, and medical history including genetic disorders and other things.<p>Imagine becoming a public person in the future with random russian mobs blackmailing me based on me and my family&#x27;s medical history.
评论 #19193551 未加载
评论 #19192796 未加载
teddyhabout 6 years ago
Latest news: The company with the security breach reports the reporter and news organization to the police for unauthorized entry into their computer system:<p><a href="https:&#x2F;&#x2F;www.dn.se&#x2F;sthlm&#x2F;medhelp-polisanmaler-tidningen-computer-sweden&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.dn.se&#x2F;sthlm&#x2F;medhelp-polisanmaler-tidningen-compu...</a>
评论 #19219080 未加载
rollulusover 6 years ago
Seeing posts like this remind me of a nice quotation I saw somewhere, which is like &quot;all data will eventually be either public or gone forever&quot;. Unfortunately my search skills are insufficient to find the exact wording or author.
评论 #19192110 未加载
teddyhover 6 years ago
Original source: <a href="https:&#x2F;&#x2F;computersweden.idg.se&#x2F;2.2683&#x2F;1.714790&#x2F;1177-lackan-integritetshaveri" rel="nofollow">https:&#x2F;&#x2F;computersweden.idg.se&#x2F;2.2683&#x2F;1.714790&#x2F;1177-lackan-in...</a>
ObscureScienceabout 6 years ago
Their router admin page and ssh are also open to the internet.
jacquesmover 6 years ago
So, who thought it was a good idea to record these in the first place and then to store them on an internet facing server? It doesn&#x27;t surprise me one bit though.
评论 #19193602 未加载
vectorEQover 6 years ago
hacking things together in an agile environment :&#x27;) just deploy to production. no worries! be happy!
评论 #19217329 未加载
dontbenebbyover 6 years ago
Why would you even record these calls indefinitely, without a deletion schedule?<p>Were they recording <i>all</i> calls, not just a subset to be audited for customer service?<p>Why not have an auditor listen to the call live and destroy the recording if everything is done by the book and evidence need not be retained?
评论 #19192966 未加载
mrintegrityover 6 years ago
The site hosting this seems to be dead, probably from the load but hopefully from action taken by the company now that it&#x27;s public knowledge. Does anyone have a list of the affected phone numbers? I would like to check if mine is in there
aboutrubyover 6 years ago
The government can&#x27;t fine itself I guess, so it would have to be the EU that fines sweden? Or some kind of class action from swedes?
评论 #19191631 未加载
评论 #19191706 未加载
评论 #19191860 未加载
rb808over 6 years ago
I&#x27;m not clear on why medical records are so sensitive. I can understand some people might want to hide HIV status - but is there anything else? In the US people have wanted to hide prior conditions from insurance companies, but I wouldn&#x27;t expect this a problem in Sweden.
评论 #19192126 未加载
评论 #19191668 未加载
评论 #19192379 未加载
评论 #19191665 未加载
评论 #19191789 未加载
评论 #19195144 未加载
评论 #19191683 未加载
评论 #19191748 未加载
评论 #19191649 未加载
评论 #19192114 未加载
评论 #19217954 未加载
评论 #19192855 未加载
评论 #19191981 未加载