Original research was done by Daniel Verlaan[0], who has uncovered data leaks related to COVID testing before[1].<p>In an email to people who had gotten an appointment from this "coronatestnu" company, all the recipients where addressed in CC[2].<p>It seems the required pentesting that is needed with these testing companies wasn't done correctly and will be looked at internally[3].<p>[0] <a href="https://twitter.com/danielverlaan/status/1416673022023458816" rel="nofollow">https://twitter.com/danielverlaan/status/1416673022023458816</a><p>[1] <a href="https://www.zdnet.com/article/dutch-covid-19-patient-data-sold-on-the-criminal-underground/" rel="nofollow">https://www.zdnet.com/article/dutch-covid-19-patient-data-so...</a><p>[2] <a href="https://twitter.com/danielverlaan/status/1416700373230923776" rel="nofollow">https://twitter.com/danielverlaan/status/1416700373230923776</a><p>[3] <a href="https://twitter.com/danielverlaan/status/1416687638896070656" rel="nofollow">https://twitter.com/danielverlaan/status/1416687638896070656</a>