The problem is that the information was accessible by people without any valid business reason:<p><pre><code> * one of the leakers is a technician, so shouldn't have had access to employee records in the first place
* bulk downloads of any of the data should not have been possible, and trying to do so manually should have started tripping alarms and access restrictions</code></pre>