{"id":1493,"date":"2025-03-04T20:15:30","date_gmt":"2025-03-04T19:15:30","guid":{"rendered":"https:\/\/nettsak.no\/?p=1493"},"modified":"2025-03-08T01:24:42","modified_gmt":"2025-03-08T00:24:42","slug":"data-breach-at-collectia-and-xplora","status":"publish","type":"post","link":"https:\/\/nettsak.no\/en\/data-breach-at-collectia-and-xplora\/","title":{"rendered":"Data breach at Collectia and Xplora"},"content":{"rendered":"<h2 class=\"wp-block-heading\">System failure uncovered: Serious data breach at Collectia and Xplora - Customer feels powerless<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Leak reveals reprehensible practices: The debt collection company blames the wrong email, while the customer rages against lack of privacy.<\/strong><\/h3>\n\n\n\n<p>Nettsak.no has uncovered a serious data breach involving debt collection giant Collectia and children's watch supplier Xplora. Sensitive personal data, including children's phone numbers, has ended up in the wrong hands. Collectia blames an incorrect email address provided by customer Tobias Tobiassen, but he fights back strongly, accusing the company of gross neglect of privacy.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Wrong addressee: Email gone astray<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"819\" src=\"https:\/\/nettsak.no\/wp-content\/uploads\/2025\/03\/image-1024x819.png\" alt=\"\" class=\"wp-image-1495\" srcset=\"https:\/\/nettsak.no\/wp-content\/uploads\/2025\/03\/image-1024x819.png 1024w, https:\/\/nettsak.no\/wp-content\/uploads\/2025\/03\/image-300x240.png 300w, https:\/\/nettsak.no\/wp-content\/uploads\/2025\/03\/image-768x614.png 768w, https:\/\/nettsak.no\/wp-content\/uploads\/2025\/03\/image-15x12.png 15w, https:\/\/nettsak.no\/wp-content\/uploads\/2025\/03\/image.png 1097w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Email sent to an email address that does not belong to Tobiassen. Zecurecode.com is a domain that offers, among other things, public reading of emails that are not sent to an existing email address, such as <a href=\"https:\/\/www.mailinator.com\/\" target=\"_blank\" rel=\"noopener\">mailinator.com<\/a>.<\/figcaption><\/figure>\n\n\n\n<p>The email, which contained details of a debt collection case and information about an Xplora children's watch, was sent to the address tobiasop1@zecurecode.com, an address that has never belonged to Tobiassen. Zecurecode.com is a domain administered by InfoDesk AS and operated by Open Info. Due to a catch-all feature, which captures all emails sent to non-existent addresses, the sensitive information ended up in a common pool available to a large number of technicians, freelancers and developers.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Collectia blames the customer - Tobiassen strikes back<\/strong><\/h2>\n\n\n\n<p>In a statement to Nettsak.no, Collectia maintains that the error is due to Tobiassen himself providing the wrong e-mail address. The company claims they have followed their routines and pushes the responsibility onto the customer.<\/p>\n\n\n\n<p>Tobiassen strongly rejects Collectia's explanation. \"I have never given the wrong e-mail address. This is an embarrassing attempt to disclaim responsibility,\" says an upset Tobiassen. He can document that he has provided correct information and believes that Collectia's handling of the case is nothing less than a scandal.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Collection letter to former employer: A mockery of privacy<\/strong><\/h3>\n\n\n\n<p>Collectia also tries to justify sending information to Tobiassen's former employer, citing the fact that he was previously employed by ZecureCode. \"This is an arrogant practice and shows a total lack of respect for basic privacy,\" Tobiassen rages.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Exposed children's personal data: A particularly serious incident<\/strong><\/h3>\n\n\n\n<p>The data breach has affected an Xplora customer with a children's watch and subscription. The leaked information could potentially be misused for identity theft, fraud and other criminal acts. It is particularly serious that children's personal data has gone astray, which makes the breach even more serious.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Gross violation of GDPR: Lack of control in the industry<\/strong><\/h3>\n\n\n\n<p>The data breach represents a gross violation of the EU's General Data Protection Regulation (GDPR), which sets strict requirements for the protection of personal data, especially when it comes to children. The incident also reveals a serious lack of control in the industry, where companies appear to have very weak compliance with the data protection rules.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Nettsak.no demands action and responsibility<\/strong><\/h2>\n\n\n\n<p>Nettsak.no demands that Collectia and Xplora immediately take responsibility for the leak, inform all affected customers and take measures to prevent similar incidents. We also question the industry's practices in general and the need for stricter supervision.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Interview with Tobias Tobiassen: \"This could be the tip of the iceberg\"<\/strong><\/h2>\n\n\n\n<p>In an exclusive interview with Nettsak.no, Tobias Tobiassen expresses his deepest frustration and anger:<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\">\n<figure class=\"wp-block-image size-large is-resized is-style-rounded\"><img decoding=\"async\" width=\"1024\" height=\"1024\" src=\"https:\/\/nettsak.no\/wp-content\/uploads\/2025\/03\/image-5-1024x1024.png\" alt=\"\" class=\"wp-image-1500\" style=\"width:261px;height:auto\" srcset=\"https:\/\/nettsak.no\/wp-content\/uploads\/2025\/03\/image-5-1024x1024.png 1024w, https:\/\/nettsak.no\/wp-content\/uploads\/2025\/03\/image-5-300x300.png 300w, https:\/\/nettsak.no\/wp-content\/uploads\/2025\/03\/image-5-150x150.png 150w, https:\/\/nettsak.no\/wp-content\/uploads\/2025\/03\/image-5-768x768.png 768w, https:\/\/nettsak.no\/wp-content\/uploads\/2025\/03\/image-5-12x12.png 12w, https:\/\/nettsak.no\/wp-content\/uploads\/2025\/03\/image-5.png 1080w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p>\"I am shocked and outraged that my and my child's personal data has ended up in the hands of unauthorized persons. This is a gross breach of trust, and I demand that Collectia and Xplora take responsibility. I have documentation showing that I have provided correct information, and Collectia's excuses are a pure diversion from the core of the matter.\"<\/p>\n\n\n\n<p>Tobiassen further explains that he worked at ZecureCode AS until 2022 and then had the e-mail address tobias@zecurecode.com. After he left, he has had tobias@op1.no as his e-mail address. He says that there is nothing that would indicate that Collectia should have used the email address tobiasop1@zecurecode.com. Tobiassen himself believes that they have merged his 2 email addresses, and that is the reason why information has been leaked to the wrong email address.<\/p>\n\n\n\n<p>\"This could be the tip of the iceberg. If they've made this mistake with me, how many others have they done it to? It's a systemic failure and it shows that companies don't take privacy seriously. I feel completely powerless.\"<\/p>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group alignwide is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns alignwide are-vertically-aligned-center is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:100%\"><\/div>\n<\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">What can you do if you are affected?<\/h2>\n\n\n\n<p>If you are an Xplora customer and suspect that your personal data has been leaked, you should:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Please contact Xplora and Collectia immediately for information about your case.<\/li>\n\n\n\n<li>Change passwords and other sensitive information.<\/li>\n\n\n\n<li>Pay extra attention to suspicious emails and scam attempts.<\/li>\n\n\n\n<li>Contact the Norwegian Data Protection Authority to report the breach.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Nettsak.no is following the case closely and demands answers<\/strong><\/h3>\n\n\n\n<p>Nettsak.no will continue to cover this serious matter and demand answers from Collectia, Xplora and relevant authorities. We will keep our readers updated on developments.<\/p>\n\n\n\n<p>It is important to note that both Xplora and Collectia were notified of this matter prior to publication. Both companies have responded to the inquiry and claim that they do not consider the incident to be a breach of law. Xplora has even demanded that the article be unpublished. This attitude, especially Xplora's request to Nettsak.no to contact the Norwegian Data Protection Authority, raises serious questions about the company's understanding and respect for GDPR.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Questions ignored<\/strong><\/h3>\n\n\n\n<p>Neither Xplora nor Collectia has answered the specific questions posed in the email from Nettsak.no:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>How did this data breach happen?<\/li>\n\n\n\n<li>What measures have you taken to prevent similar incidents in the future?<\/li>\n\n\n\n<li>Have you notified the Norwegian Data Protection Authority and the affected parties about the incident?<\/li>\n\n\n\n<li>What procedures do you have in place to ensure that personal data is not inadvertently shared?<\/li>\n\n\n\n<li>Have you considered compensating the affected parties for any consequences of the leak?<\/li>\n<\/ul>\n\n\n\n<p>Both Xplora and Collectia have been informed of the publication of this article and have been given the opportunity to respond.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Source base and transparency<\/strong><\/h3>\n\n\n\n<p>The source basis for this case is an e-mail sent to a public service operated by Open Info on behalf of ZecureCode AS. Open Info operates the online newspaper Nettsak.no. Other sources are Tobias Tobiassen, and <a href=\"https:\/\/infodesk.no\" target=\"_blank\" rel=\"noopener\">InfoDesk <\/a>AS's AI service has been used to analyze the case against Norwegian legislation. InfoDesk AS's AI service has also been used to assist with the generation of article content, controlled by the author.<\/p>\n\n\n\n\n\n<p><\/p>","protected":false},"excerpt":{"rendered":"<p>System failure uncovered: Serious data breach at Collectia and Xplora - Customer feels powerless Leak reveals reprehensible practices: The debt collection company blames the wrong email, while the customer rages against the lack of privacy. Nettsak.no has uncovered a serious data breach involving debt collection giant Collectia and children's watch supplier Xplora. Sensitive personal data, including children's phone numbers, has ended up in the wrong hands. Collectia blames a [...]<\/p>","protected":false},"author":1,"featured_media":1501,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[57,56,60,61,58,63,55,62,59],"class_list":["post-1493","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-nyheter","tag-barneklokke","tag-collectia","tag-databrudd","tag-gdpr","tag-inkasso","tag-nettsak-no","tag-personvern","tag-systemsvikt","tag-xplora"],"_links":{"self":[{"href":"https:\/\/nettsak.no\/en\/wp-json\/wp\/v2\/posts\/1493","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nettsak.no\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nettsak.no\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nettsak.no\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nettsak.no\/en\/wp-json\/wp\/v2\/comments?post=1493"}],"version-history":[{"count":0,"href":"https:\/\/nettsak.no\/en\/wp-json\/wp\/v2\/posts\/1493\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nettsak.no\/en\/wp-json\/wp\/v2\/media\/1501"}],"wp:attachment":[{"href":"https:\/\/nettsak.no\/en\/wp-json\/wp\/v2\/media?parent=1493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nettsak.no\/en\/wp-json\/wp\/v2\/categories?post=1493"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nettsak.no\/en\/wp-json\/wp\/v2\/tags?post=1493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}