On 12 August 2026, a hacker claims to have discovered a Belgian database accessible without any authentication, password or encryption. Attributed to a marketing or loyalty-programme operator, it reportedly contains 148,251 profiles, including 40,455 IBANs. No sophisticated intrusion here, just a misconfigured server. A useful reminder for any Belgian business collecting customer data of where the real weak points lie.
1. What was discovered
According to the hacker's post, the archive holds 24 fields per profile: identity, postal address, date of birth, phone number, email, but also IBAN, BIC code and order or subscription IDs. The claimed volume: 52,688 unique emails, 43,234 Belgian phone numbers, 40,455 distinct IBANs and over 132,000 order IDs, covering every Belgian province. That's roughly, duplicates aside, 1 in 80 Belgians.
2. Why this leak is more dangerous than a plain email list
An email list alone enables broad, poorly targeted campaigns. A database that links identity, contact details, date of birth, banking information and order history is a different kind of material: it lets an attacker select victims, tailor pretexts, and craft convincing phishing or spear-phishing messages, including ones that mimic a customer service reply or a purchase confirmation.
3. An organisational gap, not a sophisticated hack
The hacker's account describes an accidental exposure, not an intrusion: a file stored on a server with no password, no encryption, no access control. This kind of incident often happens at a marketing subcontractor or a loyalty-programme provider, whose security sits outside the direct control of the business that originally collected the data.
4. What GDPR requires, and within what timeframe
In the event of a data breach posing a risk to data subjects, the responsible business must notify the Data Protection Authority (APD) within 72 hours, and inform affected individuals without undue delay if the risk is high. Fines can reach 20 million euros or 4% of global turnover for non-compliance.
The AI view, humans first
An AI assistant can continuously monitor the web and the dark web for signs your business's data is circulating, or automatically audit access to a database. But deciding who should have access to your customer database, choosing a marketing provider that actually secures its servers, and triggering the GDPR notification process remain human decisions. AI monitors and alerts. Expertise decides who has access to what, and why.
This week
Check who can access your customer database and loyalty programme, internally and at your providers. Make sure sensitive fields (IBAN, date of birth) are encrypted. Ask your marketing and CRM providers for concrete proof that their servers are secured.
At Vistalaro Build & Automate, our sites and integrations run on European servers and are built with GDPR in mind from the start, with controlled access. Vistalaro Pulse designs your loyalty and satisfaction-tracking programmes with the same security standard, so your customers' trust never depends on a misconfigured server.
Is your customer data really protected?
We audit access to your marketing tools, CRM and loyalty programme, no jargon.
Let's talk