Nobody wants to be confronted with this: a cyber incident in your organisation in which personal data of your employees or customers are stolen. Unfortunately, this kind of thefts is on the rise. If there are consequences, they are often not immediately visible. Stolen data can be sold for fraudulent activities and can victimise others. This is known as secondary victimisation. Since there is no advice yet on how to deal with this, best practices have been published from Project Melissa, with concrete recommendations on how to act to prevent this kind of theft, or to limit the impact thereof once data have been captured.
What is secondary victimisation?
Personal data are often stolen in data theft, including ransomware attacks. Examples of personal data are name, address, residence data: telephone numbers, copies of ID cards, information on a person’s health, or data about a person’s salary. These data are interesting for criminals, because they may be used, for example, for identity fraud. Criminals can take out credits with the stolen data and will often use the data for WhatsApp fraud. The stolen mobile phone numbers are abused to mislead people and tempt them into transferring money to someone who impersonates an acquaintance.
Secondary Victimisation Best Practices
This may have big consequences for the victims. The best practices target organisations that are or have been confronted with data theft and whose employees (or customers) are at risk of secondary victimisation. In the best practices, advice is given that can be used during several phases of dealing with such a data theft. For example, tips are given on communication when a data theft has occurred and how to prevent employees from falling victim to identity fraud.
Pim Takkenberg, General Manager at Northwave Cyber Security, says: “As a former cybersecurity expert with the police and the AIVD, I know how devastating the consequences of data theft can be. When there is a cyber incident, the damage does not end at the organisation in question. Stolen personal data may still make victims months afterwards via identity fraud or other kinds of fraud. With these best practices we wish to give organisations concrete tools to protect their employees and customers better against this ‘secondary victimisation’.”
Project Melissa
Project Melissa is a collaboration between the Dutch Public Prosecution Service, the police, the National Cyber Security Centrum (NCSC), Cyberveilig Nederland and several cyber security companies[1] with the purpose of making the Netherlands unattractive to ransomware attacks. The alliance consists of parties exchanging information with each other on a structural basis and sharing and discussing topical developments more often. The collaboration started in 2021 and was consolidated in a covenant in 2023. Melissa has contributed to successful operations such as Deadbolt, Genesis Market, Qakbot, Lockbit and Cactus. Several whitepapers were also published.
You can find more information on: Project melissa - Cyberveilig Nederland (in Dutch)
Download the best practices via the button below (in Dutch).
[1] Computest Security, Data Expert, Deloitte, Eye Security, Fox-IT, Kennedy Van der Laan, NFIR, Northwave, PWC Nederland, Responders, Tesorion en Trellix.