Registrant data was temporarily visible on sidn.nl

Error caused by maintenance activities

On the morning of Monday 9 September, during maintenance to the SIDN website, visitors who used the Whois to look up domain names were temporarily able to see registration data that shouldn't have been visible. A total of 1,918 domain names were looked up while the problem was active. The Whois is a search tool that's intended to enable people to look up domain names, but details of private registrants are normally withheld. Registrant details are supposed to be visible only if the registrant is a business.

Cause

The maintenance work that was carried out involved replacing our web servers. Unfortunately, an error was made when connecting the new servers, which resulted in them having greater access than they should have had. Whois users could therefore see more registration data than they should have, including registrant details. The information mistakenly made available was the name, address, e-mail address and phone number of the registrant, the administrative contact and the technical contact. That information should be visible only to the domain name's registrar and to SIDN.

The problem was confined to the Whois service on sidn.nl. Our other information systems (command line-based Whois/Is service and RDAP service) continued to function correctly.

Thorough investigation

Since the incident was detected, we have taken great care to follow the correct response procedure and to report the matter correctly to the Data Protection Authority. We are conducting a thorough investigation to establish exactly what happened and the exact impact. Appropriate steps will then be taken to prevent recurrence.

Update, 11 September 2024

All the registered contacts for the 1,918 domain names affected by the data breach have now been identified. We have today e-mailed the people in question, telling them about the data breach and explaining the remedial action we have taken. The incident has also been reported to the Data Protection Authority.

Feel free to get in touch if you've got a question

You can reach us on working days between 8:30am and 5pm (Dutch time) by calling +31 26 352 5555 or mailing support@sidn.nl.