Belgique : 148 251 citoyens exposés selon un pirate
A Belgian hacker, known as ‘Orion,’ claims to have discovered a publicly accessible database containing personal information of 148,251 Belgian citizens, including names, addresses, phone numbers, email addresses, bank details (IBANs), and order IDs. Orion asserts the database was exposed due to misconfigured services, not a traditional hacking attack. This incident follows a series of similar data exposures attributed to the same actor throughout August 2026, targeting various sectors and countries, including a US automotive service, Web3 infrastructure, and services linked to hardware wallets.
A Belgian hacker, known as ‘Orion,’ is claiming to have discovered a publicly accessible database containing personal information of 148,251 Belgian citizens. The database reportedly includes names, addresses, phone numbers, email addresses, bank details (IBANs), and order IDs. Orion states that the exposure stemmed from misconfigured services, specifically a publicly accessible database, rather than a sophisticated hacking attack.
According to Orion’s publication from mid-August 2026, the database is a result of a series of similar data exposures attributed to the same actor throughout the month. These previous exposures targeted various sectors and countries, including a US automotive service with 59,278 emails, nearly 39,000 phones, and 222 bank card details, as well as a Web3 infrastructure accessible via Firebase, exposing 16.9 million records.
Orion describes a chain of data circulation: consumer, marketing program, data aggregator, and finally, the exposed database. He claims the information was accumulated through loyalty programs, subscriptions, and consumer panels. The database lacks any form of password protection, encryption, or access control, according to Orion.
This incident is part of a broader pattern of activity by Orion, who has previously exposed databases linked to services in Norway (148,288 citizens), a Saudi government welfare service, the United Nations, a photographic service, and a stalkerware Android application. The data includes GPS locations, photographs, and call logs.
Furthermore, Orion has claimed exposure of data from a South Korean service (47.9 million lines with bank details), and 34 MSSQL databases belonging to the Gran Caribe hotel group. The hacker emphasizes the prevalence of misconfigured services, particularly Firebase, and open databases without authentication. It’s important to note that while Orion’s claims are extensive, independent verification of the data’s authenticity and continued accessibility remains challenging.
