Sharing sensitive data with strangers

Situation 1 – “A photo with my grandson”

Mrs Maria posted a photo of her grandson on Facebook to mark his birthday. However, she didn’t notice that a document with a visible address was lying on the table next to him. Modern mobile phone cameras have very high resolution, which means that a great deal of detail can be easily seen in the photos. In addition, the photo also showed a plaque with the flat number on the door. On the table next to the cake was a card with her grandson’s full name, and the caption under the photo read: “We’re off on holiday tomorrow!”.

Why is this dangerous? A fraudster could have found out the address, linked it to the family, and realised that the household would be away in the near future.

Situation 2 – “A boarding pass as a souvenir”

Mr Jan returned from his holiday and decided to share his travel destination on social media. He posted a photo of his boarding pass, and his open passport was also lying on the table next to it. This ‘souvenir’ also contained information about the airline, the booking reference, and the passenger’s full name. The photo also showed the passport, from which the number could be easily read. The fraudster had the booking reference, the airline, the surname and the passport number – which was enough to gain access to the airline’s system and retrieve Mr Jan’s full travel details.

Situation 3 – “Renovation in progress”

For several weeks, extensive renovation work had been underway in Kasia’s flat. Finally, the last touches in the living room were completed and she could now show off her new living space to her friends. Photos of the newly refurbished living room appeared on Instagram. The photos showed expensive audio-visual equipment, as well as large windows overlooking the clearing behind the block of flats. An earlier post on the social media site from a few days ago read: “I’m due to have an operation at the hospital tomorrow; I’ll be back on Monday – keep your fingers crossed.” A third party received information about the empty flat, as well as its approximate location based on the view from the window.

Situation 4 – “Health-related comment”

Mr Stefan posted a comment on a health forum saying, “I’m home on my own; my wife’s away, and I’ve got an appointment with the cardiologist tomorrow. I hope the results will be fine.” Mr Stefan didn’t realise that his post included his full first name and distinctive surname, as well as his location. At the same time, his social media profile was publicly accessible, so a third party could easily obtain a range of information about Mr Stefan and, furthermore, could call “on behalf of the clinic” to obtain further details such as his full address (“we’ll send you the results by post”), his PESEL number (“please just provide your PESEL number and we’ll issue a prescription”).

Situation 5 – “Sport is health”

Ms Ewa had just posted photos of her green balcony on social media. The balcony stood out from a distance thanks to the large number of colourful flowers. In addition, several times a week, Ms Ewa would go for a run of a few kilometres with a group from her housing estate, posting a screenshot of her results and time each time. For a burglar, the combination of information about the person’s absence and the distinctive balcony was practically an invitation to break in.

The situations above show that our everyday, routine activities often lead to data ‘leaks’. It is not a single piece of information that is dangerous, but the combination of such details and a stroke of bad luck. We’re not trying to scare anyone here, but to raise awareness so that we look at our photos and comments on social media through the eyes of a third party. Is there anything about us there that shouldn’t be revealed?