
A Data Breach That Crosses Municipal Borders
In December 2024, a serious data breach was reported at JCC Software, an external software vendor that provides the digital appointment system to several Dutch municipalities. Through this … Read more
In December 2024, a serious data breach was reported at JCC Software, an external software vendor that provides the digital appointment system to several Dutch municipalities. Through this system, which is used by Municipality of Amersfoort, among others, hackers gained access to sensitive personal data.
However, the impact was not limited to Amersfoort. Because the same vendor also worked for the Municipality of Dinkelland and the Municipality of Tubbergen, data from residents of these municipalities was also exfiltrated. This included names, addresses, contact details, and BSN numbers. This incident painfully illustrates that digital services in the public sector do not stop at organizational boundaries but are part of a shared digital supply chain where risks can multiply.
What Went Wrong Here: One Vendor, Multiple Municipalities
The core of this incident lies in the scale at which software vendors operate. Municipalities often deliberately choose the same vendors to save costs and standardize processes. While efficient, this also creates concentration risk. In this case, one vendor managed an appointment system for multiple municipalities, processing data from different organizations within the same technical environment. When that environment was compromised, the consequences were immediately widespread. For administrators, this is an important insight: outsourcing reduces the operational burden but increases the impact when things go wrong. An incident with a vendor is rarely an isolated problem; it affects all organizations dependent on that vendor.
The Role of the Test Server: A Small Error with Major Consequences
A striking and instructive aspect of this data breach is how the attackers gained entry. They accessed it via a test server that was still linked to the production system. Test environments are used to develop and verify new functionality but should be strictly separated from systems processing real personal data.
In practice, however, test environments are often less strictly secured and insufficiently cleaned up. In this case, that link provided an entry point to production data. For non-technical readers, it is essential to understand: it was not an advanced attack on the core systems of municipalities but the exploitation of an organizational and technical oversight.
Old Data: Hidden Risk in the Chain
Even more concerning is that data that should have been deleted long ago was also exposed via this test server. This points to inadequate data management and insufficient oversight of data retention. From an administrative perspective, this is an important signal. Data no longer needed for service delivery provides no value but introduces risk. Especially with sensitive personal data such as BSN numbers, this can lead to long-term harm for citizens, for example, in the form of identity fraud. The incident shows that privacy legislation like the GDPR not only requires policy documents but also discipline throughout the entire digital chain, including with vendors.
The Impact on Citizens and Trust
For residents of the affected municipalities, this incident is profound. They provided their data to their municipality trusting that it would be handled securely. The fact that this trust is breached by an external vendor does not make it any less serious for citizens. Administratively, this is a difficult dilemma: the cause lies outside the organization itself, but the responsibility towards residents remains. Furthermore, municipalities must allocate time and resources for communication, support, and oversight, even though direct control is limited. This underscores that reputational damage and loss of trust are often the biggest consequences of supply chain incidents.
Why This Is a Textbook Example of Supply Chain Risk
This data breach meets all the characteristics of a classic supply chain incident. The vulnerability was not with the primary organization but with a shared vendor. The impact was not local but spread across multiple municipalities. And the cause was not a single error but a combination of factors: shared infrastructure, insufficient separation of environments, and the retention of old data. For boards of directors and CISOs, this is a clear signal that supply chain risk management must also be maturely implemented in the public sector. It's not just about contracts and SLAs but about understanding technical dependencies and governance in the chain.
Administrative Lessons: From Assumptions to Demonstrable Control
An important lesson from this incident is that trust in vendors must be supplemented with demonstrable control. Administrators do not need to know how a test server technically works, but they should be able to ask: are test and production systems strictly separated? How is it verified that old data is actually deleted? And what happens when a vendor serves multiple organizations? For CISOs, the task here is to translate these questions into clear requirements, periodic controls, and explicit escalation agreements. Without such administrative involvement, these types of risks remain under the radar until something goes wrong.
Broad Relevance for Public and Semi-Public Organizations
Although this incident concerns municipalities, the lessons are more broadly applicable. Healthcare institutions, educational organizations, and housing corporations also work with external software vendors that process sensitive personal data for multiple clients simultaneously. The dependence on shared digital platforms is increasing, and with it, the importance of supply chain responsibility. Positively, incidents like this initiate conversations about digital resilience and governance. The data breach at JCC Software shows that supply chain risk is not an abstract IT theme but a concrete administrative issue that directly impacts trust, continuity, and public responsibility.