
The Nebu Incident: When a Supplier Suddenly Becomes Visible
Cyber incidents are increasingly less contained within the boundaries of a single organization. The data breach at Nebu is a clear example of this. What started as a… Read more
Explore phishing and social-engineering intelligence and data exposure and breach intelligence in the live cyber intelligence feed.
Explore
Related signal context
Open the classified signal themes connected to this analysis.
Cyber incidents are increasingly less contained within the boundaries of a single organization. The data breach at Nebu is a clear example of this. What started as a security incident at a relatively unknown software supplier quickly gained a much broader impact. Not because it was technically exceptional, but because its consequences became visible at organizations that serve millions of people daily.
Attention to the incident grew when organizations such as Nederlandse Spoorwegen (Dutch Railways) and VodafoneZiggo, along with healthcare and pension organizations, had to inform their customers and members about potentially leaked personal data. It was notable that these organizations themselves had not observed an attack. Their systems functioned as expected, yet the impact was still felt.
Precisely this makes the Nebu incident relatable for many executives and CISOs. The vulnerability was not in their own IT environment, but in a link further down the chain.
A Central Role, Largely Out of Sight
Nebu develops software for market research and customer satisfaction surveys. This software is used by market research agencies that conduct surveys on behalf of organizations among customers, travelers, insured parties, or participants. This involves processing personal data such as names, email addresses, phone numbers, and additional data needed to analyze results.
For many end organizations, Nebu is not a party with whom direct contact exists. The relationship runs through the research agency executing the assignment. At the same time, this means that large amounts of data converge in one technical environment, without end organizations having daily visibility into it.
That is not an exceptional situation. In many digital chains, there are suppliers who are functionally seen as supportive but operationally hold a key position. The Nebu incident suddenly made that position visible.
How the Incident Unfolded
In the spring of 2023, it became clear that unauthorized parties had gained access to Nebu's systems. Through this access, data stored by customers on the platform could be viewed or exfiltrated. Because Nebu itself does not communicate directly with end-users, information provision occurred through multiple layers.
Market research agencies informed their clients, who in turn had to inform their customers and participants and reported the incidents to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). As a result, the full extent of the incident did not become clear all at once, but the picture gradually emerged.
Ultimately, it turned out that personal data of an estimated 2.5 million people were involved, spread across approximately 190 organizations. For many of these organizations, the incident only became concrete when they themselves had to communicate and account for it.
The Consequences for Visible Organizations
For organizations like NS and VodafoneZiggo, this meant they became the point of contact for customer questions and concerns, even though the technical cause lay outside their own systems. Nevertheless, the responsibility for communication, explanation, and internal assessment rested with them.
In public perception, that distinction makes little difference. Citizens and customers turn to the organization with which they have a direct relationship. Where the incident technically originated plays a subordinate role in that context.
That tension between technical cause and social responsibility clearly emerged during this incident.
What Kind of Data Was Involved?
The data involved in the Nebu incident largely consisted of contact details and research data. There were no indications that passwords or financial information had been leaked. At the same time, this type of information can be relevant for targeted phishing or deception, especially when combined with other available datasets.
Besides the direct data risk, something else became visible: the limited prior overview. Many organizations did not have a complete picture of which software suppliers were part of their data processing and how these suppliers related to each other within the chain.
That made it difficult to assess in advance where vulnerabilities lay and what the potential impact would be if one link failed.
Legal and Organizational Aftermath
Following the incident, investigations by the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) ensued, and legal proceedings arose between parties in the chain. These concerned, among other things, information provision, liability, and contractual agreements. Market research agencies indicated that they were not always informed in a timely or complete manner about the nature and extent of the data breach.
This phase of the incident largely took place out of sight of end-users but did influence cooperation and trust between involved parties. It made clear that handling a supply-chain incident extends beyond technical recovery measures.
A Recognizable Pattern in Digital Chains
The Nebu incident is often mentioned in discussions about supply-chain cyber risks precisely because it is so recognizable. Organizations are increasingly using specialized suppliers who operate in the background but play a central role in data processing and digital processes.
These dependencies often arise gradually and are not always explicitly considered critical. Only when an incident occurs does it become visible how intertwined the chain is and how many organizations can be affected simultaneously.
In that sense, the Nebu incident fits into a broader pattern also visible with cloud providers, software suppliers, and other service providers who occupy a similar position within digital ecosystems.
Visibility as a Starting Point
What this incident primarily shows is how important insight is into how data and processes move through the chain. Not only with direct suppliers but also with underlying software and platforms that play a role in execution.
By understanding these connections, more context emerges when an incident occurs. The Nebu incident thus makes visible how digital dependencies function in practice, precisely when they come under pressure.