🌙

从盾牌到利剑:数据隐私如何削弱数据安全

From Shield to Sword: How Data Privacy Can Undermine Data Security

Information Systems Research · 2026
被引 0
人大 AFT50UTD24ABS 4*

中文导读

研究发现欧洲GDPR的“访问权”可被黑客利用来冒充受害者获取敏感个人信息,通过真实攻击实验揭示了隐私法规如何反而成为身份盗窃的工具。

Abstract

What is the point in hacking computer systems when organizations voluntarily disclose personal data to anyone who asks convincingly? We show that the European GDPR is paradoxically exploitable for identity theft despite being designed to protect personal data. Subject access requests (SARs) according to its “right of access” (Article 15) can be weaponized by impersonating a victim and submitting fraudulent SARs in their name. We task attackers with stealing the personal data of three volunteers (highly privacy aware person, average user, and semipublic figure) in a real-world setting. These attacks could be replicated by just about anyone. Yet, they obtained sensitive personal data, including addresses, phone numbers, national ID and bank account information, and insurance data. Based on 718 submitted SARs and 21 interviews with data protection officers, we tell a frightening, yet fascinating story of how these identity thefts unfold, expose flaws in how organizations process SARs, and uncover a systemic weakness in the GDPR. We analyze the underlying factors enabling such attacks, assess their real-world impact, and explore mitigation options for individuals, organizations, and lawmakers. Our insights have important implications for how data privacy and data security interrelate and how we manage and regulate them.

数据隐私数据安全身份盗窃GDPR网络安全