Comment by olau

13 hours ago

Just to expand slightly on this: Some old procedures, probably from the main frame age, live to this day in old institution, including the belief that you can ask people about their personal number over the telephone and auth them that way.

I don't think any IT infrastructure is doing it, it's all by a national single-sign on system.

I will expand a bit further - all the data that was compromised in this breach is public by design in sweden, as far as I know. Not just the personal numbers.