[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3q6tpl60x1ace":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":31,"seoTitle":32,"seoTitleEn":8,"seoDescription":32,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":4,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda48825134","bulgarian-national-revenue-agency","Bulgarian National Revenue Agency Data Breach","nap.bg","2019-07-15T00:00:00.000Z","2019-07-18T18:38:49.000Z","2026-07-09T17:53:21.732Z","2026-07-18T23:46:54.327Z","Third party breach","https:\u002F\u002Fwww.oecd.org\u002Fen\u002Fnetworks\u002Fglobal-forum-tax-transparency\u002Fnews-events\u002F2019\u002Fstatement-on-the-data-breach-in-the-national-revenue-agency-of-bulgaria.html",[15,17,18,19],"https:\u002F\u002Fwww.reuters.com\u002Farticle\u002Fus-bulgaria-cybersecurity-idUSKCN1UB0MA","https:\u002F\u002Fwww.akingump.com\u002Fen\u002Finsights\u002Falerts\u002Fcyber-attack-in-bulgaria-businesses-foreign-nationals-as-well-as","https:\u002F\u002Fwww.cshub.com\u002Fattacks\u002Farticles\u002Fincident-of-the-week-4-million-bulgarian-citizens-affected-by-tax-agency-data-breach",471167,"known",null,"unknown","High",[26,27,28,29,30],"Email addresses","Names","Phone numbers","Physical addresses","Taxation records","\u003Cp>The Bulgarian National Revenue Agency data breach is related to the leak of extensive tax and personal data records obtained from the systems of the Bulgarian National Revenue Agency in July 2019. In this record, the verified main impact used for the search is 471,167 unique email addresses. The overall context of the incident is broader than this; various news reports and investigations have indicated that the data included tax and administrative records concerning approximately 5 million individuals. Therefore, the distinction in numbers should be kept clear: the search record refers to the unique email impact, while the incident context refers to the larger national data set.\u003C\u002Fp>\n\u003Cp>The verified main data categories are email addresses, names, phone numbers, physical addresses, and tax records. Tax records can be associated with highly sensitive areas such as income, liabilities, debt, social security, and administrative transaction context. Since this incident concerns a government tax agency, users should not consider the data as they would a voluntary membership account; citizens and related individuals may have shared such information as part of mandatory public services.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>In this record, email addresses, names, phone numbers, physical addresses, and tax records are verified data classes. Email and phone information can be used for direct contact. Names and physical addresses may make phishing or fraud messages appear more personal. Tax records may carry sensitive context regarding a person's income, debt, social security, or details related to public administration.\u003C\u002Fp>\n\u003Cp>The password is not a verified data field for this record; the risk assessment should be based not on password cracking but on phishing, impersonation of public institutions, tax debt fraud, fake notifications, and abuse of identity verification. An attacker may prepare messages that appear to be from a tax authority, payment notification, refund process, or public service application. The presence of real names, addresses, or tax context in such messages can make them appear credible.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The scope of this record is 471,167 unique email addresses. The verified data classes are email addresses, names, phone numbers, physical addresses, and tax records. Although the entire incident can be considered part of a broader national data leak, this page uses the number of verified records that can be matched to emails as the main figure. This distinction is important to prevent giving users the false impression that all 471,167 individuals represent the total impact of the incident.\u003C\u002Fp>\n\u003Cp>It has been reported that administrative records belonging to citizens and companies exist in the broader context of the data set; however, the fields shown to the user on this page are limited to verified primary data classes. Payment card, account password, private message, or health record are not among the primary verified data classes for this record. User action should be planned based on tax and identity theft risks.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Citizens registered for tax purposes in Bulgaria, foreigners with income or public administration relationships in the country, and company representatives may be in the highest risk group. Individuals whose email addresses are included in this data set may be targeted with messages impersonating public institutions. Users with phone and physical address information may be subjected not only to email but also to scam attempts via calls, SMS, and mail.\u003C\u002Fp>\n\u003Cp>Tax records may carry sensitive clues about a person's financial situation or obligations to the public. Therefore, the risk is not only account takeover. Identity theft, false debt notification, public payment requests, promises of tax refunds, or targeted social engineering attempts aimed at company representatives are possible. Records matching corporate email addresses should also be examined in terms of workplace safety and finance department processes.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Users who receive matching notifications should verify any messages appearing to be from the tax authority or public administration directly through a reliable channel. Instead of logging in via incoming links, they should manually type the address of the institution or use official communication channels. Extra caution should be exercised if messages about tax debts, refunds, penalties, registration updates, or public service applications contain requests for payment or documents.\u003C\u002Fp>\n\u003Cp>Users should protect their email accounts with strong passwords and enable two-factor authentication if possible. Even if this breach does not involve passwords, the compromise of an email account can have a greater impact on public services and tax notifications. Personal data should not be shared over phone calls, and requests from people claiming to call on behalf of official institutions should be verified through an independent channel. Company representatives should be informed about the risk of fraudulent instructions in finance and accounting processes.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Bulgarian National Revenue Agency incident shows that the mandatory data held in government institutions is highly sensitive. Individuals should strongly protect the email addresses used in public services, habitually verify messages received from public institutions, and pay attention to channel security when sharing documents containing personal data. Tax, social security, and public payment notifications should always be checked through official channels.\u003C\u002Fp>\n\u003Cp>For institutions, this incident reminds that tax and administrative records should be protected along with access control, network security, data segregation, record retention periods, and incident reporting processes. On the user side, awareness of phishing, email security, two-factor authentication, and the habit of regularly checking financial\u002Fpublic notifications provide long-term protection. Public data leaks can be used for social engineering even years later.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>The presence of a match with the email address in this record indicates that the user is included in one of the records in the Bulgarian National Revenue Agency data set that can be matched by email. The user should first determine whether this email address has been used in public, tax, or corporate transactions. Then, a more careful verification process should be applied for messages related to tax authorities, accounting, finance, and public services.\u003C\u002Fp>\n\u003Cp>A match does not indicate that the user's password or payment card information has been exposed; however, the presence of email, name, phone, physical address, and tax records together is a strong sensitive data alert. Users verifying official institution messages directly through a trusted channel, protecting their email account with two-factor authentication, questioning unexpected payment requests, and using a second approval mechanism in company processes reduce the risks of fraud and phishing that may arise from this breach.\u003C\u002Fp>","","Bulgarian National Revenue Agency Data Breach. 471.2 Thousand reported records were reported. Reported data: Email addresses, Names, Phone numbers. Review the…","\u002Fuploads\u002Flogo\u002Fnap_bg.webp",false,{"name":37,"sector":38,"country":39,"website":9,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":22},"Bulgarian National Revenue Agency","Government tax authority","Bulgaria"]