{"id":2052,"date":"2018-06-01T09:33:18","date_gmt":"2018-06-01T09:33:18","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\/"},"modified":"2018-06-01T09:33:18","modified_gmt":"2018-06-01T09:33:18","slug":"bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\/","title":{"rendered":"BCC is hard, OK? Quite a lot of orgs blurted your email addresses in GDPR mailouts"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2018\/05\/29\/bravo_clap_hipster_shutterstock.jpg?x=1200&amp;y=794\" class=\"ff-og-image-inserted\"\/><\/div>\n<p>Amid the chaos of <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2018\/05\/25\/gdprmageddon_do_you_think_its_all_over_its_not\/\">new European data protection rules<\/a> coming into force at the end of last week, organisations are apparently struggling to grasp even the most basic of technical challenges, sending out non-blinded emails to their users.<\/p>\n<p>Topping the irony charts is ad-blocker Ghostery, which sent users an email with more than 500 addresses in the &#8220;To&#8221; field, the text of which assured them that the biz was on top of the General Data Protection Regulation and had put stringent measures in place to protect their data.<\/p>\n<p>&#8220;We at Ghostery hold ourselves to a high standard when it comes to users&#8217; privacy,&#8221; stated the mass email \u2013 sent to <em>El Reg<\/em> by a reader who described the company &#8220;a shower of pillocks&#8221;.<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\" readability=\"4.4419889502762\">\n<p lang=\"en\" dir=\"ltr\">HELL YES <a href=\"https:\/\/twitter.com\/Ghostery?ref_src=twsrc%5Etfw\">@Ghostery<\/a> JUST SENT ME A GDPR EMAIL WITH FIVE HUNDRED EMAIL ADDRESSES CC&#8217;ED ON IT!! THANKS GHOSTERY!!!! <a href=\"https:\/\/t.co\/y0Xas28wd1\">pic.twitter.com\/y0Xas28wd1<\/a><\/p>\n<p>\u2014 Linguica (@andrewrstine) <a href=\"https:\/\/twitter.com\/andrewrstine\/status\/1000079766123245568?ref_src=twsrc%5Etfw\">May 25, 2018<\/a><\/p><\/blockquote>\n<p>Other users seized the opportunity to offer their services, with one <em>Reg<\/em> reader suggesting that, as a bus driver, they might be better suited to a role at the biz.<\/p>\n<p>&#8220;If a bus driver knows to avoid CC and use BCC instead while you don&#8217;t, I would respectfully suggest that you are in the wrong job,&#8221; the user said in an email addressed to Ghostery. &#8220;May I suggest you resign immediately and that Ghostery should raise their standards by employing former bus drivers in future?&#8221;<\/p>\n<p>The company has since apologised for the error, saying that it had recently stopped using a third-party email automation platform and was managing emails in its own system in a bid to be more secure.<\/p>\n<p>\u201cUnfortunately, due to a technical issue between us and the email sending tool we chose, the GDPR email, which was supposed to be a single email to each recipient was instead sent to a batch of users,\u201d it <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.ghostery.com\/blog\/ghostery-news\/ghostery-email-incident-update\/\">said<\/a>.<\/p>\n<p>&#8220;We are horrified and embarrassed that this happened, and are doing our best to make sure it never happens again.&#8221;<\/p>\n<h3 class=\"crosshead\"><span>Seriously, though, those fields are close together<\/span><\/h3>\n<p>But Ghostery wasn&#8217;t the only company foiled by the most basic of technical issues when trying to brag about their newfound interest in data protection.<\/p>\n<p>Nutrition biz Vitl \u2013 which pushes &#8220;tailor-made&#8221; diet and liefstyle plans \u2013 also experienced a technical hitch, sending out an email to multiple users rather than BCCing them.<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\" readability=\"4.9122807017544\">\n<p lang=\"en\" dir=\"ltr\">Oh dear <a href=\"https:\/\/twitter.com\/VITLhealth?ref_src=twsrc%5Etfw\">@VITLhealth<\/a> cares about our privacy, yet doesn&#8217;t seem to mind giving everyone&#8217;s email address out to complete strangers- awkward <a href=\"https:\/\/twitter.com\/hashtag\/oops?src=hash&amp;ref_src=twsrc%5Etfw\">#oops<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/gdpr?src=hash&amp;ref_src=twsrc%5Etfw\">#gdpr<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/gdprfail?src=hash&amp;ref_src=twsrc%5Etfw\">#gdprfail<\/a> <a href=\"https:\/\/t.co\/KLUY62nzrN\">pic.twitter.com\/KLUY62nzrN<\/a><\/p>\n<p>\u2014 Ash Stronge (@ashstronge) <a href=\"https:\/\/twitter.com\/ashstronge\/status\/999654577703215105?ref_src=twsrc%5Etfw\">May 24, 2018<\/a><\/p><\/blockquote>\n<p>The firm apologised to the &#8220;small number&#8221; of affected users, although it tried to do so without trumpeting it \u2013 an idea that infuriated users, with one posting the apology note in full:<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\" readability=\"9.7256097560976\">\n<p lang=\"en\" dir=\"ltr\">Well nothing that couldn\u2019t have been said openly on Twitter. \u201cSmall number\u201d is a cop out, I\u2019ve seen a few people mentioning it on Twitter, and no matter how small, it is serious! And what point is there in me contacting them, the damage has been done. <a href=\"https:\/\/t.co\/9eY43Rh1m5\">pic.twitter.com\/9eY43Rh1m5<\/a><\/p>\n<p>\u2014 Chris Kyle (@ChrisPKyle) <a href=\"https:\/\/twitter.com\/ChrisPKyle\/status\/999766637896138752?ref_src=twsrc%5Etfw\">May 24, 2018<\/a><\/p><\/blockquote>\n<p>Elsewhere, users have reported GDPR email fails from <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/order-order.com\/2018\/05\/25\/corbynista-mp-marks-gdpr-day-constituents-data-breach\/\">MPs<\/a>, university computing clubs, <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/twitter.com\/spillanemike\/status\/999720320863997952\">restaurants<\/a>, shops, <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/twitter.com\/bettywiderski\/status\/999068883993624576\/photo\/1\">writers&#8217; groups<\/a> and <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/twitter.com\/jon_pratty\/status\/999653804965597184\">local councils<\/a>, including <a target=\"_blank\" href=\"http:\/\/www.bbc.co.uk\/news\/uk-england-sussex-44241494\">Hastings<\/a> Borough Council.<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\" readability=\"6.0493827160494\">\n<p lang=\"en\" dir=\"ltr\">Received a GDPR email from my old university computing society. They didn&#8217;t BCC people when sending it out or send it as individual emails. Received 1000 ex\/current member emails. <a href=\"https:\/\/twitter.com\/hashtag\/ffs?src=hash&amp;ref_src=twsrc%5Etfw\">#ffs<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/gdpr?src=hash&amp;ref_src=twsrc%5Etfw\">#gdpr<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/amateurhour?src=hash&amp;ref_src=twsrc%5Etfw\">#amateurhour<\/a><\/p>\n<p>\u2014 Mike P (@mike_palfrey) <a href=\"https:\/\/twitter.com\/mike_palfrey\/status\/999741125907943424?ref_src=twsrc%5Etfw\">May 24, 2018<\/a><\/p><\/blockquote>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\" readability=\"6.4489795918367\">\n<p lang=\"en\" dir=\"ltr\">One of our suppliers just sent us an email, addressed to all of their customers, about GDPR. They forgot to BCC all 720 email addresses. <a href=\"https:\/\/t.co\/xnQYsmW2c8\">pic.twitter.com\/xnQYsmW2c8<\/a><\/p>\n<p>\u2014 Pete (@Kibbled) <a href=\"https:\/\/twitter.com\/Kibbled\/status\/999282068369666048?ref_src=twsrc%5Etfw\">May 23, 2018<\/a><\/p><\/blockquote>\n<p>Although some decided not to name and shame the <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/twitter.com\/keiblob\/status\/999544080110641152\">smaller firms<\/a> that had made the error \u2013 the bigger organisations didn\u2019t get off so lightly.<\/p>\n<p>That includes the <em>New York Times<\/em>, which \u2013 according to <a target=\"_blank\" href=\"https:\/\/twitter.com\/CindyOtis_\/status\/1000168481403359233\">multiple<\/a> <a target=\"_blank\" href=\"https:\/\/twitter.com\/AndrewRLewis\/status\/1000192732705558529\">Twitter<\/a> <a target=\"_blank\" href=\"https:\/\/twitter.com\/samueloakford\/status\/1000210367103094784\">users<\/a> \u2013 accidentally cc&#8217;d a number of freelancers and vendors into its GDPR notice, unleashing upon the unwitting recipients a flurry of reply-all emails to add to the existing pile of GDPR missives.<\/p>\n<p>However, showing that there&#8217;s nearly always a silver lining if you look hard enough, some saw this sort of mistake as a possible networking opportunity.<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\" readability=\"6.7878787878788\">\n<p lang=\"en\" dir=\"ltr\">Vendor, not customers. Essentially all the freelancers. The list is now organizing drinks in some cities. \ud83d\ude00 I still haven\u2019t replied all. I should, right? Right? <a href=\"https:\/\/t.co\/pxHOQhfc39\">https:\/\/t.co\/pxHOQhfc39<\/a><\/p>\n<p>\u2014 zeynep tufekci (@zeynep) <a href=\"https:\/\/twitter.com\/zeynep\/status\/1000175313488248832?ref_src=twsrc%5Etfw\">May 26, 2018<\/a><\/p><\/blockquote>\n<p>The foul-ups follow a series of US websites \u2013 including newspapers owned by Tronc \u2013 <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2018\/05\/25\/tronc_chicago_tribune_la_times_gdpr_lock_out_eu_users\/\">shutting down services for EU users<\/a> on Friday, in an attempt to dodge the much-publicised \u2013 and overblown \u2013 megabucks fines touted by many ahead of the enforcement date. \u00ae<\/p>\n<p class=\"wptl btm\"><span>Sponsored:<\/span> <a href=\"https:\/\/go.theregister.co.uk\/tl\/1759\/shttp:\/\/www.mcubed.london\/\">Minds Mastering Machines &#8211; Call for papers now open<\/a><\/p>\n<p>READ MORE <a href=\"http:\/\/go.theregister.com\/feed\/www.theregister.co.uk\/2018\/05\/29\/bcc_is_hard_okay_organisations_blab_email_addresses_in_gdpr_mailouts\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ad blocker Ghostery, UK councils, vitamin sellers all in the blabtastic mix Amid the chaos of new European data protection rules coming into force at the end of last week, organisations are apparently struggling to grasp even the most basic of technical challenges, sending out non-blinded emails to their users.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":2053,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-2052","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>BCC is hard, OK? Quite a lot of orgs blurted your email addresses in GDPR mailouts 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"BCC is hard, OK? Quite a lot of orgs blurted your email addresses in GDPR mailouts 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2018-06-01T09:33:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/06\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"794\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"BCC is hard, OK? Quite a lot of orgs blurted your email addresses in GDPR mailouts\",\"datePublished\":\"2018-06-01T09:33:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\\\/\"},\"wordCount\":806,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/06\\\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\\\/\",\"name\":\"BCC is hard, OK? Quite a lot of orgs blurted your email addresses in GDPR mailouts 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/06\\\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts.jpg\",\"datePublished\":\"2018-06-01T09:33:18+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/06\\\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/06\\\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts.jpg\",\"width\":1200,\"height\":794},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"BCC is hard, OK? Quite a lot of orgs blurted your email addresses in GDPR mailouts\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"BCC is hard, OK? Quite a lot of orgs blurted your email addresses in GDPR mailouts 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\/","og_locale":"en_US","og_type":"article","og_title":"BCC is hard, OK? Quite a lot of orgs blurted your email addresses in GDPR mailouts 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2018-06-01T09:33:18+00:00","og_image":[{"width":1200,"height":794,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/06\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"BCC is hard, OK? Quite a lot of orgs blurted your email addresses in GDPR mailouts","datePublished":"2018-06-01T09:33:18+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\/"},"wordCount":806,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/06\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\/","url":"https:\/\/www.threatshub.org\/blog\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\/","name":"BCC is hard, OK? Quite a lot of orgs blurted your email addresses in GDPR mailouts 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/06\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts.jpg","datePublished":"2018-06-01T09:33:18+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/06\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/06\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts.jpg","width":1200,"height":794},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/bcc-is-hard-ok-quite-a-lot-of-orgs-blurted-your-email-addresses-in-gdpr-mailouts\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"BCC is hard, OK? Quite a lot of orgs blurted your email addresses in GDPR mailouts"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/2052","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=2052"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/2052\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/2053"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=2052"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=2052"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=2052"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}