Hello DarkForums! :3 Today i have uploaded the database of Polish political party 'Nowa Nadzieja'.
![[Image: NowaNadzieja_Logo_2.png]](https://wolnosc.pl/wp-content/uploads/2022/11/NowaNadzieja_Logo_2.png)
In March 2025, the attacker @poisonivy3 gained access to a database of people who sent donations to
the Polish Political party 'Nowa Nadzieja' through a misconfigured, completly open API
. This database is very sensitive because it contains
a 'PESEL' number. In addition, the database unfortunately contains data of minors,
I hope that the people responsible for configuring the API will be punished for this.
I also inform you that during the hack I noticed files with messages written in Polish
'no GDPR, no fun', which means that the people responsible for maintaining the server knew about
the vulnerability.
As a bonus, Im also doxxing some politicians from 'Nowa Nadzieja' - Grzegorz Placzek, Tomasz Brzezina and few more
3,3K DATABASE ROWS: email, pesel, first_name, last_name, city, fee, gdpr consent (lol)
DOXX ROWS: pesel, first_name, last_name, email, ip, passwords, usernames, password_hashes, socials
If the link stops working, check the posts at the bottom, I'll do an update
Sample:
![[Image: NowaNadzieja_Logo_2.png]](https://wolnosc.pl/wp-content/uploads/2022/11/NowaNadzieja_Logo_2.png)
In March 2025, the attacker @poisonivy3 gained access to a database of people who sent donations to
the Polish Political party 'Nowa Nadzieja' through a misconfigured, completly open API

a 'PESEL' number. In addition, the database unfortunately contains data of minors,
I hope that the people responsible for configuring the API will be punished for this.
I also inform you that during the hack I noticed files with messages written in Polish
'no GDPR, no fun', which means that the people responsible for maintaining the server knew about
the vulnerability.
As a bonus, Im also doxxing some politicians from 'Nowa Nadzieja' - Grzegorz Placzek, Tomasz Brzezina and few more

3,3K DATABASE ROWS: email, pesel, first_name, last_name, city, fee, gdpr consent (lol)
DOXX ROWS: pesel, first_name, last_name, email, ip, passwords, usernames, password_hashes, socials
If the link stops working, check the posts at the bottom, I'll do an update
Sample:
Code:
/var/www/html/PayByNet/common/../Array
(
[email] => g.placzek@post.pl
[rodo] => Wyrażam zgodę na przetwarzanie danych osobowych przez Nową Nadzieję
[district] => Okręg nr 31 (Katowice)
[donation] =>
[fee] => 60
[citizen] => Oświadczam, że jestem obywatelem polskim mającym stałe miejsce zamieszkanie na terenie Rzeczypospolitej Polskiej
[pesel] => 78051301357
[name] => Grzegorz Płaczek
)
/var/www/html/PayByNet/common/../Array
(
[email] => wmiszczyk@wp.pl
[rodo] => Wyrażam zgodę na przetwarzanie danych osobowych przez Nową Nadzieję
[district] => Okręg nr 1 (Legnica)
[donation] =>
[fee] => 60
[citizen] => Oświadczam, że jestem obywatelem polskim mającym stałe miejsce zamieszkanie na terenie Rzeczypospolitej Polskiej
[pesel] => 77060106278
[name] => Wojciech Miszczyk
)
/var/www/html/PayByNet/common/../Array
(
[email] => justyna.chm@outlook.com
[rodo] => Wyrażam zgodę na przetwarzanie danych osobowych przez Nową Nadzieję
[district] => Okręg nr 31 (Katowice)
[donation] =>
[fee] => 60
[citizen] => Oświadczam, że jestem obywatelem polskim mającym stałe miejsce zamieszkanie na terenie Rzeczypospolitej Polskiej
[pesel] => 92111308083
[name] => Justyna Gosławska