When national IDs were issued each one got a "tramite number" that I'm guessing was sequentially assigned when the physical ID cards where issued.
Because this number is vaguely random and is printed on the actual physical ID card, it was used as a password on government apps (for example, for getting authorization to move around during covid). To log into the app, you enter your national ID number and then the "tramite number" that is printed on your physical ID card.
Of course, the number can't be changed, and is stored in plaintext in a large database somewhere. It therefore makes for a horrible password.
The database in question just got stolen, and the aforementioned apps now include all sorts of sensitive PII.