Imagine you hide your house key under a specific rock in your garden. A stranger who speaks only Italian asks your French-speaking neighbor where the key is — and the neighbor, who has never seen the key, somehow points to the right rock. That is the core finding here: LLMs memorize PII during English pre-training, and prompts translated into Italian, Spanish, French, or German can extract that same PII, even when the translated prompts never appeared online. The committed claim: Training Data Extraction (TDE) attacks transfer cross-lingually. The authors build a multi-domain PII dataset — social media handles, email addresses, phone numbers — embed them in English attack prompts, then translate those prompts into four European languages. Both English-centric and multilingual models leak PII when prompted in the non-English translations. A web-presence check on the translated prompts confirms they are not available online, ruling out the possibility that the model simply memorized the translated version. The mechanism is not surface-level pattern matching. The authors analyze model activations and find that different translations of the same prompt converge to similar internal representations, with the strongest alignment occurring in the middle layers. This means multilingual pre-training builds latent cross-linguistic bridges — shared representational spaces — that act as highways for PII retrieval regardless of prompt language. The more multilingual the model, the higher the share of English leaks recoverable in other languages. When the original English wording is paraphrased (even without changing language), the leak rate drops sharply, confirming that the bridge depends on semantic-structural alignment, not just topic overlap. On the ladder: prior TDE work (Carlini et al., Huang et al.) has demonstrated memorization extraction in English, and some work has probed multilingual safety alignment failures, but systematic cross-lingual PII extraction with controlled web-presence checks is genuinely new territory. The authors don't claim to beat a SOTA metric — this is a vulnerability demonstration, not a benchmark race. The closest comparators are monolingual TDE papers that did not test language transfer. The validation regime is solid but bounded. The dataset is constructed (not a community benchmark), the web-presence check is a strong methodological addition, and the activation analysis provides mechanistic evidence beyond just observing leaks. However, exact model names, parameter counts, and per-language recovery rates are described in aggregate terms in the abstract — the full paper would need to supply precise numbers for independent replication. No code release is mentioned. The milestone that matters: current work demonstrates the phenomenon on a handful of European languages structurally close to English. The real test is whether the same bridges exist for typologically distant languages — Chinese, Arabic, Swahili — where surface and syntactic overlap with English is minimal. If cross-lingual PII extraction works across language families, every existing alignment and sanitization strategy is insufficient by design. If it only works for Romance/Germanic languages, the threat is serious but narrower. The obvious experiment not run: testing on languages outside the Indo-European family. The honest read is (a) — the authors likely lacked resources or suitable PII datasets for non-European languages, and the Indo-European scope was already a substantial contribution. But this is exactly the experiment that would turn a strong finding into a field-reshaping one.