DPO PARTAGE
No Result
View All Result
  • Login
  • Accueil
  • Cybersécurité
    Cyber threat Overview 2021

    Cyber threat Overview 2021 – CERT-FR

  • Trouver un DPO
  • Secteurs d’activité
  • Contact
Premium
S'INSCRIRE
  • Accueil
  • Cybersécurité
    Cyber threat Overview 2021

    Cyber threat Overview 2021 – CERT-FR

  • Trouver un DPO
  • Secteurs d’activité
  • Contact
No Result
View All Result
DPO PARTAGE
No Result
View All Result
Home Data Breach

Thales is attempting to improve its image by presenting a transparency operation following a cyber attack that compromised three user accounts and downloaded 9 GB of data.

by Laurent de Cavel - DPO
8 March 2026
in Data Breach
Reading Time: 3 mins read
0
Thales attaque informatique

Thales attaque informatique

A lire aussi sur DPO PARTAGE

Data Breach at DecathlonThe Critical Importance of Cybersecurity Highlighted by the Recent Data Breach Involving Nearly 8,000 Employees and Customers of DecathlonData Breach at Decathlon

Pepsi Bottling Ventures LLC suffered a data breach.

Cyberattacks: How to protect your SME in 3 points

Thales Cyber Attack by LockBit : French electronics and defense giant Thales has revealed details of the cyber attack it suffered in October and November 2022. The crisis began on October 31, 2022, but Thales said that the start of the incident was a few weeks earlier. According to the company, the crisis was rooted in the theft of three user accounts in mid-August 2022. Login credentials of three user accounts for a portal used to communicate with a partner were stolen.

Thales Cyber Attack by LockBit

Thales is not certain how these three accounts were compromised, but it is leaning towards two possibilities: either access was obtained through reuse of a password used on a hacked third-party site, or a terminal with browser access was hacked to access password syncing. A few weeks later, access to these three accounts was sold on the dark web. Two of the three accounts belonged to insiders and access to these two compromised internal accounts was immediately blocked. But the purchase of the third user account, which belonged to its industrial partner, went unnoticed by Thales.

The hackers then spent five days exploring the portal and data they had access to, before downloading around 9 GB of data from a European hosting server, which was the volume of data accessible to Thales’ partner. The LockBit hacking group claimed responsibility for the attack on its website the day before a public holiday. Thales ruled out the possibility of intrusion into its information systems and the deployment of ransomware, in favor of the hypothesis of data theft. The stolen files, approximately 400 unique files, were mostly from the compromised portal. However, a small portion of the archive, less than 1 GB, was from another theft and was more than two years old.

Thales suspects that the stolen data came from an internal or external operator of the company at the beginning of the Covid-19 pandemic. According to Stéphane Lenco, Thales’ director of information systems security, this could correspond to data taken in an emergency by an employee who had to leave their office hastily. The stolen data is considered to be of little sensitivity, internally classified as level two data, which corresponds to non-public data, but shared with partners.

One point remains unclear for the company: what was the precise motive of the LockBit hackers? The hackers did not directly demand a ransom from the French company, and the usual links to buy extra time to avoid disclosure of stolen data were not present. Thales thinks that LockBit may have wanted to generate free publicity with this attack. Another hypothesis formulated is that this was an operation ultimately aimed at manipulating the company’s stock price, or was it a targeted attack on a European defense company, a sector under pressure since the beginning of the Russian military invasion in Ukraine? Whatever the motive of the hackers, Thales hopes that this transparency exercise will help restore its reputation. The company has presented an informative post-mortem to the press, which highlights the limitations of its surveillance, but also the speed of its response to the attack.

A lire aussi sur le meme sujet :

  • How to comply with GDPR principles when deleting user accounts on an e-commerce website
  • GoDaddy reveals that a data breach led to the presence of malware on its customers’ websites.
  • Thales tente de redorer son image en présentant une opération de transparence après une attaque informatique qui a compromis trois comptes utilisateurs et téléchargé 9 Go de données.
Tweet286Share80
Previous Post

Anticipating the Cyber Resilience Act: A Must for IoT Manufacturers

Next Post

Google is rolling out the beta version of Privacy Sandbox for Android, which marks the end of targeted advertising on Android devices

Laurent de Cavel - DPO

Looking for a DPO? Entrust your mission to DPO PARTAGE - Contact us at +1 813 768 3616or by email at contact@dpo-partage.fr. DPO PARTAGE is the leader in DPO services for health and sensitive data.

Related Posts

Data Breach at Decathlon
Data Breach

Data Breach at DecathlonThe Critical Importance of Cybersecurity Highlighted by the Recent Data Breach Involving Nearly 8,000 Employees and Customers of DecathlonData Breach at Decathlon

7 March 2026
Pepsi data breach.
Data Breach

Pepsi Bottling Ventures LLC suffered a data breach.

7 March 2026
Cyberattacks protect SMEs
Cyberattacks

Cyberattacks: How to protect your SME in 3 points

8 March 2026
vulnerability in Joomla
Data Breach

Risk of critical vulnerability in Joomla!: How to protect your data?

8 March 2026
asml
Data Breach

ASML accused of data theft by China.

8 March 2026
GoDaddy data breach
Data Breach

GoDaddy reveals that a data breach led to the presence of malware on its customers’ websites.

8 March 2026
Next Post
Privacy Sandbox sur Android

Google is rolling out the beta version of Privacy Sandbox for Android, which marks the end of targeted advertising on Android devices

La pseudonymisation et l'anonymisation sont deux méthodes différentes de protection de la vie privée des individus.

How Trickgate Circumvents EDR Protection: Check Point Unveils Sophisticated Cybercriminal Tool

APPLICATION RGPD

Démo gratuite

Découvrez DPO SUITE

Gérez votre conformité RGPD de A à Z avec une solution qui anticipe les évolutions réglementaires, sans effort supplémentaire.

Rappel par un expert dans les prochaines minutes

Vos données sont traitées pour répondre à votre demande. En savoir plus.

Demande envoyée !

Un expert DPO PARTAGE vous rappelle
dans les prochaines minutes.

Articles recommandés

EU regulation

Five years after the GDPR, the EU seeks to strengthen its data protection against large technology companies.

8 March 2026
GDPR in EUROPE

GDPR in Europe: subtleties to know in France, Spain, and Germany.

8 March 2026
health data hosting in France

Navigating the Regulatory Landscape of Health Data Hosting: A Comparison of France and the United States with Advice for American Companies

7 March 2026

Articles populaires

    DPO PARTAGE DPO externalisé

    DPO Partage se positionne comme un acteur clé dans le domaine de la protection des données personnelles, en offrant une gamme complète de services axés sur le Règlement Général sur la Protection des Données (RGPD). Notre structure fournit des informations régulières et pointues sur les dernières évolutions et exigences du RGPD, ce qui en fait une ressource précieuse pour les entreprises soucieuses de se conformer à la législation.

    Faites appel à DPO PARTAGE pour votre conformité RGPD.
    Contactez nous au 01 83 64 42 98
    En savoir plus »

    Recent Posts

    • Xerox Corp is reportedly the victim of a major cyberattack.
    • Navigating the Regulatory Landscape of Health Data Hosting: A Comparison of France and the United States with Advice for American Companies
    • Turning GDPR Compliance into Competitive Advantage: Unveiling the New Guide for American Enterprises
    • Web Analytics and GDPR Compliance: How Website Hosts Can Adhere in France
    • Data Breach at DecathlonThe Critical Importance of Cybersecurity Highlighted by the Recent Data Breach Involving Nearly 8,000 Employees and Customers of DecathlonData Breach at Decathlon
    • Mentions Légales
    • Politique de confidentialité
    • Politique cookies DPO Partagé
    • Nous contacter
    • Politique de cookies (UE)
    SITE AUDITÉRGPDAudit automatiséby DPO-FRANCE

    © 2026 DPO PARTAGE - Pilote de votre conformité RGPD

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In
    Question ?

    Question ?

    Comment pouvons-nous vous aider ?

    Être rappelé

    Vos données sont traitées conformément au RGPD.

    Voir une démo

    Vos données sont traitées conformément au RGPD.

    Demander un devis

    Vos données sont traitées conformément au RGPD.

    Demande envoyée !

    Nous reviendrons vers vous très rapidement.

    Une erreur est survenue

    Veuillez réessayer ou nous contacter directement.