DPO PARTAGE
No Result
View All Result
  • Login
  • Accueil
  • Cybersécurité
    Cyber threat Overview 2021

    Cyber threat Overview 2021 – CERT-FR

  • Votre conformité RGPD (Tarifs)
  • Secteurs d’activité
  • Contact
Premium
S'INSCRIRE
  • Accueil
  • Cybersécurité
    Cyber threat Overview 2021

    Cyber threat Overview 2021 – CERT-FR

  • Votre conformité RGPD (Tarifs)
  • Secteurs d’activité
  • Contact
No Result
View All Result
DPO PARTAGE
No Result
View All Result
Home Data Breach

Thales is attempting to improve its image by presenting a transparency operation following a cyber attack that compromised three user accounts and downloaded 9 GB of data.

Hackers stole three user accounts from Thales, a French electronics and defense company, in mid-August 2022. The hackers then downloaded around 9 GB of data, which they claimed on October 31, 2022. Thales presented the attack as a transparency operation aimed at restoring its image.

DPO Partagé by DPO Partagé
18 February 2023
in Data Breach
Reading Time: 2 mins read
0
Thales attaque informatique

Thales attaque informatique

Sommaire

Toggle
    • Data Breach at DecathlonThe Critical Importance of Cybersecurity Highlighted by the Recent Data Breach Involving Nearly 8,000 Employees and Customers of DecathlonData Breach at Decathlon
    • Pepsi Bottling Ventures LLC suffered a data breach.
    • Cyberattacks: How to protect your SME in 3 points
  • Thales Cyber Attack by LockBit

Thales Cyber Attack by LockBit : French electronics and defense giant Thales has revealed details of the cyber attack it suffered in October and November 2022. The crisis began on October 31, 2022, but Thales said that the start of the incident was a few weeks earlier. According to the company, the crisis was rooted in the theft of three user accounts in mid-August 2022. Login credentials of three user accounts for a portal used to communicate with a partner were stolen.

A lire aussi sur DPO PARTAGE

Data Breach at DecathlonThe Critical Importance of Cybersecurity Highlighted by the Recent Data Breach Involving Nearly 8,000 Employees and Customers of DecathlonData Breach at Decathlon

Pepsi Bottling Ventures LLC suffered a data breach.

Cyberattacks: How to protect your SME in 3 points

Thales Cyber Attack by LockBit

Thales is not certain how these three accounts were compromised, but it is leaning towards two possibilities: either access was obtained through reuse of a password used on a hacked third-party site, or a terminal with browser access was hacked to access password syncing. A few weeks later, access to these three accounts was sold on the dark web. Two of the three accounts belonged to insiders and access to these two compromised internal accounts was immediately blocked. But the purchase of the third user account, which belonged to its industrial partner, went unnoticed by Thales.

The hackers then spent five days exploring the portal and data they had access to, before downloading around 9 GB of data from a European hosting server, which was the volume of data accessible to Thales’ partner. The LockBit hacking group claimed responsibility for the attack on its website the day before a public holiday. Thales ruled out the possibility of intrusion into its information systems and the deployment of ransomware, in favor of the hypothesis of data theft. The stolen files, approximately 400 unique files, were mostly from the compromised portal. However, a small portion of the archive, less than 1 GB, was from another theft and was more than two years old.

Thales suspects that the stolen data came from an internal or external operator of the company at the beginning of the Covid-19 pandemic. According to Stéphane Lenco, Thales’ director of information systems security, this could correspond to data taken in an emergency by an employee who had to leave their office hastily. The stolen data is considered to be of little sensitivity, internally classified as level two data, which corresponds to non-public data, but shared with partners.

One point remains unclear for the company: what was the precise motive of the LockBit hackers? The hackers did not directly demand a ransom from the French company, and the usual links to buy extra time to avoid disclosure of stolen data were not present. Thales thinks that LockBit may have wanted to generate free publicity with this attack. Another hypothesis formulated is that this was an operation ultimately aimed at manipulating the company’s stock price, or was it a targeted attack on a European defense company, a sector under pressure since the beginning of the Russian military invasion in Ukraine? Whatever the motive of the hackers, Thales hopes that this transparency exercise will help restore its reputation. The company has presented an informative post-mortem to the press, which highlights the limitations of its surveillance, but also the speed of its response to the attack.

Audit RGPD / Conformité RGPD Audit RGPD / Conformité RGPD Audit RGPD / Conformité RGPD
ADVERTISEMENT
Tweet52Share14
Previous Post

Anticipating the Cyber Resilience Act: A Must for IoT Manufacturers

Next Post

Google is rolling out the beta version of Privacy Sandbox for Android, which marks the end of targeted advertising on Android devices

DPO Partagé

DPO Partagé

Looking for a DPO? Entrust your mission to DPO PARTAGE - Contact us at +33 (0)7 56 94 70 90 or by email at contact@dpo-partage.fr. DPO PARTAGE is the leader in DPO services for health and sensitive data.

Related Posts

Data Breach at Decathlon
Data Breach

Data Breach at DecathlonThe Critical Importance of Cybersecurity Highlighted by the Recent Data Breach Involving Nearly 8,000 Employees and Customers of DecathlonData Breach at Decathlon

18 October 2023
Pepsi data breach.
Data Breach

Pepsi Bottling Ventures LLC suffered a data breach.

2 March 2023
Cyberattacks protect SMEs
Cyberattacks

Cyberattacks: How to protect your SME in 3 points

28 February 2023
vulnerability in Joomla
Data Breach

Risk of critical vulnerability in Joomla!: How to protect your data?

6 March 2023
asml
Data Breach

ASML accused of data theft by China.

19 February 2023
GoDaddy data breach
Data Breach

GoDaddy reveals that a data breach led to the presence of malware on its customers’ websites.

12 January 2024
Next Post
Privacy Sandbox sur Android

Google is rolling out the beta version of Privacy Sandbox for Android, which marks the end of targeted advertising on Android devices

La pseudonymisation et l'anonymisation sont deux méthodes différentes de protection de la vie privée des individus.

How Trickgate Circumvents EDR Protection: Check Point Unveils Sophisticated Cybercriminal Tool

DPO PARTAGE

Votre partenaire pilote de votre
conformité RGPD
  • - DPO Externalisé
  • - Audit Conformité RGPD
  • - Application Conformité RGPD
  • - Devis missions RGPD

Pour toute question
01 83 64 42 98.

Articles recommandés

La pseudonymisation et l'anonymisation sont deux méthodes différentes de protection de la vie privée des individus.

How Trickgate Circumvents EDR Protection: Check Point Unveils Sophisticated Cybercriminal Tool

18 February 2023
analysis on pornographic sites

Facial analysis for accessing pornographic sites: CNIL is pragmatic and requires guarantees for the protection of personal data.

1 March 2023
Fog of War

Fog of War: The Cyber Impacts of the Ukrainian Conflict

18 February 2023

Articles populaires

    DPO PARTAGE DPO externalisé

    DPO Partage se positionne comme un acteur clé dans le domaine de la protection des données personnelles, en offrant une gamme complète de services axés sur le Règlement Général sur la Protection des Données (RGPD). Notre structure fournit des informations régulières et pointues sur les dernières évolutions et exigences du RGPD, ce qui en fait une ressource précieuse pour les entreprises soucieuses de se conformer à la législation.

    Faites appel à DPO PARTAGE pour votre conformité RGPD.
    Contactez nous au 01 83 64 42 98
    En savoir plus »

    Recent Posts

    • Xerox Corp is reportedly the victim of a major cyberattack.
    • Navigating the Regulatory Landscape of Health Data Hosting: A Comparison of France and the United States with Advice for American Companies
    • Turning GDPR Compliance into Competitive Advantage: Unveiling the New Guide for American Enterprises
    • Web Analytics and GDPR Compliance: How Website Hosts Can Adhere in France
    • Data Breach at DecathlonThe Critical Importance of Cybersecurity Highlighted by the Recent Data Breach Involving Nearly 8,000 Employees and Customers of DecathlonData Breach at Decathlon
    • Mentions Légales
    • Politique de confidentialité
    • Politique cookies DPO Partagé
    • Nous contacter
    • Politique de cookies (UE)

    © 2024 DPO PARTAGE - Pilote de votre conformité RGPD

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In
    Gérer le consentement aux cookies
    Pour offrir les meilleures expériences, nous utilisons des technologies telles que les cookies pour stocker et/ou accéder aux informations des appareils. Le fait de consentir à ces technologies nous permettra de traiter des données telles que le comportement de navigation ou les ID uniques sur ce site. Le fait de ne pas consentir ou de retirer son consentement peut avoir un effet négatif sur certaines caractéristiques et fonctions.
    Fonctionnel Always active
    Le stockage ou l’accès technique est strictement nécessaire dans la finalité d’intérêt légitime de permettre l’utilisation d’un service spécifique explicitement demandé par l’abonné ou l’utilisateur, ou dans le seul but d’effectuer la transmission d’une communication sur un réseau de communications électroniques.
    Préférences
    Le stockage ou l’accès technique est nécessaire dans la finalité d’intérêt légitime de stocker des préférences qui ne sont pas demandées par l’abonné ou l’utilisateur.
    Statistiques
    Le stockage ou l’accès technique qui est utilisé exclusivement à des fins statistiques. Le stockage ou l’accès technique qui est utilisé exclusivement dans des finalités statistiques anonymes. En l’absence d’une assignation à comparaître, d’une conformité volontaire de la part de votre fournisseur d’accès à internet ou d’enregistrements supplémentaires provenant d’une tierce partie, les informations stockées ou extraites à cette seule fin ne peuvent généralement pas être utilisées pour vous identifier.
    Marketing
    Le stockage ou l’accès technique est nécessaire pour créer des profils d’utilisateurs afin d’envoyer des publicités, ou pour suivre l’utilisateur sur un site web ou sur plusieurs sites web ayant des finalités marketing similaires.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    Voir les préférences
    • {title}
    • {title}
    • {title}
    No Result
    View All Result
    • Accueil
    • Cybersécurité
    • Votre conformité RGPD (Tarifs)
    • Secteurs d’activité
    • Contact

    © 2024 DPO PARTAGE - Pilote de votre conformité RGPD

    Are you sure want to unlock this post?
    Unlock left : 0
    Are you sure want to cancel subscription?