News: 1710432371

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Record breach of French government exposes up to 43 million people's data

(2024/03/14)


A French government department - responsible for registering and assisting unemployed people - is the latest victim of a mega data breach that compromised the information of up to 43 million citizens.

France Travail announced on Wednesday that it informed the country's data protection watchdog (CNIL) of an incident that exposed a swathe of personal information about individuals dating back 20 years.

The department's [1]statement reveals that names, dates of birth, social security numbers, France Travail identifiers, email addresses, postal addresses, and phone numbers were exposed.

[2]

Passwords and banking details aren't affected, at least.

[3]

[4]

That said, CNIL warned that the data stolen during this incident could be linked to stolen data in other breaches and used to build larger banks of information on any given individual.

It's not clear whether the database's entire contents were stolen by attackers, but the announcement suggests that at least some of the data was extracted.

[5]

"The database allegedly extracted illicitly contains the personal identification data of people currently registered, people previously registered over the last 20 years as well as people not registered on the list of job seekers but having a candidate space on francetravail.fr," the statement reads, which was translated electronically from French.

"It is therefore potentially the personal data of 43 million people which have been exfiltrated."

The Cybercrime Brigade of the Paris Judicial Police Department is heading up the investigation into the breach, which it says was carried out between February 6 and March 5.

[6]

French citizens are urged to remain on heightened alert and vigilant to any phishing attempts in the coming days, weeks, and months. Checking all passwords are strong and not easily crackable is another of the key recommendations.

"Reports indicate the data includes personal identity data, social security numbers, and other physical address data," Joe Hancock, non-lawyer partner and head of the cybersecurity and investigations practice at Mishcon de Reya told The Reg .

"This would seem to have value for identity theft and fraud and is of obvious concern. Often though it is difficult to link a specific breach to actual harm, and individuals may never know if they are impacted.

"It's not clear how the attack happened apart from reports that the attackers posed as members of Cap Emploi. This could indicate some kind of social engineering over a more technical attack, or likely the two together."

Cap Emploi, is a similar department that looks after disabled people looking for work.

France Travail will soon undertake the mammoth task of directly informing those affected by email or by other means, and has apologized for the incident.

"The security of data entrusted by job seekers and companies is a constant concern for us. Faced with the threat of cyberattacks which increasingly weighs on companies and organizations at national and European levels, we must continually strengthen our protection systems, procedures, and instructions," it said.

"Also, as soon as we became aware of this intrusion, we took additional measures with the Cap emploi network to strengthen our systems for protecting access to our applications by our partners."

This data breach is a real stinker for France Travail, which seems to be unable to catch a break. In August last year, it was caught up in an incident at a service provider that also compromised the data of an estimasted 10 million French citizens.

Wider reporting at the time pinned the blamed for the attacks on Cl0p's supply chain assault of [7]MOVEit MFT .

[8]Microsoft confirms Russian spies stole source code, accessed internal systems

[9]Nissan to let 100,000 Aussies and Kiwis know their data was stolen in cyberattack

[10]Swiss cheese security? Play ransomware gang milks government of 65,000 files

[11]Iranian charged over attacks against US defense contractors, government agencies

It's been a tough month for France in terms of cybersecurity and data protection too. Just a month ago, the contry was contending with what was called the largest-ever data breach.

Data breaches at Viamedis and Almerys, two third-party payment providers for healthcare and insurance companies, led to [12]more than 33 million people's data being compromised .

Yann Padova, a data protection lawyer and former secretary general at the CNIL, told Franceinfo at the time that he believed the incident to be the largest of its kind in France.

Affecting more people and including more data points than the breaches of Viamedis and Almerys, the France Travail attack will, for now, be known as the country's worst-ever data breach.

The France Travail attack also comes just days after numerous French government departments were reportedly targeted by DDoS attacks, which were later claimed by the pro-Russia Anonymous Sudan group.

Local media [13]reported on Monday that Prime Minister Gabriel Attal's Office said the attacks were of "unprecedented intensity" but were ultimately contained.

The strikes weren't attributed to the Kremlin, although the cyber nuisances at Anonymous Sudan are believed to act against Russia's enemies.

Perhaps just a coincidence, the attacks also came just days after France President Emmanuel Macron publicly reaffirmed the country's unwavering support for Kyiv in the war against Ukraine. ®

Get our [14]Tech Resources



[1] https://www.francetravail.fr/candidat/soyez-vigilants/cyberattaque-soyez-vigilants.html

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZfMtJ@kNA7D89yBABjtkSwAAAMQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfMtJ@kNA7D89yBABjtkSwAAAMQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfMtJ@kNA7D89yBABjtkSwAAAMQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfMtJ@kNA7D89yBABjtkSwAAAMQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfMtJ@kNA7D89yBABjtkSwAAAMQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2023/11/20/moveit_victim_77m_medical/

[8] https://www.theregister.com/2024/03/08/microsoft_confirms_russian_spies_stole/

[9] https://www.theregister.com/2024/03/14/nissan_oceania_100k_affected/

[10] https://www.theregister.com/2024/03/08/swiss_government_files_ransomware/

[11] https://www.theregister.com/2024/03/01/iranian_cyberattack_charges/

[12] https://www.theregister.com/2024/02/12/infosec_news_roundup/

[13] https://www.france24.com/en/live-news/20240311-french-state-hit-by-intense-cyberattack-pm-s-office

[14] https://whitepapers.theregister.com/



Not again ...

Mike 137

Adversaries masquerading as another government department is an interesting departure, but (as usual) what we haven't been told is what the primary vector was -- e.g. how did the get into the position to be able to masquerade?

I'm becoming convinced that most of these massive breaches are actually pretty trivial to initiate, which reflects badly on the general infosec stance of the victims. We urgently need to beef up our pre-emptive defences, as opposed to continuing in the reactive mode in which infosec still largely seems to be stuck.

Any public cloud is safer

Anonymous Coward

Because any public cloud already has all the data and more. For example people send emails with personal details and never delete them.

Shared implementation of such PII-access over a few big cloud providers would be a much safer solution. The access should be logged and mostly ingress-only, with semi-cold storage, and protection against bulk-downloads.

Why is big cloud safer? Because it has concentrated the best cyber-security experts from all over the World. And no, they are not purely American. Take any Big One, and you will see any country represented.

Some EU countries never appear in the top-hacked list. Maybe good implementations already exist.

Re: Any public cloud is safer

Mike 137

" Why is big cloud safer? Because it has concentrated the best cyber-security experts from all over the World "

But if, as frequently happens, the adversary penetrates your cloud instance via your own endpoints, none of that ostensible super-security of the cloud means diddly. This is a seriously common error -- to assume that because the provider's infrastructure is well protected against attacks on that infrastructure (and it usually is), your security can rely on that as your 'security'. If someone successfully masquerades as one of your employees, they can do whatever that employee is allowed to do with your data (and in fact, probably more in most cases).

Re: Any public cloud is safer

Anonymous Coward

Some EU countries never appear in the top-hacked list. Maybe good implementations already exist.

Some countries just regard privacy as more important than others.

Working in France years ago I received a letter from HR, addressed to me (at work) and clearly labelled Personal and Confidential. Since I wasn't there, the office admin opened it to see if it needed attention. She could not understand why I went ballistic, since it was "only" a letter from HR.

I also remember going to the mairie (town hall) to get some information on a planning application for a field next door to our house. I asked to see the plans for the proposed building, as I was legally entitled to do. The secretary just handed me the entire dossier, complete with name, address and salary/mortgage information for the buyer, noting "the plans will be in there somewhere".

Expert, n.:
Someone who comes from out of town and shows slides.