Cyber-attack in Hauts-de-France: data of 700,000 people stolen from Atexo and Docaposte
Two service providers in the Hauts-de-France region were hacked, resulting in the theft of personal data belonging to several hundred thousand people.

Massive personal data theft following cyber-attack on two regional service providers
Two service providers in the Hauts-de-France region fell victim to cyber-attacks, causing the theft of personal data belonging to several thousand people, according to franceinfo.fr citing a statement published on Saturday 3 October by the Region. The region announced it would be filing a complaint with the relevant authorities.
The two companies targeted are Atexo, a software publisher for public authorities, and Docaposte, a subsidiary of La Poste specialising in the management of professional document exchanges. According to the Region, the data potentially stolen includes "names, forenames, email addresses, as well as potentially bank account details (RIB) and other identification data".
Up to 700,000 people affected according to specialist website
The site FrenchBreaches, specialising in documenting data breaches, claims to have found data posted on a cybercriminal forum on Saturday. It refers to 700,000 people being affected. Among the hacked documents would be apprenticeship contracts, bank account details and housing certificates.
According to FrenchBreaches, the information would have been extracted from the Génération#HDF service, a card intended for secondary school pupils and apprentices to finance the purchase of textbooks or educational materials. Other files would be linked to regional subsidies and support for project initiators and entrepreneurs.
The Region specified that Atexo managed and hosted the regional subsidies platform, whilst Docaposte was responsible for the Carte Génération#HDF platform. The "Maison des entrepreneurs Hauts-de-France" platform was also affected, but the Region states that this incident "has now been resolved".
Political figures among exposed data
On a search engine for hacked data, personal information belonging to Édouard Philippe, Marine Tondelier and François Ruffin was identified, mixed in with that of anonymous individuals.
Platforms suspended, investigation underway
"The service providers have identified the vulnerabilities as well as the attacker's method of operation and have undertaken remedial work," the Region stated on Saturday evening. The two hacked platforms are "temporarily suspended" pending investigations and corrections, which "affects access to the services concerned," the authority specifies.
Investigations are continuing to "determine the exact number of people affected" and establish whether other data was extracted. "The platforms concerned have been closed and users have been informed by the Region" from Friday onwards, it added.
The National Agency for Information Systems Security (Anssi) was alerted to the incident.
Source: Google News LU FR