Gîtes de France: 389,000 customers hit by personal data breach

Gîtes de France suffered a major cyberattack ahead of the summer season, exposing the data of over 389,000 customers. No banking details were compromised, but experts warn of the risks of fraud and burglaries.

Gîtes de France: 389,000 customers hit by personal data breach

Cyberattack at Gîtes de France: data of 389,000 customers exposed

More than 389,000 customers of Gîtes de France had their personal data stolen in a large-scale cyberattack, revealed on Saturday by the French Breaches website and confirmed on Sunday 17 May by the organisation itself. The attack comes a few weeks before the start of the summer holidays, according to France Info.

No banking information was compromised in this intrusion. The stolen data was limited to the names of occupants, dates of birth, telephone numbers and information relating to reserved stays.

Gaëlle Cuntz, president of Gîtes de France in Val-d'Oise, sought to reassure affected customers: "The data that was hacked is not only banking data. We are pleased that it did not go that far. Everyone is on the case, the network is securing things and they have people to respond to them." Affected customers were to be informed from Monday onwards.

Two major risks identified by an expert

Although no bank accounts were directly emptied, the stolen information is sufficient to expose customers to two serious threats, according to Clément Domingo, a cybersecurity expert.

"The first risk is that people will receive a phone call from individuals posing as their next holiday destination, offering them a very attractive offer, such as an upgrade, for a few dozen euros," he explained. "They will think it's a good deal, except that afterwards, they will be asked for bank details and so their account will be emptied."

The second risk is of a physical nature: because the hackers have the start and end dates of stays, the homes of holidaymakers could be targeted by burglars during their absence.

A flaw in an external IT provider

Gîtes de France indicated that the breach originated from an external IT service provider, whose software is only deployed in certain departments. The hacker, contacted by French Breaches, cited Guadeloupe, Haute-Garonne and Cantal among the affected territories.

Third player in French tourism targeted

This attack is part of a series of cyber incidents affecting France's tourism sector. Gîtes de France is the third player in the sector to be targeted, after the Pierre & Vacances group, Center Parcs and Belambra Clubs. In each of these cases, the brands have filed complaints, and affected customers are urged to exercise extra caution in the coming weeks and months.

Source: France Info

Read this article in the original language