Global Breach Wave: Massive Data Leaks Hit France & Poland as US Endorses Cyber Retaliation

UK BASED BEACON CRM HACKED, CHARITIES’ DATA STOLEN

London-based Cloud-based customer relationship management software provider Beacon CRM Beacon said it first learned on July 29 that its systems may have been breached. Beacon says its CRM system is used by over 1,000 charities and non-profit organizations, ranging from Special Olympics Ireland and Great Lakes Outreach to Heart Research UK, to handle everything from collecting online donations, to managing memberships and selling tickets to events.

The company first notified customers on Monday August 3 that a breach did occur and said they suspect data was exfiltrated. “Their current understanding is that compromised credentials were used to gain access to Beacon, and copies of our database backups were made,” the company said.

A update the next day had the company telling customers that it might never be able to ascertain exactly how much data hackers stole. “Out of an abundance of caution, you may want to assume that all data that you store in Beacon, including attachment files, has been downloaded,” the company said. The breach appears to affect customers as well as free-trial users who held an account before July 27. Beacon CRM is designed to track and manage a variety of types of business-critical charity data. “As well as having all of the standard fundraising features right out-of-the-box, Beacon can also store any kind of data that your organization needs to manage: animal adoptions, grant making, tracking memorial benches – all covered in one database,” reads its website.

 

CREDIT AGRICOLE SUFFERS A LARGE ATTACK AIMING TO LURE ITS CUSTOMERS

Crédit Agricole, a major French bank, went through a widespread phishing campaign, just two months after the European Central Bank (ECB) had warned about the cybersecurity risks revealed by the latest artificial intelligence models. The scam started by taking advantage of poorly secured AWS cloud storage spaces. The attackers were looking for configuration files, database backups, and swap files containing access keys for email services like SendGrid and Amazon SES, which are normally used by legitimate companies for invoices or notifications.

By hijacking these credentials, the scammers were able to send their fraudulent messages from a trusted infrastructure, making spam filters much less effective. Then, better than launching a massive generalized attack, the hackers took the time to select their targets. The messages, pretending to be from Crédit Agricole, urged recipients to renew the registration of a trusted device or risk losing access to their account. The link led to a fake form that faithfully copied the official bank website’s interface. As a result, 912 victims entered their banking credentials. Unlike a typical bank fraud, the stolen credentials weren’t used right away. The attackers first gathered additional information about each victim: account balance, branch, advisor’s name. These details turned out to be crucial for the second phase of the scam, which was entirely based on fraudulent phone calls. By showing detailed knowledge of their target’s file, the scammers managed to create enough trust to convince some victims to pay fake service fees. This approach resulted in 83 fraudulent payments.

 

THE FRENCH TAX MANAGEMENT SYSTEM HIT, USERS’ DATA COLLECTED 

By the end of last June, the French tax declaration and payment system impots.gouv.fr suffered a cyber attack, recognized only last August 11, which allowed hackers to steal users’ data, such as identity, fiscal number, associated to the amount of due taxes. A bonanza for hackers future phishing campaigns.

 

AND BLOCTEL USERS’ DATA STOLEN AS WELL

BLOCTEL was the name of the French service in charge of regulating advertising phone calls. This service has been closed on August 11, as online advertisers are now obliged to seek the consent of person before addressing calls. But just before the closure, the service was hacked, resulting in a major data leak, including the phone numbers of the “opt out consumers”. A lot of malicious phone calls ahead ?

 

A LARGE CYBERATTACK IN POLAND

Nearly 19 million Poles, or half of the country’s population, saw their personal and medical data potentially compromised after a hack of MyDr, a software provider used by 12,000 healthcare facilities. About two terabytes of data were indeed stolen, coming from historical files dating back to April 2024. The exposed data includes identifying information like name, first name, PESEL number (the Polish equivalent of a social security number), postal address, email, and phone number. Sensitive medical data might also be involved: test results, prescriptions, treatment histories. Medical data is indeed among the most sought-after on underground markets. Unlike a credit card or a password, which can be replaced if compromised, some medical information and identity data are unchangeable or can be exploited for years…

 

US PRESIDENT ENCOURAGES STRIKE BACK AGAINST FOREIGN HACKERS

On August 10, President Trump signed a national security presidential memorandum directing federal law enforcement to use cyber tools against transnational criminal organizations operating overseas that target Americans with ransomware attacks and financial fraud schemes. The memo creates a formal pathway for private-sector cyber companies to help the government identify and disrupt these foreign-based networks, according to the White House.

The memorandum directs the Homeland Security Task Force’s National Coordination Center to stand up a new program led jointly by Executive Directors from the Department of Justice and the Department of Homeland Security, tasked with executing cyber operations against foreign criminal organization. According to a REUTERS reports, the memo directs Trump’s administration to leverage private-sector capability and innovation for cyber operations conducted under U.S. government direction, control, and authority.

ECA comment: though the official policy has long been not to directly hit the hackers themselves unless under Justice supervision, it sounds rather obvious that for some time already State cybersecurity Agencies were not sitting on a purely defensive posture. The US decision goes one step further by endorsing a role for private companies in such “retaliation”, though it maintains it should be done “under U.S. government direction, control, and authority”. That will be the key issue. In previous circumstances, some US actors as Oliver North have deliberately infringed this sort of control… (Mr North diverted proceeds from the arms sales to support the Contra rebel groups in Nicaragua, official funding for which had been specifically prohibited under the Boland Amendment)

Share:

More Posts