Ticker

6/recent/ticker-posts

Data of nearly 500,000 French people on sale on the "Cybercrime Amazon"

Data of nearly 500,000 French people on sale on the "Cybercrime Amazon"

A new database has just been put up for sale on BreachForums, the criminal forum that has become a hub for compromised information. Spotted by researcher Clément Domingo, the directory is said to include data from users of Sport-Découverte, the online platform that offers a wide range of sports activities, from thrills to discoveries, such as skydiving or driving courses, in the form of gift boxes.

The database includes potentially sensitive information, such as the type of customer (individual or company), title, first name, last name, date of birth, mobile number, and email address. The data was stolen in 2024, the seller announced. They concern nearly 500,000 people.

They are obviously very interesting for cybercriminals who orchestrate online scams, such as phishing attacks. If you are a Sport-Découverte customer, we recommend that you exercise extra caution. However, the company has not yet confirmed the leak.

A credible and active cybercriminal

As Clément Domingo explains in his post, we are inclined to take the directory seller's word for it. The cybercriminal, who operates under the name TheFrenchGuy, has already put several databases relating to French organizations online on BreachForums last month. Several of the stolen databases have proven to be authentic. The announcement also includes a significant sample of information.

Several of the sports organizations hacked by TheFrenchGuy last month have confirmed a cyberattack that resulted in data theft. This is the case for the French Archery Federation and the French Mountain and Climbing Federation (FFME). In total, eight major French sports federations are believed to have been compromised. The attacker exploited a security flaw discovered in an IT service provider common to all the federations. This explains this accumulation of attacks. All the databases stolen through this vulnerability were sold in a short time on BreachForums, TheFrenchGuy reports.

In the ad, viewed by 01Net, the hacker asks buyers interested in Sport-Découverte data to contact him by private message to arrange payment in cryptocurrencies. For the moment, there is no indication that a buyer has come forward.

The scourge of data leaks in France

Data leaks are occurring at a steady pace in France at the start of the year. Cyberattacks, already frequent last year with 14 times more leaks than in 2023, continue to increase. In January, several French companies, such as Kiabi and Showroomprivé, were targeted by hackers looking for data. In this context, "it is crucial for French users to strengthen the protection of their data by opting for complex passwords, activating two-factor authentication and being vigilant against cyber threats", advises Maud Lepetit, France Manager at Surfshark.

Post a Comment

0 Comments