Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

French Government Reports Data Breach Affecting Over 73,000 Employees' Secure Messaging Accounts

The French government has disclosed a significant data breach impacting over 73,000 user accounts on its secure instant messaging service, Tchap. This incident underscores critical vulnerabilities in government communication infrastructure, potentially compromising sensitive official correspondence and personal data of civil servants. The breach raises serious concerns about the security posture of digital platforms designed for secure governmental use.

Today's question

Under Article 13 GDPR, when personal data is collected directly from the data subject, the controller must provide information:

  1. At the time when personal data is obtained
  2. Within 30 days of collection, subject to the applicable communication standards
  3. Only if the data subject requests it, subject to documented procedural requirements
  4. Within one year of collection, in accordance with the information provision framework

Answer this question on the site

Worth knowing

  1. FBI Disrupts Large Scale AI Powered Phishing Operation Targeting Millions of URLs

    The FBI has successfully dismantled a sophisticated AI powered phishing service that utilized over a million URLs to scam numerous victims. This operation highlights the increasing use of artificial intelligence in cybercrime and the complex challenges law enforcement faces in combating these advanced threats. The action demonstrates a proactive approach to disrupting criminal enterprises leveraging emerging technologies for illicit gain.

  2. Chinese Hackers Maintain Decade Long Surveillance on Isolated Networks Through Authentication Flow Hijacks

    A report indicates that Chinese state sponsored hackers successfully hijacked authentication flows to spy on isolated networks for a decade. This prolonged breach underscores critical vulnerabilities in network access controls and the persistence of advanced persistent threat actors. It raises significant concerns about long term espionage and the undetected compromise of sensitive systems.

  3. Over 400 Arch Linux Packages Compromised to Distribute Rootkits and Infostealers

    More than 400 Arch Linux packages have been found compromised, pushing malicious rootkits and information stealers to users. This supply chain attack highlights the inherent risks in open source software ecosystems and the difficulty in ensuring the integrity of widely used software components. User data and system security are at severe risk due to these pervasive compromises.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.