Atout France Has Been Hacked: Cyberattack Hits French Tourism Agency


ttt

tttt
Atout France dans la lignée de Belambra, Maeva et Gîtes de France - Depositphotos retouchée par l'IA
ttt

ttt

t

tt

CroisiEurope


tt

tt

tt

tt

ttt

tttt The list is long and shows no signs of stopping.
tttt
tttt
tttt After the historic wave of hacks that hit tourism in May, revealing a relatively basic vulnerability among several major players in the sector, cyberattacks continue in the tourism industry, without ever stopping.
tttt
tttt
tttt And this time, it is the turn of a public institution to have its vulnerabilities laid bare.
tttt
tttt
tttt Atout France therefore suffered an attack by a malicious individual who could have extracted, according to their statements, data from approximately 400,000 user accounts.
tttt
tttt
tttt Samples, as a gesture of good faith, as is customary on the dark web, have been shared.
ttt

tt

tt

t

ttt

ttt

Atout France Following in the Footsteps of Belambra, Maeva, and Gîtes de France

tt

tt

ttt

tttt The hacker claims to have exploited an access-control flaw, i.e., an IDOR (Insecure Direct Object Reference) vulnerability, according to frenchbreaches, as was the case for Belambra, Gîtes de France or Maeva.
tttt
tttt
tttt “In French, one could translate that as having a direct reference to an unsecured object.
tttt
tttt
tttt That is to say that if a profile, a file or an invoice is stored directly within an application, simply entering the direct address could allow access, even without the proper authorization.
tttt
tttt
tttt We are not facing an extraordinarily sophisticated technical exploit, but rather a misunderstanding of security at the human level,
” we were told by Christophe Mazzola, founder of the Cyber Academy, in a previous article.
tttt
tttt
tttt Beyond this weakness, the consequences can be dire for companies or individuals.
tttt
tttt
tttt Regarding Atout France, about 400,000 user accounts would thus be compromised. The attacker(s) would have access to names, first names, roles, emails, phone numbers, billing postal addresses, organizations, member numbers…
tttt
tttt
tttt A multitude of information that could feed, in the future, phishing campaigns or other highly targeted malicious actions. Vigilance will therefore need to be doubled in case of emails purportedly sent by Atout France in the days and months to come.
ttt

tt

tt

t

ttt

ttt

Pacha Tours and Trenitalia France Also Hacked

tt

tt

ttt

tttt Do not believe that, after the historic wave of hacks that the tourism industry experienced, hackers have lost interest in the sector; quite the opposite.
tttt
tttt
tttt Taking advantage, no doubt, of the sector’s cybersecurity weaknesses, the trophies have been many.
tttt
tttt
tttt There was, at the end of June, Pacha Tours. The hackers claimed to have extracted 2 GB of data thanks to “a code-injection technique used to modify or retrieve data in SQL databases (tables with rows and columns, ndlr)“, according to Cloudflare.
tttt
tttt
tttt Thus, on both the Pacha Tours site and its pro space, the compromised data would concern 31,087 unique individuals, 4,413 unique emails, 3,705 unique phones, 132 cleartext passport numbers, 10,153 PNR codes, and 1,096 B2B agency accesses with passwords in clear text, according to the attackers.
tttt
tttt
tttt But that’s not all, because Trenitalia France also suffered a similar misfortune.
tttt
tttt
tttt The malicious actors gained unauthorized access to certain personal data of customers related to ticket purchases. This attack has been confirmed by the operator.
tttt
tttt
tttt An email campaign was sent to the company’s customers.
tttt
tttt
tttt It reveals that the information in the pirates’ possession includes: civil and identification data (buyer and passenger names, passenger date of birth); contact data (email address, phone number); travel data (information associated with the transport ticket, such as itinerary, travel date and time, ticket number); type of offer or service linked to the transport ticket and data needed to benefit from these offers.
tttt
tttt
tttt Moreover, the attackers claim to have extracted data from 60,568 user accounts, as well as metadata from Smartbox agreements or e-signature documents.
tttt
tttt
tttt “We really need to roll up our sleeves and get to work, because this kind of data leak, in Europe, we are truly among the few who know this story.
tttt
tttt
tttt I work a lot in the United Kingdom, Germany, the Netherlands, Luxembourg, Switzerland and Belgium; there, this isn’t as common. France is acting as the delinquent student,
” Christophe Mazzola explained to us.
ttt

tt

tt

t

Amara Nambinga

Amara Nambinga

I write about tourism, culture, and emerging destinations with a Namibian perspective. Through my articles, I try to highlight the places, people, and travel stories that show how Africa and the wider world are changing.