French Rugby Federation hit by cyberattack affecting 530,000 members

14:15
French Rugby Federation hit by cyberattack affecting 530,000 members
Zoom

Fédération française de rugby has confirmed a cyberattack that targeted its members, exposing personal information belonging to approximately 530,000 license holders. The breach was reported on Tuesday and involved a phishing campaign, rather than a direct intrusion into the federation’s computer systems.

According to the FFR, the hacker attempted to sell a large database containing names, license numbers, club affiliations, administrative history, and nearly one million player photos, including some of minors. The compromised data also reportedly included 948 national ID cards, medical information related to sports injuries, social security numbers, addresses, phone numbers, emails, professions, and dates of birth. Club-related information such as contact details and administrative records was also affected.

Phishing, a form of online fraud designed to trick individuals into revealing sensitive information such as passwords or payment details, was the method used in this attack. The federation has filed a complaint with authorities and informed the Commission Nationale de l’Informatique et des Libertés as well as relevant state services.

The FFR emphasized that the attack was contained through rapid measures, including temporary suspension of certain services, reinforced access controls, password resets, and deployment of additional security tools. Members and partners are urged to remain vigilant against unusual communications via email, phone, or SMS and to never share personal information through these channels.

This is the second cyberattack the federation has experienced; in June 2023, a ransomware group known as Play had threatened to release confidential personal and employee data, prompting the FFR to act quickly to remove the malicious software.

The federation continues to stress the importance of protecting personal data and advises members to consult official cybersecurity resources such as cybermalveillance.gouv.fr if in doubt.



Read more