French government agency fined nearly $6 million for data security failings
嗯,用户让我总结一下这篇文章的内容,控制在100字以内,而且不需要用“文章内容总结”之类的开头。首先,我需要快速浏览文章,抓住主要信息。 文章讲的是法国的数据保护机构对一个政府部门罚款500万欧元,因为数据安全差。这个部门负责求职登记、失业救济和就业援助。黑客在2024年初通过社会工程攻击入侵了他们的系统,控制了支持残疾人就业的组织账户。黑客获取了过去20年的注册数据,包括国民保险号、邮箱、地址和电话号码,但没有健康数据。 罚款的原因是该部门忽视了基本安全原则,影响人数多,处理的数据量大且敏感。安全漏洞包括身份验证流程差、日志检查不足以及不必要的广泛数据访问。部门被要求立即实施安全措施,并承认事件的严重性和责任,虽然不反对决定,但觉得处罚过重。 现在我要把这些信息浓缩到100字以内。重点包括:法国数据保护机构罚款500万欧元给求职登记部门;黑客入侵导致20年数据泄露;罚款基于安全疏忽和影响范围;部门需加强安全措施,并承认责任但认为处罚过重。 这样组织起来应该可以控制在100字左右。 </think> 法国数据保护机构对负责求职登记和失业救济的政府部门处以500万欧元罚款,因其数据安全漏洞导致黑客入侵并泄露20年注册数据。事件涉及身份验证不足等多重问题,影响人数众多且数据敏感。该部门被要求立即加强安全措施,并承认事件严重性及责任。 2026-1-29 18:1:18 Author: therecord.media(查看原文) 阅读量:0 收藏

The French data protection authority announced Thursday it has fined the country’s primary governmental agency responsible for registering job seekers, providing unemployment benefits and aiding in job placement €5 million (about $6 million) for poor data security.

Early in 2024, hackers breached France Travail’s computer systems using social engineering attacks, the regulator known as CNIL said in a press release.

The hack allowed the adversaries to take over the accounts of the organizations responsible for supporting and monitoring the employment of people with disabilities, the press release said.

The hackers accessed data belonging to everyone who had registered with the organization for the past 20 years. They did not access job seekers’ health data, but did obtain National Insurance numbers, email and postal addresses and telephone numbers. 

The fine amount was based on France Travail’s “ignorance of essential security principles, the number of people affected and the volume and sensitivity of the data processed,” the press release said.

Security flaws included poor authentication processes, insufficient logging checks to detect abnormal behavior and broader data access than was needed.

France Travail has been ordered to immediately implement proper security controls.

The organization said it is “fully aware of the seriousness of the events that occurred and of our responsibility in matters of data protection.” 

“While we do not dispute the CNIL's decision, we nevertheless regret its severity given our very strong commitment to cybersecurity and the protection of our users' data since this incident occurred.”

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.


文章来源: https://therecord.media/france-travail-fined-cnil
如有侵权请联系:admin#unsafe.sh