France fines unemployment agency €5 million over data breach
好的,我现在需要帮用户总结一篇文章的内容,控制在100个字以内,并且不需要特定的开头。首先,我得仔细阅读文章内容,抓住主要信息。 文章讲的是法国的数据保护机构CNIL对国家就业局France Travail罚款500万欧元,原因是未能保护求职者的数据,导致黑客窃取了4300万人的个人信息。事件发生在2024年初,黑客使用了社会工程学手段入侵了顾问账户。此外,CNIL还要求该机构记录补救措施,否则每天罚款5000欧元。 接下来,我需要将这些关键点浓缩到100字以内。包括罚款金额、原因、受影响人数、黑客手段以及后续措施。要确保信息准确且简洁。 最后,检查一下是否符合用户的要求:中文总结,不使用特定开头,控制在100字以内。这样应该能满足用户的需求了。 </think> 法国数据保护机构因未保护求职者数据对国家就业局处以500万欧元罚款。黑客利用社会工程学手段窃取4300万人个人信息。机构需采取补救措施,否则面临每日5千欧元处罚。 2026-1-29 13:45:46 Author: www.bleepingcomputer.com(查看原文) 阅读量:0 收藏

France flag

The French data protection authority fined the national employment agency €5 million (nearly €6 million) for failing to secure job seekers' data, which allowed hackers to steal the personal information of 43 million people.

France Travail (formerly known as Pôle Emploi) is the country's public employment service, providing unemployment benefits and helping job seekers find work. The agency also maintains extensive databases containing personal and financial information for millions of French citizens.

The National Commission on Informatics and Liberty (CNIL) imposed the penalty on France Travail following a data breach in early 2024 that exposed job seekers' personal information spanning 20 years.

Wiz

In March 2024, the French government agency disclosed that the attackers stole the sensitive data of up to 43 million individuals, including their names, dates of birth, national insurance numbers, email and home addresses, and phone numbers.

However, the data breach didn't affect bank details or account passwords, and the hackers didn't obtain complete job-seeker files, which may also have contained sensitive health data.

"In the first quarter of 2024, one or more hackers managed to hack into the FRANCE TRAVAIL information system. They used techniques known as 'social engineering,' which involve exploiting people's trust, ignorance or credulity," the CNIL said on Thursday.

"This method enabled them to hijack the accounts of CAP EMPLOI advisers, i.e. the organisations responsible for supporting, monitoring and upholding the employment of people with disabilities."

The data protection watchdog also ordered France Travail to document corrective measures and to provide a detailed implementation schedule. Failure to comply with CNIL's order will result in daily penalties of €5,000 until the government agency demonstrates that it has remedied its security issues.

In August 2023, France Travail suffered another massive data breach affecting approximately 10 million individuals, exposing their full names and social security numbers.

Last year, CNIL also slapped Google with a €325 million ($378 million) fine for violating cookie regulations and imposed a €150 million ($174 million) fine on Shein's Irish subsidiary for similar violations of the General Data Protection Regulation (GDPR).

More recently, it fined Free Mobile and its parent company €42 million after an October 2024 data breach for failing to protect customer data against cyber threats.

Wiz

Secrets Security Cheat Sheet: From Sprawl to Control

Whether you're cleaning up old keys or setting guardrails for AI-generated code, this guide helps your team build securely from the start.

Get the cheat sheet and take the guesswork out of secrets management.


文章来源: https://www.bleepingcomputer.com/news/security/france-fines-unemployment-agency-5-million-over-data-breach/
如有侵权请联系:admin#unsafe.sh