CSIDB logo
Incident

Ucar

Incident posture

Attack window
Jan 2021
Location
France
Status
Historical
CIA posture
Available to members
Updated
2025-10-27 00:00

Linked entities

Victim
Ucar
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jan 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A vehicle rental company experienced a ransomware attack after hackers breached its servers. The organization engaged cybersecurity risk management consultants and forensic experts to assess the compromise's scope and determine the nature and volume of stolen data, with investigations still ongoing. Operations were restored from backups without service disruption, maintaining functionality across client-facing agencies, web services, and business software throughout the incident. The company committed to providing further updates as the analysis progressed.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 20, 2021, vehicle rental company Ucar publicly disclosed it had suffered a ransomware attack earlier that year. Hackers gained unauthorized access to the company’s servers through an unidentified gateway, triggering an operational disruption. Nicolas Martin, Ucar’s Secretary General, confirmed the incident but noted that a comprehensive analysis of the attack’s scope, depth, and associated consequences remained ongoing at the time of disclosure. The company engaged external cybersecurity professionals, including a risk management consulting firm specializing in IT and cyber incidents, alongside forensic experts, to investigate the breach. These teams worked to determine the nature and volume of data compromised during the intrusion. Despite the attack, Ucar managed to restore operations using existing data backups, minimizing downtime.

Ucar maintained business continuity throughout the incident, with no reported interruptions to customer-facing services. Its agencies continued client operations unimpeded, while web services and core business software remained fully operational. Martin emphasized this resilience, attributing it to the effective deployment of backup systems to recover critical functions. The company committed to providing further updates as investigations progressed, particularly regarding the extent of data exfiltration and potential impacts. No specific details about ransom demands, payment, or data types were disclosed in the initial announcement. Forensic work continued to assess the attack’s pathways and the full implications for data security and system integrity.

Sources

Sources available to members: 1 source.

CSIDB