Cyber Incident Victim: Ucar
Date:
Jan 2021
Location:
France
Summary
A vehicle rental company experienced a ransomware attack after hackers breached its servers. The organization engaged cybersecurity risk management consultants and forensic experts to assess the compromise's scope and determine the nature and volume of stolen data, with investigations still ongoing. Operations were restored from backups without service disruption, maintaining functionality across client-facing agencies, web services, and business software throughout the incident. The company committed to providing further updates as the analysis progressed.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 3 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On January 20, 2021, vehicle rental company Ucar publicly disclosed it had suffered a ransomware attack earlier that year. Hackers gained unauthorized access to the company’s servers through an unidentified gateway, triggering an operational disruption. Nicolas Martin, Ucar’s Secretary General, confirmed the incident but noted that a comprehensive analysis of the attack’s scope, depth, and associated consequences remained ongoing at the time of disclosure. The company engaged external cybersecurity professionals, including a risk management consulting firm specializing in IT and cyber incidents, alongside forensic experts, to investigate the breach. These teams worked to determine the nature and volume of data compromised during the intrusion. Despite the attack, Ucar managed to restore operations using existing data backups, minimizing downtime.

Ucar maintained business continuity throughout the incident, with no reported interruptions to customer-facing services. Its agencies continued client operations unimpeded, while web services and core business software remained fully operational. Martin emphasized this resilience, attributing it to the effective deployment of backup systems to recover critical functions. The company committed to providing further updates as investigations progressed, particularly regarding the extent of data exfiltration and potential impacts. No specific details about ransom demands, payment, or data types were disclosed in the initial announcement. Forensic work continued to assess the attack’s pathways and the full implications for data security and system integrity.
