CSIDB logo
Incident

Fondation Cancer

Incident posture

Attack window
Apr 2025
Location
Luxembourg
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 11:21

Linked entities

Victim
Fondation Cancer
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Luxembourg-based cancer foundation confirmed that it was targeted by a recent cyberattack aimed at one of its email accounts. The organization reported that its specialized cybersecurity provider immediately detected the malicious activity and successfully stopped it. According to the foundation, there is no evidence that any data was disclosed, stolen, or copied during the incident. The attack did not affect the foundation's services for patients, and financial operations, including transactions and bank accounts, remained unaffected as they are processed through secure payment channels.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On Thursday, April 1, 2025, the Fondation Cancer, a Luxembourg-based cancer support organization, publicly confirmed that it had recently been the target of a cyberattack. The disclosure came in the form of an official statement issued by the foundation itself, in which it acknowledged that suspicious activity had been detected in one of its email accounts. According to the statement, a specialized service provider immediately analyzed the incident and identified it as a malicious attack directed at a portion of the foundation's email infrastructure. The wording used by the foundation indicated that the attack was deliberate and targeted, though the precise nature of the malicious activity—whether it involved phishing, credential compromise, or another method—was not specified in the public communication.

The foundation emphasized that, upon detection, all necessary measures were taken in cooperation with its cybersecurity service provider to halt the attack without delay. This rapid response was credited with stopping the intrusion before it could progress further. Importantly, the organization stated that there were no indications that any data had been disclosed, stolen, or copied as a result of the incident. The foundation was explicit in its assertion that its core operations, particularly the services it provides to cancer patients, were not impacted at any point during or after the attack. This continuity of services was highlighted as a key reassurance to patients, donors, and other stakeholders who rely on the foundation's work.

Regarding the scope and financial implications of the incident, the Fondation Cancer clarified that the attack bore no relation to the organization's financial processes. The foundation stated that all transactions continued to be processed through secure payment channels and that its bank accounts were unaffected. This distinction was made to reassure donors and partners that their financial contributions and interactions with the foundation remained secure. The foundation also took the opportunity to note that it was doing everything within its power to defend against malicious attacks, acknowledging a broader trend in which an increasing number of organizations are being targeted by such threats. The public statement did not identify the attackers, disclose the specific vulnerability exploited, or provide a timeline detailing when the suspicious activity first began and when it was contained, leaving the precise operational details of the incident undisclosed.

Sources

Sources available to members: 1 source.

CSIDB