CSIDB logo
Incident

Compagnie des Guides de Chamonix

Incident posture

Attack window
Aug 2025
Location
France
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 18:59

Linked entities

Victim
Compagnie des Guides de Chamonix
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Aug 2025
Discovered
Undetermined
Disclosed
Aug 2025
Resolved
Pending

Summary

The computer system of the Compagnie des Guides de Chamonix was subjected to an intrusion that partially bypassed existing defenses, allowing attackers to view and possibly exfiltrate confidential data such as email addresses and associated information. While security measures contained a portion of the breach, the accessed data could have been stolen, prompting the organization to assess the extent of the compromise and notify affected individuals.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Friday, 15 August 2025, the computer system of the Compagnie des Guides de Chamonix was targeted by an intrusion. The attack occurred on the day of the company's annual celebration, as indicated by the article's title referencing the fĂȘte. The intrusion was identified by the organization's existing security defenses. Those defenses managed to contain a portion of the malicious activity, limiting its spread within the network. Despite the containment, unauthorized access was achieved to certain confidential data stored on the system. The specific data that were consulted included email addresses and associated information. The article notes that the consulted information could have been stolen, indicating a potential exfiltration. The incident was reported in a news article published on 16 August 2025. The article carries the source report ID 31f416ed-d488-48a1-8b25-2bdb15ead194 and was sourced from the URL https://www.ledauphine.com/faits-divers-justice/2025/08/16/une-cyberattaque-cible-la-compagnie-des-guides-le-jour-de-sa-fete.

No details are provided in the source about the identity or motives of the threat actor responsible for the intrusion. The article does not specify which particular servers, workstations, applications, or databases were compromised beyond the general reference to the computer system. The extent of any data loss remains uncertain, as the source only notes the possibility that the accessed email addresses and associated information could have been taken. The company has not disclosed additional response actions beyond the defensive measures that succeeded in containing part of the attack. No information is given regarding whether affected individuals were notified, whether regulatory authorities were informed, or what remediation steps were undertaken. The article does not mention any downtime, service disruption, or financial impact resulting from the intrusion. Further details about the incident are not available in the provided source. The reported facts are limited to the timing, the defensive containment, and the potential compromise of email-associated data. No additional information about the intrusion is present in the source material.

Sources

Sources available to members: 2 sources.

CSIDB