Cyber Incident Victim: Sidaction
Date:
Jan 2023
Location:
France
Summary
A cyberattack targeting a service provider's hosting system compromised an AIDS charity's donor data, potentially exposing personal information including names, addresses, contact details, and donation amounts. Approximately 3% of impacted records included banking identifiers (IBAN/BIC), though payment card data remained unaffected. The organization notified potentially affected donors and relevant authorities while urging vigilance against fraudulent solicitations. It confirmed ongoing secure online donation capabilities through the provider, which implemented additional security enhancements. This incident followed recent healthcare sector cyberattacks affecting millions in France through compromised third-party systems and hospital data breaches.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On January 1, 2024, Sidaction, a French nonprofit organization cofounded in 1994 to combat HIV/AIDS, disclosed a cybersecurity incident affecting its operations. The breach originated from a cyberattack targeting the system of one of Sidaction’s third-party hosting providers, compromising donor data processed since January 2023. Personal data potentially exposed included names, postal addresses, email addresses, telephone numbers, and donation amounts for less than 20% of donors who contributed during that period. Approximately 3% of the impacted records also contained banking information—specifically IBAN (International Bank Account Number) and BIC (Bank Identifier Code)—though credit card details remained unaffected. Sidaction confirmed the incident involved cyber-malveillance but did not identify the threat actors or their methods. The organization acknowledged the risk of personal data disclosure and initiated direct notifications to affected individuals while alerting France’s data protection authority, the CNIL.

Sidaction emphasized ongoing efforts to mitigate the breach’s consequences, including collaboration with its provider to reinforce existing security measures. The association assured donors that online donation channels remained secure despite the incident and urged vigilance against potential fraud attempts leveraging the exposed data. No operational disruptions to Sidaction’s fundraising events or research initiatives were reported. The disclosure occurred amid a series of cyberattacks against French healthcare entities, including a separate incident impacting 33 million individuals through a third-party payment processor and a hospital breach in Armentières affecting 300,000 patients. Sidaction’s communication stressed transparency but did not specify whether data had been actively misused or if ransomware or extortion tactics were involved in the attack.
