CSIDB logo
Incident

Sidaction

Incident posture

Attack window
Jan 2023
Location
France
Status
Historical
CIA posture
Available to members
Updated
2026-01-07 15:38

Linked entities

Victim
Sidaction
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeting a service provider's hosting system compromised an AIDS charity's donor data, potentially exposing personal information including names, addresses, contact details, and donation amounts. Approximately 3% of impacted records included banking identifiers (IBAN/BIC), though payment card data remained unaffected. The organization notified potentially affected donors and relevant authorities while urging vigilance against fraudulent solicitations. It confirmed ongoing secure online donation capabilities through the provider, which implemented additional security enhancements. This incident followed recent healthcare sector cyberattacks affecting millions in France through compromised third-party systems and hospital data breaches.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On January 1, 2024, Sidaction, a French nonprofit organization cofounded in 1994 to combat HIV/AIDS, disclosed a cybersecurity incident affecting its operations. The breach originated from a cyberattack targeting the system of one of Sidaction’s third-party hosting providers, compromising donor data processed since January 2023. Personal data potentially exposed included names, postal addresses, email addresses, telephone numbers, and donation amounts for less than 20% of donors who contributed during that period. Approximately 3% of the impacted records also contained banking information—specifically IBAN (International Bank Account Number) and BIC (Bank Identifier Code)—though credit card details remained unaffected. Sidaction confirmed the incident involved cyber-malveillance but did not identify the threat actors or their methods. The organization acknowledged the risk of personal data disclosure and initiated direct notifications to affected individuals while alerting France’s data protection authority, the CNIL.

Sidaction emphasized ongoing efforts to mitigate the breach’s consequences, including collaboration with its provider to reinforce existing security measures. The association assured donors that online donation channels remained secure despite the incident and urged vigilance against potential fraud attempts leveraging the exposed data. No operational disruptions to Sidaction’s fundraising events or research initiatives were reported. The disclosure occurred amid a series of cyberattacks against French healthcare entities, including a separate incident impacting 33 million individuals through a third-party payment processor and a hospital breach in Armentières affecting 300,000 patients. Sidaction’s communication stressed transparency but did not specify whether data had been actively misused or if ransomware or extortion tactics were involved in the attack.

Sources

Sources available to members: 1 source.

CSIDB