Menu
Browse

Cyber Incident Victim: SVI Assurances

Date:

Feb 2021

Location:

France

Summary

A French insurer was targeted by the Avaddon ransomware group, which claimed to have exfiltrated approximately 100GB of human resources data. The attackers threatened to release the allegedly stolen information unless their demands were met, accusing the organization of failing to cooperate or recognize the severity of the breach. Despite the victim's denial of any intrusion or data theft, Avaddon maintained possession of sensitive materials and issued an impending deadline for public disclosure.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 2 techniques
Threat Actors Type Location
6 actors Available to members Available to members

Description

The Avaddon ransomware group targeted French insurance provider SVI Assurances in early February 2021, with public evidence of the attack emerging on February 5. Attackers claimed to have exploited system vulnerabilities to gain initial access before infiltrating networks and exfiltrating approximately 100GB of human resources data. Avaddon set a ransom deadline of February 7, threatening to publish the allegedly stolen information unless payment was made. The group characterized SVI as uncooperative and unaware of the incident's severity, stating the company had become "hostages of the situation." When contacted by journalists, SVI representatives denied experiencing any security breach or data theft, creating conflicting narratives about the attack's validity.

Cyber Incident Image

The incident carried significant reputational and operational risks for SVI due to the sensitive nature of HR data potentially exposed. Avaddon's threatened data leak could have impacted employee privacy and client trust if executed. The February 7 deadline created time pressure for response decisions, though no public confirmation exists regarding whether data was ultimately published. The attack occurred amid Avaddon's simultaneous targeting of Canadian cleaning firm Qualinet, suggesting a broader campaign pattern. Limited information exists regarding SVI's internal detection methods, containment procedures, or recovery actions beyond their initial denial of compromise. The discrepancy between attacker claims and corporate statements left the incident's full scope unverified in public reporting.

Sources
Sources available to members
1 source