CSIDB logo
Incident

Egor Recursos Humanos

Incident posture

Attack window
Jul 2022
Location
Portugal
Status
Historical
CIA posture
Available to members
Updated
2025-10-17 00:00

Linked entities

Victim
Egor Recursos Humanos
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cybersecurity incident involving Egor Recursos Humanos resulted from an external intrusion targeting candidate files stored on the company's website. Attackers accessed personal data including names, identification numbers, addresses, contact details, and human resources information. The organization detected and blocked the breach promptly, implementing corrective security measures such as immediate website shutdown, attack vector analysis, and access mechanism revisions. They notified Portugal's National Data Protection Commission and engaged cybersecurity experts for ongoing system monitoring to prevent future vulnerabilities. While characterizing the compromised files as "residual," the company apologized to affected candidates and initiated judicial authority consultations while avoiding public disclosure to prevent encouraging further attacks.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On July 22, 2022, at approximately 17:00, the Portuguese recruitment firm Egor Recursos Humanos suffered a cybersecurity breach involving unauthorized access to its website. The attackers executed an external intrusion targeting candidate files stored within the website's memory systems. Compromised data included personally identifiable information such as full names, national identification numbers, residential addresses, contact details, and human resources-related records. Egor's executive leadership, including CEO Afonso Carvalho, confirmed the incident occurred despite existing security measures, characterizing the volume of exfiltrated files as "residual" though no specific quantification was provided. The organization detected the intrusion in real-time and immediately severed external access to the website to contain the breach, preventing ongoing data exposure.

Technical teams promptly initiated forensic analysis to determine the attack vector and operational methodology employed by the threat actors. Corrective security measures were implemented to address identified vulnerabilities, including revisions to access control mechanisms and system hardening to block recurrence pathways. Egor formally notified Portugal's National Data Protection Commission (CNPD) within compliance timelines and engaged judicial authorities for potential legal proceedings. With website functionality restored post-remediation, the firm enlisted cybersecurity specialists to conduct continuous monitoring of implemented safeguards, aiming to detect residual vulnerabilities or subsequent intrusion attempts. Executive communications emphasized operational normalization while apologizing to affected candidates, asserting maximal efforts to mitigate damages and prevent future incidents. Carvalho publicly acknowledged the breach while minimizing reputational amplification concerns, stating controlled disclosure aligned with organizational priorities following regulatory and law enforcement reporting obligations.

Sources

Sources available to members: 1 source.

CSIDB