Cyber Incident Victim: Egor Recursos Humanos
Timeline
Summary
A cybersecurity incident involving Egor Recursos Humanos resulted from an external intrusion targeting candidate files stored on the company's website. Attackers accessed personal data including names, identification numbers, addresses, contact details, and human resources information. The organization detected and blocked the breach promptly, implementing corrective security measures such as immediate website shutdown, attack vector analysis, and access mechanism revisions. They notified Portugal's National Data Protection Commission and engaged cybersecurity experts for ongoing system monitoring to prevent future vulnerabilities. While characterizing the compromised files as "residual," the company apologized to affected candidates and initiated judicial authority consultations while avoiding public disclosure to prevent encouraging further attacks.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 22, 2022, at approximately 17:00, the Portuguese recruitment firm Egor Recursos Humanos suffered a cybersecurity breach involving unauthorized access to its website. The attackers executed an external intrusion targeting candidate files stored within the website's memory systems. Compromised data included personally identifiable information such as full names, national identification numbers, residential addresses, contact details, and human resources-related records. Egor's executive leadership, including CEO Afonso Carvalho, confirmed the incident occurred despite existing security measures, characterizing the volume of exfiltrated files as "residual" though no specific quantification was provided. The organization detected the intrusion in real-time and immediately severed external access to the website to contain the breach, preventing ongoing data exposure.

Technical teams promptly initiated forensic analysis to determine the attack vector and operational methodology employed by the threat actors. Corrective security measures were implemented to address identified vulnerabilities, including revisions to access control mechanisms and system hardening to block recurrence pathways. Egor formally notified Portugal's National Data Protection Commission (CNPD) within compliance timelines and engaged judicial authorities for potential legal proceedings. With website functionality restored post-remediation, the firm enlisted cybersecurity specialists to conduct continuous monitoring of implemented safeguards, aiming to detect residual vulnerabilities or subsequent intrusion attempts. Executive communications emphasized operational normalization while apologizing to affected candidates, asserting maximal efforts to mitigate damages and prevent future incidents. Carvalho publicly acknowledged the breach while minimizing reputational amplification concerns, stating controlled disclosure aligned with organizational priorities following regulatory and law enforcement reporting obligations.
