CSIDB logo
Incident

Staedion

Incident posture

Attack window
May 2024
Location
Netherlands
Status
Historical
CIA posture
Available to members
Updated
2025-12-30 19:43

Linked entities

Victim
Staedion
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A data breach occurred at Staedion's communications supplier AddComm, potentially exposing tenant personal data, though specific compromised details remain undetermined and no passwords were confirmed leaked. The housing association reported the incident to Dutch data protection authorities while AddComm investigates the scope and nature of accessed information. Tenants were alerted to heightened phishing risks through fraudulent communications impersonating the organization, with guidance provided to identify legitimate correspondence via official email domains and absence of password or payment requests.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On May 17, 2024, Dutch housing corporation Staedion disclosed a data breach involving its third-party supplier AddComm, which provides digital communication services for tenant interactions. The incident involved unauthorized access to Staedion tenant personal data processed by AddComm, though the specific types of compromised data remained undetermined at the time of disclosure. Staedion confirmed no passwords were exposed in the breach. AddComm initiated an investigation to determine whether data theft occurred and to identify the exact scope of affected records. Staedion filed a mandatory breach notification with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) following discovery of the incident. The organization committed to notifying affected tenants promptly upon receiving confirmation from AddComm regarding whose data was involved and which data elements were accessed.

Staedion issued warnings to tenants about heightened phishing risks stemming from the breach, advising vigilance against unsolicited communications via email, SMS, WhatsApp, phone calls, or physical mail impersonating Staedion. The alert specified that legitimate Staedion emails exclusively use domains @staedion.nl or @nieuwsbrief.staedion.nl and emphasized that the organization never requests banking details, PINs, or passwords through any channel. Tenants were instructed to report suspicious communications to [email protected] or via a dedicated phone line and to terminate calls if asked for sensitive information. The supplier investigation remained ongoing with no public timeline for resolution, leaving the full impact on tenants undefined beyond the confirmed absence of credential exposure.

Sources

Sources available to members: 1 source.

CSIDB