Agence France-Presse reported potential data breach after cyberattack
- Organization
- Agence France-Presse
- Exploit
- Hacking
- Industry
- Media
Agence France-Presse, the Paris based global news agency, said in late September 2024 that a cyberattack had targeted its IT systems and disrupted part of the service that delivers content to client publications. The agency said its newsroom and its services continued to provide news coverage around the world.
AFP subsequently notified the Commission Nationale de l'Informatique et des Libertes, France's data protection regulator, of a potential personal data breach. Under GDPR rules, organizations must report qualifying breaches within 72 hours of discovery. The CNIL confirmed it had received the notification, and AFP said it was working with the regulator to assess the risks.
The agency warned media partners that passwords for the FTP servers used to receive AFP content may have been compromised, and advised them to change those credentials and secure their receiving systems. Parts of the AFP website were intermittently unavailable in the days after the attack, at times redirecting to a maintenance page.
AFP's technical teams worked on the incident with ANSSI, the French national cybersecurity agency. The agency said it was not yet known who carried out the attack or why, and no group publicly claimed responsibility. AFP did not say what types of personal data may have been accessed or how many people were affected.