FIA discloses data breach after phishing attacks on two email accounts

Organization
Fédération Internationale de l'Automobile (FIA)
Exploit
Phishing
Industry
Sports Governing Body

The Fédération Internationale de l'Automobile, the body that governs Formula 1 and the World Rally Championship, disclosed in early July 2024 that phishing attacks had led to unauthorized access to personal data held in two of its email accounts.

In a short statement, the FIA said it had taken all actions to rectify the issues, notably by cutting the illegitimate accesses in a very short time once it became aware of the incidents. It said additional security measures had since been put in place but did not describe them.

The organisation notified two regulators: the Commission Nationale de l'Informatique et des Libertés in France and the Préposé Fédéral à la Protection des Données et à la Transparence in Switzerland, reflecting its presence in both jurisdictions.

Several basic questions went unanswered. The FIA did not say when the phishing messages arrived or when the breach was detected, how many individuals had data exposed, what categories of personal information sat in the affected mailboxes, or who was behind the attack. Nothing in its account indicated ransomware or a wider network compromise. As of the reporting date the statement remained the FIA's only public description of the incident.

Sources