{"reference":"BREACH-2025-003","notification_date":"2025-02-20","notification_time":"10:45 CET","phased":"initial","authority":{"name":"Autorité de protection des données (APD/GBA)","portal_case_number":"Pending"},"controller":{"name":"Acme Supplies SRL","address":"Rue de la Loi 100, 1040 Brussels, Belgium","contact_email":"privacy@acme-supplies.eu","dpo_name":"Marie Laurent","dpo_email":"dpo@acme-supplies.eu","dpo_phone":"+32 2 123 45 67"},"breach":{"occurred_on":"2025-02-17","occurred_time":"approximately 23:10 CET","discovered_on":"2025-02-18","discovered_time":"08:30 CET","description":"An unauthorised actor used compromised credentials of a former contractor (whose access had not been revoked at contract end) to log into our customer support tool and export a list of support ticket subjects and submitter email addresses.","nature":["confidentiality"],"root_cause_known":true,"root_cause":"Offboarding process failed to revoke the contractor's SSO account when the contract ended on 2025-01-31. The account remained active and was targeted via credential reuse from a third-party breach."},"data_affected":{"data_subjects_estimated":8742,"data_subjects_notes":"Customers who opened support tickets between 2023-01-01 and 2025-02-17.","records_estimated":12315,"records_notes":"Support ticket subject lines and submitter email addresses. No ticket bodies, attachments or credentials were exported.","data_categories":["Email address","Ticket subject line (free text)","Date of ticket"],"children_affected":false},"consequences":"Low to moderate risk of phishing targeted at the affected customers, given that attackers now know the customers use our product and roughly what issues they raised. No financial data, credentials or special-category data was exposed.","measures":{"taken":["Compromised SSO account revoked within 12 minutes of discovery","Full audit of other contractor accounts; 3 similarly stale accounts revoked","Support tool session tokens rotated; re-authentication forced for all users","Engaged external DFIR firm for scope confirmation","Internal communication to staff outlining the incident and next steps"],"proposed":["Deploy automated offboarding check via HRIS integration (ETA 30 days)","Mandatory 2FA for all SSO accounts by end of Q1","Notify affected data subjects via email once scope is confirmed (Art. 34 assessment in progress)"],"mitigations_effects":"Immediate account revocation prevents further export. External DFIR confirms no secondary movement beyond the support tool. Data subject notification is planned to arm customers against phishing follow-ups."},"data_subject_notification":{"required":true,"sent_on":"2025-02-21","method":"Email to each affected customer, dedicated status page at acme-supplies.eu/incident-2025-003"},"signatory":{"name":"Marie Laurent","title":"Data Protection Officer"}}