Supply chain
β Supply Chain
French Government Third-Party Breach (February 2021)
Primary Source βIncident Details
Government Contractor Stormshield Suffers Double Breach. French security company warns of customer data and source code theft. A French cybersecurity company with government clients revealed this week that an unauthorized third party has stolen customer data and some of its source code. Airbus subsidiary Stormshield counts the French government among its public sector client list. It claimed that attackers targeted a customer portal used by customers and partners to manage support tickets. Third-party company: Stormshield.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Stormshield
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2021-02-01 Breach occurred
- 2021-02-05 Publicly disclosed