ctipilot.ch

CCI Nice Côte d'Azur eDRH administrator-account export breach (July 2026)

incident · incident:cci-nice-cote-dazur-edrh-breach-2026-07 single-source

Compromise of an administrator account on the eDRH candidate-and-company platform of the Chambre de commerce et d'industrie Nice Côte d'Azur, the French public-law chamber of commerce for the Alpes-Maritimes. On 2026-07-18 an unauthorised party used the account's legitimate export functions to generate several exports of registered candidate and company data, including name, email, telephone, date of birth, professional history, education level and account timestamps. The chamber has not disclosed the account-takeover vector, the duration of access, or the number of people affected (Cyberattaque.org, FrenchBreaches.com, 2026-07-31/2026-08-01).

Coverage timeline
1
first 2026-08-02 → last 2026-08-02
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
2
pinned v19.1 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

2 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-02/cci-nice-cote-dazur-edrh-admin-account-export-breach · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-02/cci-nice-cote-dazur-edrh-admin-account-export-breach · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-02/cci-nice-cote-dazur-edrh-admin-account-export-breach · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-02/cci-nice-cote-dazur-edrh-admin-account-export-breach · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-08-02/cci-nice-cote-dazur-edrh-admin-account-export-breach · ATT&CK page ↗

Story timeline

  1. 2026-08-02CCI Nice Côte d'Azur: a compromised administrator account on the chamber's jobseeker platform was used to run the platform's own export function
    active-threatsA French public-law chamber of commerce confirms bulk candidate-data exports run from a hijacked admin account, with the takeover route undisclosed

Where this entity is cited

  • active-threats1

Source distribution

  • cyberattaque.org1 (50%)
  • frenchbreaches.com1 (50%)

explore in graph

Entries about CCI Nice Côte d'Azur eDRH administrator-account export breach (July 2026) (1)

2026-08-02 · view entry permalink →

NOTABLENATOC2

CCI Nice Côte d'Azur: a compromised administrator account on the chamber's jobseeker platform was used to run the platform's own export function

The Chambre de commerce et d'industrie Nice Côte d'Azur — the public-law chamber of commerce serving businesses and project founders in the Alpes-Maritimes — has confirmed a security incident affecting its eDRH platform, which brings together candidate profiles and registered companies around employment and recruitment. On 2026-07-18, "un accès non autorisé à un compte administrateur a permis la réalisation de plusieurs exports contenant des informations sur des candidats et des entreprises" — an unauthorised party reached an account holding administrator rights and used it to generate several exports covering registered candidates and enrolled companies (Cyberattaque.org, 2026-08-01). This was not a blocked attempt — files were actually produced — and the chamber has not published the number of people affected or the total volume exported (Cyberattaque.org, 2026-08-01). A second French breach tracker reproduces the same notification (FrenchBreaches.com, 2026-07-31).

Per the notification sent to affected individuals, the fields that may have been consulted or exported are surname and first name, email address, telephone number, date of birth, professional experience and career history, education level, profile title and stated attributes, contact and notification preferences, account-creation date and last-login date (Cyberattaque.org, 2026-08-01). The chamber says it engaged technical measures with its service provider on detection to end the unauthorised access and secure the platform, and it does not say how long the account remained accessible or how many exports ran before it was blocked. Cyberattaque.org adds in its own voice — not as a statement from the chamber — that nothing disclosed supports a conclusion that the chamber's wider IT estate was compromised (Cyberattaque.org, 2026-08-01).

How the account was taken over is explicitly not stated. The relayed account lists a stolen password, a phishing campaign, credential reuse and session hijacking as the possibilities without selecting one (Cyberattaque.org, 2026-08-01) — a gap worth stating plainly rather than filling, because it is the one fact that would tell another public body which control to check first.

Detection concepts follow from what the attacker actually did after authenticating, which is the reason this is worth carrying despite the thin technical detail: no tooling was deployed and nothing was exploited on the way out. Once holding administrator rights, the intruder used the platform's own legitimate export functions to retrieve candidate and company lists. How those rights were obtained is a separate and undisclosed question — the possibilities the notification's relay lists include session hijacking, which can itself involve a software flaw, so this is not a case where the absence of a vulnerability has been established. The telemetry that catches this sits in the SaaS or hosted application's own audit log rather than in endpoint or network telemetry — administrative authentication events assessed against the account's normal geography, hours and device, followed by export or bulk-read operations assessed against that account's normal export volume and cadence. Triage: administrators of an HR or CRM platform legitimately run exports, so the export event alone discriminates nothing; the separating signals are an export by an account that has never run one, a run of exports compressed into a single session, and an export whose result-set size has no precedent for that account — and, upstream, an administrative sign-in whose source or timing breaks that account's own pattern.

un accès non autorisé à un compte administrateur a permis la réalisation de plusieurs exports contenant des informations sur des candidats et des entreprises

Un attaquant connaissant le parcours, le niveau d'études et les coordonnées d'un candidat peut se faire passer pour un recruteur, une entreprise ou un conseiller de la CCI.

Cyberattaque.org 2026-08-01
incident02 Aug 04:09Zsingle-sourceOpen finding ↗