ctipilot.ch
← Back to the live brief
NOTABLENATOC2incident

CCI Nice Côte d'Azur: a compromised administrator account on the chamber's jobseeker platform was used to run the platform's own export function

discovered 2026-08-02 04:09 UTCrun 2026-08-02T0409Z-intel2 sourcessingle-source

The Chambre de commerce et d'industrie Nice Côte d'Azur — the public-law chamber of commerce serving businesses and project founders in the Alpes-Maritimes — has confirmed a security incident affecting its eDRH platform, which brings together candidate profiles and registered companies around employment and recruitment. On 2026-07-18, "un accès non autorisé à un compte administrateur a permis la réalisation de plusieurs exports contenant des informations sur des candidats et des entreprises" — an unauthorised party reached an account holding administrator rights and used it to generate several exports covering registered candidates and enrolled companies (Cyberattaque.org, 2026-08-01). This was not a blocked attempt — files were actually produced — and the chamber has not published the number of people affected or the total volume exported (Cyberattaque.org, 2026-08-01). A second French breach tracker reproduces the same notification (FrenchBreaches.com, 2026-07-31).

Per the notification sent to affected individuals, the fields that may have been consulted or exported are surname and first name, email address, telephone number, date of birth, professional experience and career history, education level, profile title and stated attributes, contact and notification preferences, account-creation date and last-login date (Cyberattaque.org, 2026-08-01). The chamber says it engaged technical measures with its service provider on detection to end the unauthorised access and secure the platform, and it does not say how long the account remained accessible or how many exports ran before it was blocked. Cyberattaque.org adds in its own voice — not as a statement from the chamber — that nothing disclosed supports a conclusion that the chamber's wider IT estate was compromised (Cyberattaque.org, 2026-08-01).

How the account was taken over is explicitly not stated. The relayed account lists a stolen password, a phishing campaign, credential reuse and session hijacking as the possibilities without selecting one (Cyberattaque.org, 2026-08-01) — a gap worth stating plainly rather than filling, because it is the one fact that would tell another public body which control to check first.

Detection concepts follow from what the attacker actually did after authenticating, which is the reason this is worth carrying despite the thin technical detail: no tooling was deployed and nothing was exploited on the way out. Once holding administrator rights, the intruder used the platform's own legitimate export functions to retrieve candidate and company lists. How those rights were obtained is a separate and undisclosed question — the possibilities the notification's relay lists include session hijacking, which can itself involve a software flaw, so this is not a case where the absence of a vulnerability has been established. The telemetry that catches this sits in the SaaS or hosted application's own audit log rather than in endpoint or network telemetry — administrative authentication events assessed against the account's normal geography, hours and device, followed by export or bulk-read operations assessed against that account's normal export volume and cadence. Triage: administrators of an HR or CRM platform legitimately run exports, so the export event alone discriminates nothing; the separating signals are an export by an account that has never run one, a run of exports compressed into a single session, and an export whose result-set size has no precedent for that account — and, upstream, an administrative sign-in whose source or timing breaks that account's own pattern.

un accès non autorisé à un compte administrateur a permis la réalisation de plusieurs exports contenant des informations sur des candidats et des entreprises

Un attaquant connaissant le parcours, le niveau d'études et les coordonnées d'un candidat peut se faire passer pour un recruteur, une entreprise ou un conseiller de la CCI.

Cyberattaque.org 2026-08-01

ATT&CK mapping

2 techniques mapped from the cited reporting · MITRE ATT&CK v19.1

Initial Access TA0001
T1078Valid Accounts

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

overlap matrix · ATT&CK page ↗

Persistence TA0003
T1078Valid Accounts

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

overlap matrix · ATT&CK page ↗

Privilege Escalation TA0004
T1078Valid Accounts

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

overlap matrix · ATT&CK page ↗

Stealth TA0005
T1078Valid Accounts

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

overlap matrix · ATT&CK page ↗

Collection TA0009
T1213Data from Information Repositories

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.