Your supplier has been hacked
Complete plan
A supplier announces it was hacked, or you find out: alert your own people, ask it the right questions, cut what connects it to you, and beware of invoices and emails from its mailbox.
- 3 min
- 3-question check
- English · Français
- Attestation
You will be able to
- Alert IT security at once, the DPO if personal data may be affected, and management
- Ask the supplier, in writing, what is affected, since when, what has been done, which signs to watch and who the contact is
- Suspend its access and connections, change shared passwords and keys, and check any invoice or request from its mailbox through a known number
The module
3 min-
Your supplier has been hacked 2 min
-
Knowledge check
3 questions, pass mark 80 %. Explanations after each answer; you can try again.
-
Attestation
One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.
Sources
- RGPD, art. 33(1) (« without undue delay and, where feasible, not later than 72 hours after having become aware of it »), 33(2) (« The processor shall notify the controller without undue delay after becoming aware of a personal data breach »), 33(3) (lu en entier, copie GitHub du texte du JO)
- CEPD, lignes directrices 9/2022 sur la notification des violations, v2.0 (28 mars 2023) : le responsable est considéré comme informé (« aware ») dès que le sous-traitant l'a prévenu (lu en extrait de recherche seulement)
- Okta, analyse de l'incident du système de support (3 novembre 2023) ; Cloudflare, billet du 1er février 2024 : identifiants exposés lors de l'incident Okta, non changés car jugés inutilisés, puis utilisés par un attaquant en novembre 2023 (lus en extrait de recherche seulement, via la presse ; aucun chiffre dans la voix)
- Cybermalveillance.gouv.fr, fiche réflexe fraude au virement (février 2024) : « Ce type d'escroquerie est souvent consécutif au piratage d'un compte de messagerie (mail) » ; prévenir le créancier usurpé car « il est possible que l'un de ses comptes de messagerie ait été piraté » (lu en extrait de recherche seulement)
- Progress, avis MOVEit Transfer (31 mai 2023, relayé par HHS HC3 le 2 juin 2023) : couper le trafic, réinitialiser les identifiants des comptes de service, supprimer les comptes non autorisés (extrait de recherche seulement)
- ISO/IEC 27001:2022, annexe A, 5.19, 5.21, 5.24, 5.26 (intitulés) ; directive NIS 2, art. 21(2)(b) et (d)
Version 1 · updated October 6, 2026