France’s data protection authority, CNIL, imposed a €1.7 million ($2 million) fine on the software company Nexpublica France following a data breach that exposed sensitive documents of third parties through a company portal. The breach, reported in November 2022, allowed users to access documents belonging to other individuals, prompting an investigation by CNIL, which found that Nexpublica’s data security program was insufficient and failed to meet basic security standards.
The regulator cited several aggravating factors in determining the fine, including Nexpublica’s lack of awareness of fundamental security principles, the number of people affected, the sensitivity of the exposed data, and the company’s financial capacity. CNIL also noted that Nexpublica was aware of the security issues prior to the breach but did not take corrective action until after the incident, constituting a violation of the General Data Protection Regulation (GDPR).

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
CNIL imposed a €1.7 million fine on Nexpublica France for inadequate cybersecurity practices tied to the breach, citing the company's financial capacity, poor basic security knowledge, the number of affected people, and the sensitivity of the exposed data.
Following its investigation, France's data protection regulator CNIL concluded that Nexpublica had known about the security weaknesses before the breach and only addressed them afterward, in violation of GDPR security requirements.
In November 2022, users of a Nexpublica France portal found they could access documents belonging to third parties, revealing a data breach affecting sensitive information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.