Ransomware – EDC
Company
EDC
Sector
Real Estate
Actor
Black Basta
##Description
Denmark's largest estate agency chain was attacked on 1 November 2023 by the ransomware group Black Basta, which exfiltrated around 2.5 TB of data. The attackers did not reach EDC's main case-management server; they obtained a backup file that had been created by human error and left accessible.
The stolen data was mostly contact information — phone numbers, email addresses and home addresses, including protected addresses — but also close to 100,000 CPR numbers. For roughly 1,300 people it included copies of passports, driving licences and health insurance cards.
Black Basta demanded USD 6 million. EDC did not pay, and in November 2023 the group published the data on the dark web. Version2's follow-up reporting found EDC had been missing central security controls.
One of the largest exposures of Danish CPR numbers by a private company, and a textbook case of an incidental backup becoming the entire blast radius.
##Timeline
- 2023-11-01
Black Basta compromises EDC and exfiltrates ~2.5 TB
- 2023-11-10
EDC confirms the breach; ~100,000 CPR numbers compromised
- 2023-11-19
Attackers threaten to publish the data
- 2023-11
Data published on the dark web
##References
- TV 2 — EDC er blevet hacket: knap 100.000 cpr-numre er kompromitteret
- DR — Ejendomsmæglerkæden EDC hacket: Cpr-numre er blevet stjålet
- TV 2 — Hackere truer med at dele oplysninger efter EDC-angreb
- DR — Russiske hackere har frigivet tusindvis af danske EDC-kunders personlige oplysninger
- DR — 100.000 CPR-numre lækket på det mørke net
- Version2 — Inficeret e-mail var hackernes adgang under ransomwareangrebet mod EDC
- Version2 — Efter stort datalæk: EDC manglede helt central it-sikkerhed