{"id":29165,"date":"2022-12-06T14:51:04","date_gmt":"2022-12-06T13:51:04","guid":{"rendered":"https:\/\/www.arc-data-shield.fr\/?p=29165"},"modified":"2024-07-02T09:47:52","modified_gmt":"2024-07-02T07:47:52","slug":"lafnor-victime-dune-cyberattaque-par-ransomware-en-fevrier-2021","status":"publish","type":"post","link":"https:\/\/www.arc-data-shield.fr\/en\/lafnor-victime-dune-cyberattaque-par-ransomware-en-fevrier-2021\/","title":{"rendered":"AFNOR to fall victim to ransomware cyberattack in February 2021"},"content":{"rendered":"<p>[et_pb_section fb_built=\u00a0\u00bb1&Prime; _builder_version=\u00a0\u00bb4.16&Prime; background_enable_image=\u00a0\u00bboff\u00a0\u00bb global_colors_info=\u00a0\u00bb{}\u00a0\u00bb][et_pb_row _builder_version=\u00a0\u00bb4.16&Prime; background_size=\u00a0\u00bbinitial\u00a0\u00bb background_position=\u00a0\u00bbtop_left\u00a0\u00bb background_repeat=\u00a0\u00bbrepeat\u00a0\u00bb global_colors_info=\u00a0\u00bb{}\u00a0\u00bb][et_pb_column type=\u00a0\u00bb4_4&Prime; _builder_version=\u00a0\u00bb4.16&Prime; custom_padding=\u00a0\u00bb|||\u00a0\u00bb global_colors_info=\u00a0\u00bb{}\u00a0\u00bb custom_padding__hover=\u00a0\u00bb|||\u00a0\u00bb][et_pb_text _builder_version=\u00a0\u00bb4.16&Prime; background_size=\u00a0\u00bbinitial\u00a0\u00bb background_position=\u00a0\u00bbtop_left\u00a0\u00bb background_repeat=\u00a0\u00bbrepeat\u00a0\u00bb width=\u00a0\u00bb95.8%\u00a0\u00bb global_colors_info=\u00a0\u00bb{}\u00a0\u00bb]<\/p>\n<p><span style=\"font-size: medium;\"><span style=\"font-size: large;\"><span style=\"color: #666666; font-family: inherit; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; display: inline !important; float: none;\">\u00a0\u00bb <\/span><span style=\"font-family: inherit;\">Le 18\u00a0f\u00e9vrier\u00a02021, toute l\u2019activit\u00e9 de l\u2019Afnor \u00e9tait immobilis\u00e9e par une attaque informatique. Le ransomware Ryuk venait de faire une nouvelle victime. Jean-Marc\u00a0Aubert, RSSI de l\u2019Afnor raconte dans le d\u00e9tail cette gestion de crise sur la dur\u00e9e.<\/span><\/span><span style=\"color: #111111; font-family: inherit; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; display: inline !important; float: none; font-weight: normal;\"><\/span><span style=\"color: #3f4853; font-family: inherit; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;\"><span style=\"color: #000000; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; display: inline !important; float: none;\"><\/span><\/span><\/span><\/p>\n<p><span style=\"font-family: inherit; font-size: medium;\"><\/span><\/p>\n<blockquote>\n<p><span style=\"font-family: inherit; font-size: medium;\">Pour l\u2019ext\u00e9rieur, le 18\u00a0f\u00e9vrier\u00a02021 dans l\u2019apr\u00e8s-midi,\u00a0l\u2019Association fran\u00e7aise de normalisation (AFNOR) <a href=\"https:\/\/www.lemagit.fr\/actualites\/252496619\/Cyberattaque-lAfnor-reconnait-etre-confrontee-au-ransomware-Ryuk\"><span style=\"color: #636363;\">parle pudiquement<\/span><\/a> de \u00ab\u00a0probl\u00e8me technique\u00a0\u00bb avec ses sites Web. Son service de presse, heureusement plus transparent, mentionne le ran\u00e7ongiciel Ryuk. En coulisses, tout a commenc\u00e9 quelques heures plus t\u00f4t.<\/span><\/p>\n<p><span style=\"font-size: medium;\"><span style=\"font-family: inherit;\">\u00c0 8h02, un message de l\u2019\u00e9quipe technique signale au DSI de l\u2019Afnor un \u00ab\u00a0petit\u00a0\u00bb souci\u00a0: l\u2019apparition soudaine de fichiers .RYK sur le r\u00e9seau de l\u2019entreprise. Celui-ci interrompt imm\u00e9diatement ses cong\u00e9s et appelle Jean-Marc\u00a0Aubert, actuel RSSI de l\u2019Afnor, alors charg\u00e9 de la s\u00e9curit\u00e9. C\u2019est le d\u00e9but d\u2019une course contre la montre pour bloquer l\u2019attaque, puis de mois de travail pour remettre le syst\u00e8me d\u2019information en production.<\/span><\/span><\/p>\n<p><span style=\"font-size: medium;\"><span style=\"font-family: inherit;\">18 minutes seulement apr\u00e8s le d\u00e9but d\u2019alerte, le DSI et le ComEx d\u00e9cident d\u2019arr\u00eater le syst\u00e8me d\u2019information dans sa totalit\u00e9. \u00ab Tous les ordinateurs sont \u00e9teints et c\u2019est le retour au papier\/crayon pour tout le monde \u00bb, explique Jean-Marc Aubert. \u00ab Nous sommes alors en pleine phase de Covid et tous les collaborateurs sont en confinement. Nous rappelons tous les collaborateurs de la DSI, nous mettons en place une salle de gestion de crise. <\/span><span style=\"font-family: inherit;\">\u00bb<\/span><\/span><\/p>\n<p><span style=\"font-size: medium;\"><span style=\"font-family: inherit;\"><\/span><\/span><\/p>\n<p><span style=\"font-size: medium;\"><span style=\"font-family: inherit; font-weight: normal;\">Branle-bas de combat au si\u00e8ge de l\u2019AFNOR<\/span><\/span><\/p>\n<p><span style=\"font-size: medium;\"><span style=\"font-family: inherit; font-weight: normal;\">Tout le syst\u00e8me d\u2019information est arr\u00eat\u00e9 et la cellule de gestion de crise s\u2019organise rapidement. L\u2019\u00e9quipe informatique appelle ses contacts \u00e0 l\u2019aide et s\u2019occupe du volet d\u00e9claratif de la cyberattaque. L\u2019Agence nationale de la s\u00e9curit\u00e9 des syst\u00e8mes d\u2019information (Anssi) est pr\u00e9venue, de m\u00eame que l\u2019assureur. Une plainte est d\u00e9pos\u00e9e au commissariat de quartier et la d\u00e9claration obligatoire aupr\u00e8s de la CNIL est r\u00e9alis\u00e9e dans le d\u00e9lai des 72\u00a0heures.<\/span><span style=\"font-family: inherit; font-weight: normal;\">Jean-Marc Aubert se tourne aussi vers l\u2019Office central de lutte contre la criminalit\u00e9 li\u00e9e aux technologies de l\u2019information et de la communication (OCLCTIC) qui conna\u00eet bien ce type d\u2019attaque contre les entreprises fran\u00e7aises. \u00ab Nous avions heureusement souscrit \u00e0 une assurance cyber un an avant la cyberattaque. Un autre atout qui nous a \u00e9t\u00e9 pr\u00e9cieux fut le contrat d\u2019assistance que nous avions sign\u00e9 avec Airbus Protect et qui nous a permis de d\u00e9marrer tr\u00e8s rapidement notre gestion de crise. Et si notre premier appel fut pour l\u2019Anssi, le deuxi\u00e8me fut pour notre contact commercial chez Airbus Protect \u00bb. \u00ab\u00a0<\/span><\/span><span style=\"font-size: medium; font-family: inherit; font-weight: normal;\"><\/span><span style=\"color: #3f4853; font-family: inherit; font-size: medium; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;\"><span style=\"color: #000000; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; display: inline !important; float: none;\"><br \/><\/span><\/span><\/p>\n<\/blockquote>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.lemagit.fr\/etude\/Ransomware-le-RSSI-de-lAfnor-raconte-la-cyberattaque-de-fevrier-2021\">https:\/\/www.lemagit.fr\/etude\/Ransomware-le-RSSI-de-lAfnor-raconte-la-cyberattaque-de-fevrier-2021<\/a><\/p>\n<p>Cr\u00e9dit : <a href=\"https:\/\/www.lemagit.fr\/etude\/Ransomware-le-RSSI-de-lAfnor-raconte-la-cyberattaque-de-fevrier-2021\">Alain Clapaud &#8211; LeMagIT<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u00a0\u00bb Le 18\u00a0f\u00e9vrier\u00a02021, toute l\u2019activit\u00e9 de l\u2019Afnor \u00e9tait immobilis\u00e9e par une attaque informatique. Le ransomware Ryuk venait de faire une nouvelle victime. Jean-Marc\u00a0Aubert, RSSI de l\u2019Afnor raconte dans le d\u00e9tail cette gestion de crise sur la dur\u00e9e. Pour l\u2019ext\u00e9rieur, le 18\u00a0f\u00e9vrier\u00a02021 dans l\u2019apr\u00e8s-midi,\u00a0l\u2019Association fran\u00e7aise de normalisation (AFNOR) parle pudiquement de \u00ab\u00a0probl\u00e8me technique\u00a0\u00bb avec ses sites [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":29170,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.\n\n<img class=\"aligncenter wp-image-28717 size-full\" src=\"https:\/\/arc-data-shield.fr\/wp-content\/uploads\/2017\/02\/article_1.jpg?_t=1488209924\" width=\"1400\" height=\"933\" \/>\n\nUt velit mauris, egestas sed, gravida nec, ornare ut, mi. Aenean ut orci vel massa suscipit pulvinar. Nulla sollicitudin. Fusce varius, ligula non tempus aliquam, nunc turpis ullamcorper nibh, in tempus sapien eros vitae ligula. Pellentesque rhoncus nunc et augue. Integer id felis. Curabitur aliquet pellentesque diam. Integer quis metus vitae elit lobortis egestas. Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Morbi vel erat non mauris convallis vehicula. Nulla et sapien. Integer tortor tellus, aliquam faucibus, convallis id, congue eu, quam. Mauris ullamcorper felis vitae erat. Proin feugiat, augue non elementum posuere, metus purus iaculis lectus, et tristique ligula justo vitae magna.\n\n<img class=\"alignnone size-full wp-image-28719\" src=\"https:\/\/arc-data-shield.fr\/wp-content\/uploads\/2017\/02\/second_image.jpg\" alt=\"\" width=\"1400\" height=\"933\" \/>\n\nAliquam convallis sollicitudin purus. Praesent aliquam, enim at fermentum mollis, ligula massa adipiscing nisl, ac euismod nibh nisl eu lectus. Fusce vulputate sem at sapien. Vivamus leo. Aliquam euismod libero eu enim. Nulla nec felis sed leo placerat imperdiet. Aenean suscipit nulla in justo. Suspendisse cursus rutrum augue. Nulla tincidunt tincidunt mi. Curabitur iaculis, lorem vel rhoncus faucibus, felis magna fermentum augue, et ultricies lacus lorem varius purus. Curabitur eu amet.","_et_gb_content_width":"","footnotes":""},"categories":[20],"tags":[],"class_list":["post-29165","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-commonnews"],"_links":{"self":[{"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/posts\/29165","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/comments?post=29165"}],"version-history":[{"count":6,"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/posts\/29165\/revisions"}],"predecessor-version":[{"id":30202,"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/posts\/29165\/revisions\/30202"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/media\/29170"}],"wp:attachment":[{"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/media?parent=29165"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/categories?post=29165"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/tags?post=29165"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}