DisclosureLens
GLOBALtranslated → enUnknownLow

PTAC

bd_a01d8353a7c0b192 · schema v1 · pii pii-v2

Severity

Low

Discovered

Filed

Sep 3, 2026

To disclose

Affected

Not disclosed

Confidence

60%
Full breach record for PTAC

Press / market disclosure — not a breach-notification filing

A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage and machine-translated to English — verify against the source.

Summary

machine-translated

"Cert.lv" reveals how the cyberattack on the PTAC system occurred. PTAC: Le Centre de protection des droits des consommateurs (PTAC) was the victim of a cyberattack that allowed an attacker to access data through a vulnerability in the public part of its statistics system (ASDIS). The incident was detected by the cybersecurity institution Cert.lv. The stolen data includes the contact details of 697 commercial representatives and 34 PTAC officials. PTAC confirmed that the stolen data consisted of contact information (name, first name, email, phone number) and that no sensitive personal data was stored. PTAC has closed the affected system and notified the relevant authorities.

Incident timeline — mostly unverified

? — ?

Breach window unknown

Sep 3, 2026

Press report

No filing yet · watching

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Attack → press

Compliance clock

Not assessable

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market reportThis record

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

If an SEC 8-K, state-AG notice or victim statement lands, DisclosureLens merges it into an incident and links it here.

Source ceiling

  • incident type + narrative only (may be machine-translated)
  • discovery date
  • materiality
  • affected count
  • data types
  • compliance clock

The ✕ fields stay blank until a regulatory filing or victim disclosure lands.