Harvest
bd_df049f805316929f · schema v1 · pii pii-v1
Full breach record for Harvest →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage and machine-translated to English — verify against the source.
Summary
machine-translatedRansomware: French FinTech Harvest victim of a cyberattack | LeMagIT. Harvest: The French FinTech Harvest, which has more than 4,600 client companies, was the victim of a ransomware cyberattack on February 27, making its website and services inaccessible. The company has not yet officially communicated about the incident, but established data is unavailable, forcing its clients to notify the CNIL. The extent of the damage and the impact on Harvest's activity remain unknown for now. Linked ransomware group: RunSomeWares.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Feb 27, 2025
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siterunsomewaresbd_b2cce554c0aee6042025-04-10 · +42dCandidate
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.