CDC Biodiversité
bd_e8ce8274c8107831 · schema v1 · pii pii-v1
Full breach record for CDC Biodiversité →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage and machine-translated to English — verify against the source.
Summary
machine-translatedInformation Notice | CDC Biodiversité. CDC Biodiversité: CDC Biodiversité has been the victim of a ransomware cyberattack since September 26, 2024. A crisis management team has been established to investigate and resolve the incident, with priority given to protecting the information of clients, suppliers, and employees. The objective is to restore normal system operations as soon as possible. Linked ransomware group: blackout.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Sep 26, 2024
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteblackoutbd_53ed5eb187463a5f2024-09-26Candidate
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
blackout
According to ransomware.live, Blackout is a ransomware group that first appeared in early 2024, initially claiming attacks against healthcare entities in Canada, France, and Germany before expanding to telecommunications, mining, and manufacturing sectors, operating a double-extortion model with a data leak site.