Orange confirmed that it had suffered a ransomware attack, saying that the data of twenty of its corporate customers was exposed.
Orange is a French telecommunications company that offers consumer communications services and business services to businesses. With 266 million customers and 148,000 employees, Orange is the fourth largest mobile operator in Europe.
As part of its services portfolio, the Orange Business Services division offers business solutions with services such as remote support, virtual workstations , system security and cloud backup and hosting.
Nefilim ransomware leaks Orange customer data
On July 15, 2020, the ransomware operators behind the Nefilim Ransomware reported Orange on the data leak site they maintain and stated that they breached the company through the “Orange Business Solutions” division.
Orange confirmed to BleepingComputer that it fell victim to a ransomware attack targeting its Orange Business Services division on the evening of Saturday, July 4, 2020, through July 5.
This attack allowed Nefilim operators to gain access to the data of twenty Orange Pro/SME customers.
“A malware-type computer attack was detected by Orange teams during the night of Saturday 04 July to Sunday 05 July 2020. Orange teams immediately mobilized to identify the origin of this attack and have put in place all the necessary solutions required to ensure the security of our systems. According to the initial analysis of security experts, this attack concerned data hosted on one of Neocles’ IT platforms, “Le Forfait informatique” and no other services have been affected. However, this attack appears to have allowed hackers to gain access to the data of approximately 20 PRO/SME customers hosted on the platform. Affected customers have already been informed by Orange teams and Orange continues to monitor and investigate this breach. Orange apologizes for the disruption caused.”
Orange's "Le Forfait Informatique" platform allows corporate customers to host virtual workstations in the cloud, while also providing external support for these hosted workstations to Orange Business Services.
As part of the leak, a 339MB archive file titled "Orange_leak_part1.rar" was published which contained data allegedly stolen from Orange during the attack.

The Ransom Leaks Twitter account, run by researchers who analyze ransomware leaks, said this archive contained emails, airplane blueprints, and files from ATR Aircraft, a French aircraft manufacturer.
This data may indicate that ATR is a customer of Orange's Le Forfait Informatique platform and was stolen during the attack.
Ransomware attacks are data breaches
Since file encryption is not a strong component of ransomware operations targeting companies, all attacks should be considered data breaches.
Almost all ransomware attacks now include a pre-encryption component where attackers steal unencrypted files from the victim.
The threat of publishing these stolen files is the latest leverage used to force victims to pay the ransom.
Although Orange did the right thing by informing its customers about the attack, it is equally vital for affected customers to disclose these breaches to their customers and employees .
Employees are usually the last to learn about these attacks, but they are also at great risk as their personal information is made public or sold to other threat actors.
