The incident has been “contained”. However, the data breach has not yet been contained. In an email sent on Saturday 1 August, the Chamber of Employees informed some of its contacts that “unauthorised access to certain CSL servers” had been identified. The organisation states that it has secured the systems concerned and has launched an investigation with the support of cybersecurity specialists.
The attack may have exposed full names, email and postal addresses, as well as private and work telephone numbers. The message also refers to “certain financial information” and, where applicable, participation in training courses organised by the CSL.
At this stage, the Chamber does not confirm that this information was, in fact, stolen. It states that the perpetrator of the breach “may potentially have accessed or extracted certain personal data”. This wording leaves two possibilities open: access to the databases without evidence of data exfiltration, or a copy of information whose content and volume have yet to be established.
The CSL does not specify either the number of people potentially affected or the exact nature of the financial data that was accessed. Nor does it state which servers were compromised, for how long the intruder was able to access them, or by what method. “In-depth technical investigations are still ongoing […] to determine precisely the origin, timeframe, scope and consequences of this access,” it states.
Target groups among those undertaking training courses
The incident affects an organisation whose scope extends far beyond its own staff. The CSL represents more than 630,000 employees, apprentices, pensioners and jobseekers, both residents and cross-border workers, making it the country’s largest trade union. However, this figure does not correspond to the number of potential victims of the attack, which remains unknown. The information mentioned in the email appears to relate in particular to contacts with the organisation and its training activities. Its Luxembourg Lifelong Learning Centre organises evening classes, seminars, university courses and certification programmes.
The main immediate threat lies in the use of genuine data to make a scam appear credible. An attacker who knows an employee’s name, employer, contact details or participation in a training course can personalise an email, text message or phone call. The CSL therefore recommends verifying any request for payment, a refund or a change to bank details via a second channel, and never disclosing a password or verification code. The institution has also announced that it will file a criminal complaint “against the alleged perpetrators of the attack”. It has appointed a contact at the Luxembourg-based cybersecurity firm Rsecure for technical enquiries and is referring requests relating to personal data to its Data Protection Officer.



