Belgium’s table tennis federations are investigating a Belgium sports federations cyberattack after a hacker claimed to have stolen data belonging to tens of thousands of members and users. The French-speaking Association Francophone de Tennis de Table (AFTT) confirmed the cyberattack and said the Royal Belgian Table Tennis Federation (FRBTT) was also affected. The federations are working with their IT provider to determine whether any data was accessed or compromised.
The incident comes as the French-speaking Gymnastics Federation separately investigates unauthorized access to part of its IT environment.
The federation confirmed that some personal data belonging to members and clubs was extracted and said it has notified Belgium’s Data Protection Authority.
Jean-Michel Mureau, president of the French-speaking Association Francophone de Tennis de Table (AFTT), confirmed over the weekend that the organization had suffered a cyberattack. He also said the Royal Belgian Table Tennis Federation (FRBTT) had been affected.
The federation was alerted to the incident on Thursday and asked its IT provider to investigate the extent of the incident. Mureau said the investigation was intended to establish exactly what data may have been compromised.
In a statement released Monday, the federation said it had conducted several checks, including with the service provider responsible for its results website. Those checks had not found evidence that the provider’s infrastructure had been compromised.
“As soon as we became aware of this information, we conducted several checks, including with our service provider in charge of the results website. At this stage, the checks carried out have not revealed any evidence to suggest that their infrastructure has been compromised,” reads press statement.
The federation also said information referenced in press reports appeared, for the most part, to consist of information that was already publicly available.
The federation said it had conducted additional checks on its own server and reinforced several security measures as a precaution. It stated that it was not currently aware of any access to or retrieval of members’ telephone numbers or email addresses.
However, the organization said its checks were continuing and that it could not provide an absolute guarantee until the analysis was complete.
If further investigation identifies a breach involving personal data, the federation said it would take the necessary steps and notify affected individuals in accordance with applicable regulations.
The organization also clarified that a separate issue involving missing players from rosters on Saturday evening was not connected to the cyberattack. According to the information available to the federation, that issue resulted from a synchronization problem.
The French-speaking Gymnastics Federation subsequently confirmed a separate cybersecurity incident involving personal data belonging to members and clubs.
The federation said it discovered on September 14 that unauthorized individuals had accessed part of its IT environment and extracted some data. Experts were brought in after the discovery, and the federation said the access route was neutralized, affected access points were secured, and enhanced monitoring was introduced.
The incident was also reported to the Data Protection Authority responsible for GDPR matters.
According to the French-speaking Gymnastics Federation, the data that may have been accessed or extracted includes names, mailing addresses, email addresses, telephone numbers, dates of birth and gender.
The information may also include affiliation details and history, management training diplomas, judges’ licenses, and limited information connected to accident reports, specifically the date and file number rather than the reports themselves.
The federation said it had not observed any use of the data so far. It warned that the information could potentially be used in attempts to obtain additional personal information by impersonating a trusted organization or individual.
Members were advised to remain alert to unusual emails, messages and calls, avoid disclosing passwords or confidential information following unexpected requests, and verify sender addresses before opening links or attachments.
Both incidents remain subject to ongoing investigation and security checks.