Cecotec was hacked in 2023 and the company hid it so far
Cecotec was hacked in 2023 When unidentified attackers had access to the company’s electronic commerce platform (inactive, and it seems that without security updates, for 5 years), accessing a multitude of personal data of its customers.
Specifically, the security gap allowed cybercounts to have access to data such as Name, surname, complete ID, mobile and fixed phones, as well as the postal address of the users.
Beyond the gravity that a company does not offer sufficient protection of its customers’ data, it is especially striking that it has not been until now, two years later, when Cecotec has decided to notify users, without them having been able to take measures since then.
It will be necessary to see if the authorities take any measure in the absence of notification of the theft of personal data by the company, as required by the Spanish Agency for Data Protection (AEPD). According to the law, the company I should have notified the affected customers in 72 hours after the security gap so that these could take prevention measures to attacks that could use their personal data.
In fact, they have waited just 2 years, since the cyber attack took place in April 2023.