A Labor Law Database Under Siege
The Centre National du Droit du Travail is facing a potential security crisis. An individual using the alias TimeSape, claiming to represent the collective LunarisSec, alleges they have exploited a SQL injection vulnerability to compromise the website’s database, according to reports from Cyberattaque.org.
The Scope of the Alleged Exposure
The attackers assert they have extracted 150,000 lines of data from centre-national-droit-du-travail.fr. The haul purportedly includes information relative to accounts, coordinates, companies, orders, and records of legal content access.
The claimants have provided a list of fields they suggest were compromised: names, first names, postal addresses, postal codes, cities, countries, phone numbers, email addresses, fax numbers, and company names. Further logs allegedly include account usernames, creation or activation dates, expiration dates, and last access timestamps. The hackers pointed to fields labeled "password" and "password_sas," though it is currently unverified whether these entries hold actual passwords or how that data is stored.

Centre National Du Droit Du Travail Has Not Confirmed Breach
There is no independent confirmation that the breach occurred. Cyberattaque.org has not secured access to the database or any samples that would validate the hackers’ claims. Consequently, the authenticity of the leak, the volume announced, and the existence of the claimed SQL injection vulnerability remain unconfirmed.
The Centre National du Droit du Travail has yet to issue a public statement. Because the 150,000 lines of data may contain multiple entries for a single person—such as separate records for an account, order, address, subscription, or access history—the total number of affected individuals is currently unknown and cannot be calculated from the hackers' assertions.
Heightened Phishing Risks
If the data is proven authentic, the exposure of professional and personal contact information invites targeted phishing campaigns. Attackers could impersonate the Centre National du Droit du Travail to solicit payments or sensitive information by referencing a collective agreement, orders, a subscription, or regulatory updates.
SQL Injection Risks Prompt Vigilance for Users
A SQL injection occurs when the controls of an application are insufficient, allowing an attacker to interact with its database in unauthorized ways. Depending on the rights associated with the technical account used by the application, the impact can range from the consultation of some information to the extraction of a much larger volume of data.
Until the organization confirms or denies the breach, users should remain vigilant. If you receive unexpected emails or phone calls claiming to be from the Centre National du Droit du Travail requesting payment or account verification, do not provide any information and contact the organization through their official, verified channels.
Related reading