Daily News

View All News

Belgium – Adecco says data of Belgian staff affected by Suprema leak

22 August 2019

The Adecco Group told Belgium’s privacy regulator that the breach of a security platform run by South Korea’s Suprema ID Inc. compromised the biometric data of some 2,000 employees of its Belgian unit, according to Bloomberg.

The breach of Suprema’s BioStar 2 system affected data including fingerprints and facial recognition details of Adecco employees in Belgium, the country’s data protection authority said in a statement Wednesday.

The regulator said it has contacted Adecco to check the “seriousness of this breach.” A spokeswoman for Suprema declined to comment while an Adecco spokeswoman confirmed that staff data was compromised and that it is "investigating this supplier data breach.”

Suprema had tried to ease concerns on Tuesday, saying in a statement that fewer users were at risk of having been affected than initially thought. "We launched an internal investigation and immediately closed the access point," Suprema said. "In addition, we have also engaged a leading global forensics firm to conduct an in-depth investigation into the incident".

Once lost, data such as digital fingerprints are nearly impossible to retrieve. Cybercriminals, state-sponsored actors and terrorist organizations might be particularly interested in getting their hands on this sort of information, according to security experts.

“This concerns the loss of control of extremely sensitive data of no fewer than 2,000 people,” David Stevens, president of the Belgian watchdog, said in the statement. He said it’s their duty “to shed light on this.”

Under General Data Protection Regulation, European-based companies are required to report a breach if there is a "high risk" of impacting personal data.