Dear students,
Dear partners,
We wish to inform you that a personal data breach was identified in January 2025 within our IT system. It concerns the hacking of the Microsoft account of our education department staff.
This breach could affect certain personal data stored in our systems: bank details, ID cards, student cards, passports, diplomas, CVs, etc. of students and experts who attended courses at the IHU Strasbourg during the period 2013 to 2024. This breach resulted in the loss of confidentiality of the personal data concerned.
As soon as this incident was detected, technical and organizational measures were immediately put in place to secure our systems and limit the risks. The password of the Microsoft 365 account affected by the hacking was immediately changed. Other internal accounts are being checked. 2-factor authentication was quickly adopted by our establishment to reinforce the security of personal accounts.
The French Data Protection Authority (CNIL) has been informed of the breach. A complaint has also been lodged with the public prosecutor.
Due to the nature and volume of the information involved, it is not possible for us to identify and contact all the people concerned individually. The method adopted is individual notification of some of the high-risk data subjects and public information on the website.
We invite you to exercise the utmost vigilance in the face of the risk of fraudulent e-mails, SMS messages or calls, and to ensure the security of your bank card.
In the event of any suspicion or abnormal situation, we invite you to contact the official digital victim assistance service at: www.cybermalveillance.gouv.fr to make a report and assert your rights.
Should you have any questions or queries, please do not hesitate to contact us by e-mail: dpo@ihu-strasbourg.eu or by post, quoting your e-mail address:
Institut de Chirurgie guidée par l’Image (IHU Strasbourg) – DPO
1 place de l’Hôpital – 67091 Strasbourg Cedex, France.
We deeply regret this incident and assure you that we take the protection of your data very seriously. We are committed to implementing all necessary measures to prevent similar incidents in the future.
Thank you for your understanding and trust.
Yours faithfully,
Christian DEBRY
Chief Executive