← All resources

Data breach at FWB: three weeks before it was confirmed (05/10)

Published October 7, 2026 · 7 min read · CyberNovaLabs.io

Flagged from outside in mid-September, confirmed on 5 October 2026: the EAD-online.be data breach shows where the GDPR's 72 hours are really lost, and why the weak link is so often a supplier.

In short

On 5 October 2026 the Federation Wallonie-Bruxelles confirmed a cyberattack on EAD-online.be, its distance-learning platform: according to its education administration, a flaw was exploited by a malicious third party and data was exfiltrated[1]. Around 19,456 people are potentially affected; the sample published by the attacker contains surnames, first names and email addresses[1][2]. The attack had already been reported publicly in mid-September by a breach-monitoring site, roughly three weeks before the official confirmation, and the platform stays closed until mid-October[2][3].

Why this breach matters to your SME

Three details here apply to any company in the four countries we work in. One: the alert came from outside, not from the victim. Two: the affected platform is not run in-house but by a third party, ETNIC, the Federation's IT body[1]. Three: the exfiltrated data is only names and email addresses, which is exactly what a convincing phishing campaign needs.

None of those three features depends on headcount. A twelve-person SME exposing a client extranet, a training portal or a document drop-box sits in the same configuration: a public component, maintained by somebody else, holding named personal data.

And if your supplier is breached, it is your name in the press and your obligation that starts running. A processing agreement organises cooperation; it does not transfer your position as controller.

When the data breach notification clock starts

The GDPR (Article 33(1)) requires the controller to notify a personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it[4]. Two points are routinely misread:

Article 33(2) adds that the processor shall notify the controller without undue delay after becoming aware of a breach[4]. That is the exact clause you need to be able to point at in your contract, not a general sentence about information security. Article 28 frames the processor's contractual obligations more broadly[4].

Article 34 then requires informing the data subjects where the breach is likely to result in a high risk to their rights and freedoms[4]. We do not rule on whether that threshold is met in this case: as of 6 October 2026 there was no public information indicating proceedings opened by the Belgian authority, and the exploited flaw had not been detailed[1][3].

Four countries, four authorities to know before the incident

CountryData protection authorityCyber authority (NIS2)
BelgiumAPD / GBACCB
FranceCNILANSSI
NetherlandsAutoriteit PersoonsgegevensRDI, with NCSC-NL
LuxembourgCNPDILR

The form, the account and the person who fills it in are prepared cold. Hunting for a notification address on a Sunday evening, while the clock runs, costs hours the regulation does not give back.

If you are the supplier, you are also the link

NIS2 adds a second clock for the entities it covers: an early warning within 24 hours, then an incident notification within 72 hours (Article 23)[5]. It also requires supply-chain security management. The direct consequence for an SME outside the direct scope: it is your customers, who are in scope, who come and ask. That is the logic behind supplier security questionnaires, and the real commercial driver of this topic — the question arrives before the contract renewal, not after.

The next risk is a perfectly plausible email

A file of names and email addresses tied to an identified service is worth far more than an anonymous list: the phishing message can name the right service at the right moment, so it reads as genuine. Give your teams and your users one written rule: after an incident, your organisation will never ask for a password or a payment by email or text message.

On how fines are calculated, we have set out the five-step method the EDPB fixed for GDPR fines. And for a case where IBANs were exposed, see what the Jims breach changes for your notification duties.

To do this week

  • Put on one page, readable offline, the name and number of the person who notifies, plus your authority's form address.
  • List the suppliers holding your customers' or employees' data: training platform, payroll, CRM, appointment setting, hosting, print shop.
  • For each one, check the contract carries the Article 33(2) duty to inform without undue delay, and a named on-call contact.
  • Set up monitoring on your own domain name, so you do not learn about an incident from a journalist three weeks later.
  • Run a 60-minute dry-run notification: who decides, who drafts, who informs the data subjects.
  • Check that any publicly exposed extranet or training portal is patched, and can be taken offline on a single decision.

At CyberNovaLabs.io

We help SMEs in the Netherlands, Belgium, France and Luxembourg prepare this file before the incident: mapping processors, clauses to require, a one-page notification procedure. Start with our supplier security questionnaire and the NIS2 position for Belgium; the whole offer sits on our cybersecurity and NIS2 page. If you would rather talk it through, book a 20-minute call. We also support teams prospecting the region, with B2B appointment setting in Brussels.

Sources

  1. La Libre / Belga — Pres de 19.450 personnes potentiellement touchees par une cyberattaque d'un site de la FWB (05/10/2026)
  2. DH.be — Pres de 20.000 personnes potentiellement touchees par une cyberattaque d'un site de la FWB (05/10/2026)
  3. Tinynews — Fuite de donnees a la FWB : pres de 20 000 personnes touchees, et encore beaucoup de questions (06/10/2026)
  4. RGPD, reglement (UE) 2016/679, articles 28, 33 et 34 — texte officiel EUR-Lex
  5. Directive (UE) 2022/2555 (NIS2), article 23 — texte officiel EUR-Lex
CyberNovaLabs.io

Qualified meetings, no lock-in.

Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.

→ Get meetings booked

Read next

Newsletter · CyberNovaLabs.io

Security Briefing

One email a month: a figure from our barometer, the NIS2 and CRA dates that matter in the Netherlands, Belgium and Luxembourg, and one practical guide. In English. Unsubscribe in one click.

→ Get meetings booked