Data breach at FWB: three weeks before it was confirmed (05/10)
Flagged from outside in mid-September, confirmed on 5 October 2026: the EAD-online.be data breach shows where the GDPR's 72 hours are really lost, and why the weak link is so often a supplier.
In short
On 5 October 2026 the Federation Wallonie-Bruxelles confirmed a cyberattack on EAD-online.be, its distance-learning platform: according to its education administration, a flaw was exploited by a malicious third party and data was exfiltrated[1]. Around 19,456 people are potentially affected; the sample published by the attacker contains surnames, first names and email addresses[1][2]. The attack had already been reported publicly in mid-September by a breach-monitoring site, roughly three weeks before the official confirmation, and the platform stays closed until mid-October[2][3].
Why this breach matters to your SME
Three details here apply to any company in the four countries we work in. One: the alert came from outside, not from the victim. Two: the affected platform is not run in-house but by a third party, ETNIC, the Federation's IT body[1]. Three: the exfiltrated data is only names and email addresses, which is exactly what a convincing phishing campaign needs.
None of those three features depends on headcount. A twelve-person SME exposing a client extranet, a training portal or a document drop-box sits in the same configuration: a public component, maintained by somebody else, holding named personal data.
And if your supplier is breached, it is your name in the press and your obligation that starts running. A processing agreement organises cooperation; it does not transfer your position as controller.
When the data breach notification clock starts
The GDPR (Article 33(1)) requires the controller to notify a personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it[4]. Two points are routinely misread:
- the starting point is becoming aware, not the end of the technical investigation. The text itself allows information to be provided in phases where it is not all available at once;
- learning about the breach from a third party — a researcher, a journalist, a monitoring site, a customer — is becoming aware. The clock does not restart because the news came from outside.
Article 33(2) adds that the processor shall notify the controller without undue delay after becoming aware of a breach[4]. That is the exact clause you need to be able to point at in your contract, not a general sentence about information security. Article 28 frames the processor's contractual obligations more broadly[4].
Article 34 then requires informing the data subjects where the breach is likely to result in a high risk to their rights and freedoms[4]. We do not rule on whether that threshold is met in this case: as of 6 October 2026 there was no public information indicating proceedings opened by the Belgian authority, and the exploited flaw had not been detailed[1][3].
Four countries, four authorities to know before the incident
| Country | Data protection authority | Cyber authority (NIS2) |
|---|---|---|
| Belgium | APD / GBA | CCB |
| France | CNIL | ANSSI |
| Netherlands | Autoriteit Persoonsgegevens | RDI, with NCSC-NL |
| Luxembourg | CNPD | ILR |
The form, the account and the person who fills it in are prepared cold. Hunting for a notification address on a Sunday evening, while the clock runs, costs hours the regulation does not give back.
If you are the supplier, you are also the link
NIS2 adds a second clock for the entities it covers: an early warning within 24 hours, then an incident notification within 72 hours (Article 23)[5]. It also requires supply-chain security management. The direct consequence for an SME outside the direct scope: it is your customers, who are in scope, who come and ask. That is the logic behind supplier security questionnaires, and the real commercial driver of this topic — the question arrives before the contract renewal, not after.
The next risk is a perfectly plausible email
A file of names and email addresses tied to an identified service is worth far more than an anonymous list: the phishing message can name the right service at the right moment, so it reads as genuine. Give your teams and your users one written rule: after an incident, your organisation will never ask for a password or a payment by email or text message.
On how fines are calculated, we have set out the five-step method the EDPB fixed for GDPR fines. And for a case where IBANs were exposed, see what the Jims breach changes for your notification duties.
To do this week
- Put on one page, readable offline, the name and number of the person who notifies, plus your authority's form address.
- List the suppliers holding your customers' or employees' data: training platform, payroll, CRM, appointment setting, hosting, print shop.
- For each one, check the contract carries the Article 33(2) duty to inform without undue delay, and a named on-call contact.
- Set up monitoring on your own domain name, so you do not learn about an incident from a journalist three weeks later.
- Run a 60-minute dry-run notification: who decides, who drafts, who informs the data subjects.
- Check that any publicly exposed extranet or training portal is patched, and can be taken offline on a single decision.
At CyberNovaLabs.io
We help SMEs in the Netherlands, Belgium, France and Luxembourg prepare this file before the incident: mapping processors, clauses to require, a one-page notification procedure. Start with our supplier security questionnaire and the NIS2 position for Belgium; the whole offer sits on our cybersecurity and NIS2 page. If you would rather talk it through, book a 20-minute call. We also support teams prospecting the region, with B2B appointment setting in Brussels.
Sources
- La Libre / Belga — Pres de 19.450 personnes potentiellement touchees par une cyberattaque d'un site de la FWB (05/10/2026)
- DH.be — Pres de 20.000 personnes potentiellement touchees par une cyberattaque d'un site de la FWB (05/10/2026)
- Tinynews — Fuite de donnees a la FWB : pres de 20 000 personnes touchees, et encore beaucoup de questions (06/10/2026)
- RGPD, reglement (UE) 2016/679, articles 28, 33 et 34 — texte officiel EUR-Lex
- Directive (UE) 2022/2555 (NIS2), article 23 — texte officiel EUR-Lex
Qualified meetings, no lock-in.
Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.
Read next
NIS2 France: are hotels and tourism in scope?
Tourist accommodation is absent from the NIS2 annexes, and France's transposition was still in parliament on 7 October 2026. Yet in May 2026 three French tourism operators lost their reservation databases within 72 hours. Here is what actually applies to you.
Read the article →October 6, 2026 · 7 min readDGFiP breach: stolen logins, no MFA, no detection (29/09/2026)
On 29 September 2026 France's cyber agency ANSSI published its incident report on the cyberattacks against the tax administration. No rare technique: passwords stolen from personal computers, a second factor sent by email, sensitive applications reachable without segmentation, and a portal nobody was watching. All four links exist in most SMEs.
Read the article →October 6, 2026 · 8 min readB2B appointment setting: phone, LinkedIn or email?
Channel choice is not a matter of taste. It is set first by what the law of each country allows for the contact you target, then by the buyer's role. Here are the four national regimes, the channel table by buyer profile, and the formula that tells you how many contacts you need to work.
Read the article →