Decoding the world of cybersecurity

Belgian federation disputes cyber breach claims

Belgium’s AFTT says current checks do not support claims that its results infrastructure or private contact data were compromised, while a separate gymnastics breach remains confirmed.

Belgian federation disputes cyber breach claims
Summary
  • AFTT says checks with its results-site provider have found no indication that the provider’s infrastructure was compromised.
  • It currently has no evidence that members’ telephone numbers or email addresses were accessed or retrieved.
  • A separate gymnastics federation incident disclosed on 17 September did involve confirmed unauthorised access and data extraction.

Belgium’s French-speaking table-tennis federation has pushed back on public claims of a data breach, saying current checks have not found evidence that its results infrastructure was compromised or that private contact information was taken.

The Association Francophone de Tennis de Table, or AFTT, said on 21 September that it had investigated the claims with the provider responsible for its results website and had found no indication that the provider’s infrastructure had been compromised.

The organisation also said the information referred to publicly as belonging to the federation appeared, for the most part, to correspond to data that was already publicly accessible. Its own checks had not identified evidence that members’ phone numbers or email addresses had been accessed or retrieved.

The federation nevertheless said investigations were continuing and that it had strengthened some security measures as a precaution. It also separated an unrelated synchronisation issue involving missing players from the cyber investigation.

The statement follows attacker claims that a large volume of Belgian table-tennis information had been obtained. Those figures have not been independently established and the federation’s current account does not support treating them as a confirmed breach total.

A separate incident affecting the Fédération francophone de Gymnastique et de Fitness was disclosed on 17 September. That federation confirmed that unauthorised people had accessed part of its IT environment and extracted data after activity detected several days earlier.

The two cases therefore sit at different evidential stages. The gymnastics federation has acknowledged access and extraction. The table-tennis federation has acknowledged an investigation but says its current technical checks do not support some of the claims being made about compromised infrastructure and non-public contact data.

The distinction is important because criminal breach claims often appear before affected organisations have completed forensic work. Attackers may advertise datasets that contain a mixture of private records, scraped public information, older leaked material, and samples that are difficult to authenticate quickly.

A responsible investigation has to answer several separate questions. A system can be accessed without data being copied; data can be copied without containing the fields claimed by an attacker; and a dataset can appear convincing while relying heavily on information that was already public.

Sports federations can also hold broader datasets than their public-facing role suggests. Membership administration may include names, dates of birth, club affiliations, contact details, competition records, payment information, disciplinary material, and data relating to minors.

Many such bodies operate with relatively small central technology teams and depend on external providers for membership platforms, competition results, websites, event systems, and payments. That creates a distributed data environment in which responsibility for one member record can span several organisations and systems.

The Belgian cases therefore illustrate two separate disclosure problems at once: dealing with a confirmed compromise and resisting pressure to validate unverified criminal claims before the evidence supports them. The latter can be difficult when screenshots or datasets circulate publicly and reporting quickly turns alleged record counts into apparent facts.

Further disclosure from the federations, their technology suppliers, or Belgian data-protection authorities will determine whether the incidents ultimately prove related, separate, or a mixture of confirmed intrusion and overstated claims. For now, the evidence remains clear only in part: extraction is confirmed at the gymnastics federation, while AFTT disputes the central breach claims made about its own systems.

×