Cyber security incident at allergen immunotherapy manufacturer and supplier HAL Allergy B.V.
In the evening of Saturday, October 28, HAL Allergy was hit by a ransomware attack. Thanks to the timely intervention by its IT team, the attack was stopped on Sunday morning (October 29), limiting the scope of the attack. HAL Allergy immediately engaged external cybersecurity experts to assist in restoring the affected network and investigate the issue. Together with the IT team of HAL Allergy, they are working diligently to restore the affected systems.
Delay in delivery of products
Due to the attack, part of the HAL Allergy network and the data stored there, is currently not accessible for HAL Allergy. This has caused delays in the delivery of the HAL Allergy products to our customers. As a consequence, our customer may be delayed in providing you with the prescribed product.
Personal data affected by the incident
Currently, the forensic investigation into the issue is still ongoing. Part of the investigation will be to assess which (personal) data is or may have been affected by the attack, and if the attackers have also accessed and/or copied any (personal) data.
Pending the forensic investigation, HAL Allergy wishes to inform you of the issue and which of your personal data may have been compromised during the attack. The possibly affected personal data may concern:
- Address (please note that this does not apply to German or Austrian residents)
- Date of birth
- HAL Allergy product
We would like to emphasize that only limited systems of HAL Allergy were affected by the attack. The attack has not affected the systems of our customers. Any data stored with our customers has not been accessible to the attackers.
HAL Allergy immediately engaged forensic IT-experts upon discovery of the incident and has taken the necessary measures to stop the incident, to limit potential negative consequences and to prevent the incident from reoccurring as much as possible. The measures taken include:
- Disconnection of our network from the internet.
- Clean up and rebuild of the network.
- Restoring data.
- Notification with the Dutch Data Protection Authority.
- Contacting the Dutch Police.
We very much regret that this incident occurred. If you have any questions following this notification, please contact the Compliance Officer HQ, firstname.lastname@example.org.
HAL Allergy B.V.