Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Randstad confirmed on December 3, 2020, that the Egregor ransomware group had gained unauthorized access to its global IT environment and certain company data. Egregor then published material it claimed came from the staffing company. Randstad said its systems and operations continued without interruption at that time, while the scope of the data exposure—including whether personal information was involved—remained under investigation.

What happened at Randstad?

Randstad, the Netherlands-based global HR and staffing company, said it had detected malicious activity in its IT environment before its December 3, 2020 statement. The company confirmed unauthorized access to its global environment and said certain data connected particularly with operations in the United States, Poland, Italy and France had been affected. It described the incident as impacting a limited number of servers.

Randstad said Egregor had published what the group claimed was a subset of the data. The company reported no interruption to its systems or business operations at the time of its statement. It said it had activated its incident-response team, brought in external cybersecurity and forensic specialists, and notified relevant regulators and law-enforcement agencies. Randstad also said it had no indication then that third-party systems were affected.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

These statements describe the company’s position at that point in the investigation. “No interruption” is a statement about operational availability; it does not mean that confidential information was unaffected.

What did Egregor reportedly publish?

Contemporaneous reporting described a leak archive of about 32.7 MB containing 184 files. Reported file types included accounting spreadsheets, financial reports, legal documents and other corporate records. The reporting said Egregor claimed the published material represented about 1% of the data it had taken.

Those figures should be treated as reported details of the attackers’ publication, not as a complete inventory confirmed by Randstad. A later year-in-review summary gave an estimate of roughly 60 MB, rather than 32.7 MB. The accounts therefore do not agree on the archive’s size, and neither figure establishes how much data was accessed overall.

Was personal information exposed?

The initial public disclosures did not confirm that personal data had been exposed. Randstad said it was still determining what information had been accessed, including whether personal data was involved, and whether individuals or other parties would need to be identified and notified. The fact that Randstad handles recruitment and employment-related information makes the question consequential, but it does not prove that candidate, employee, client or payroll records appeared in the published files.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Nor does publication alone establish that the data was used for identity theft, fraud or another specific purpose. The public information described here does not establish how many people, if any, were affected.

How did the intrusion reportedly begin?

A Randstad spokesperson told CyberScoop that the company believed the incident began with a phishing email that led to malicious software being installed. That was the company’s preliminary assessment, not a public, independently verified reconstruction of the full attack. The spokesperson also said Randstad had not received a ransom note or direct communication from Egregor at that time.

The public accounts do not establish the specific email, compromised account, method of movement through the network, tools used to take data, or the precise sequence of events. QakBot was associated with Egregor activity more broadly, but the available case-specific information does not establish that it was used against Randstad.

Why the incident mattered even without an outage

Ransomware operations increasingly use “double extortion”: attackers steal data and threaten to publish it, often alongside encryption or disruption of systems. The stolen information gives attackers leverage even if a victim can keep its services running or restore files. Egregor’s use of publication threats is described in contemporary coverage, including Malwarebytes’ threat profile.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a staffing firm, business, legal and financial records can carry confidentiality, competitive and reputational risks. If personal data is involved, organizations also have to determine what was accessed, which people or entities may be affected, and what notifications are required. Randstad said relevant authorities had been notified, but the applicable privacy obligations can depend on the location of the data, the relevant company entity and the people concerned. The initial statement did not specify which laws applied or what final notifications followed.

The distinction is important: an incident can have a serious confidentiality impact without a visible service outage. Conversely, the fact that files were published does not by itself establish that every file was authentic, sensitive or misused.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Who were the Egregor operators?

Egregor emerged in 2020 as a ransomware-as-a-service (RaaS) operation, in which a core operation supplies malware and infrastructure while affiliates carry out intrusions against victims. NHS England Digital’s threat profile said Egregor was first observed in September 2020 and targeted high-value organizations. It noted similarities to Maze, but cautioned that the precise relationship between the operations was unclear. Egregor is therefore better described as part of the post-Maze ransomware landscape than simply as “Maze under a new name.”

Practical lessons for organizations holding employment data

The Randstad incident does not prove that any single security control would have prevented the intrusion. It does illustrate why response planning needs to cover both system availability and data confidentiality:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Reduce phishing and account-compromise risk: use phishing-resistant authentication where feasible, protect privileged accounts, and train staff to report suspicious messages.
  • Limit the damage from a compromised endpoint: apply least privilege, segment networks, and monitor endpoint and server behavior so unusual access or data movement can be investigated quickly.
  • Make recovery dependable: keep backups isolated or otherwise protected from attackers, and test restoration rather than assuming backups will work during a crisis.
  • Know what data is held and where: minimize collection and retention, maintain an inventory of sensitive records, and restrict access to what each role needs.
  • Prepare for extortion and privacy response: define how to preserve evidence, assess leaked files, involve incident-response specialists and counsel, and determine notification obligations across jurisdictions.

These measures address different risks; backups can help restore availability, for example, but cannot undo disclosure of data already taken. An incident plan should therefore treat recovery, forensic scoping and privacy decisions as connected but distinct workstreams.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.