Back to home
Health·

Andorran Transplant Group ATIDA Hit by Email Hack Sending Fraudulent QR Code Messages

An unauthorized party accessed ATIDA's email account and sent deceptive messages posing as the association, risking exposure of contact details for transplant recipients and donors. The group has secured the account and alerted authorities.

Key Points

  • ATIDA's info@atida.ad account accessed without authorization, sending fake event emails with QR codes to contacts.
  • Potentially exposed: emails, names, and recipient connections to the group.
  • ATIDA locked account, updated credentials, notified police and APDA.
  • Urges deleting emails, avoiding QR scans, contacting ATIDA if interacted.

The Andorran Association of Transplant Recipients and Donors (ATIDA) has reported an unauthorised access to its official email account, info@atida.ad, leading to the dispatch of fraudulent messages to various contacts linked to the organisation.

In a statement to those affected, ATIDA explained that an unauthorised third party accessed the account and sent emails pretending to come from the association. These messages referenced a supposed event organised by ATIDA and contained a QR code for recipients to scan. The association stressed that it did not prepare, authorise or send these communications.

Potentially compromised data includes contact details such as email addresses, and in some instances names, surnames or other basic identifying information stored in the account or its linked address book. ATIDA noted that the incident could also reveal recipients' connections to the group. At present, the organisation has no evidence that scanning the QR code prompted any specific actions from recipients, though the matter remains under investigation.

Following detection of the breach, ATIDA locked the account to prevent routine use, updated access credentials and sought technical assistance from its IT provider. The association has informed Andorra Police and the Andorran Data Protection Agency (APDA).

ATIDA urged recipients to delete the fraudulent email without forwarding or replying to it, and to avoid scanning the QR code. Those who interacted with the message—by scanning the code or sharing personal details—should contact the association to assess further steps, such as changing passwords. The group advised general caution against any unsolicited requests for personal data, passwords, payments or donations in its name, recommending verification through official channels. Suspicious emails should be preserved and forwarded to ATIDA for analysis.

The association expressed regret for the inconvenience and committed to ongoing efforts to resolve the incident and strengthen its digital security.

Share the article via