Andorra's ACA Club App Hit by Cybersecurity Breach Exposing Member Data
The Automòbil Club d’Andorra notified members of a security incident in its app that risked exposing personal details, but reports no misuse so far and has implemented fixes.
Key Points
- ACA disclosed breach on Tuesday after unauthorized access to app and platform.
- Potentially exposed data includes names, addresses, emails, phones, IDs, birth dates, and chat/incident info.
- No known fraudulent use; vulnerabilities fixed, platform audit underway, members notified.
- ACA urges vigilance against phishing and provides official contact for concerns.
The Automòbil Club d’Andorra (ACA) has informed members of a cybersecurity incident linked to its ACA Club app and related digital platform, which could have allowed unauthorised access to personal data.
The organisation disclosed the breach on Tuesday, promptly triggering internal response measures. It worked with its technical provider and external specialists to contain the situation, determine its origin, and bolster system protections. The ACA notified the Andorran Data Protection Agency (APDA) and offered cooperation to authorities overseeing cybersecurity and cybercrime.
Investigations showed that some platform access points had insufficient safeguards, potentially exposing members’ identifying and contact details, including full names, membership numbers, addresses, email addresses, phone numbers, identity documents, or birth dates. Depending on individual app usage, this might also include data from conversations or reported incidents.
To date, the ACA has no knowledge of any fraudulent exploitation of the compromised information. It reported the matter out of caution and responsibility, as such risks cannot be fully excluded. The technical provider confirmed that key vulnerabilities have now been addressed, with further steps including a comprehensive platform audit, restricted access, and the renewal or disabling of at-risk credentials. Ongoing monitoring will assess the effectiveness of these fixes and any additional needs.
The ACA directly notified members and emphasised vigilance against suspicious emails, texts, or calls mentioning the club, its services, or personal data. It stressed that it never requests passwords, verification codes, or banking details via email, SMS, or phone. Members should verify sources before sharing information, steer clear of links or attachments from untrusted origins, and reach out directly for concerns via aca@aca.ad or +376 803 400.
The club expressed regret over the incident and reaffirmed its dedication to data security, transparency, and member privacy.
Related Articles
Other articles from Catalan-language sources about the same story: