Intruders exploited CVE-2021-40539 and were able to maintain access to its servers for 70 days after the initial breach that took place on November 9, 2021. Attackers' use of « code designed purely for execution on the targeted ICRC servers » and using the targeted servers' MAC address.