Menu
Browse
Date:

Nov 2023

Location:

France

Summary

A ransomware attack targeted a server dedicated to the Agence pour l'Enseignement Français à l'Etranger, leading to service disruption and confirmed data exfiltration. The intrusion affected personal data including identification documents and banking details from schools, central services, detached staff, some locally recruited personnel, and suppliers. Security measures were implemented to restore services, and investigations remain ongoing to fully identify compromised individuals. The incident was reported to national cybersecurity authorities, judicial entities, and data protection regulators, with precautionary guidance disseminated to mitigate potential malicious activities.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 3 motives 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On November 6, 2023, the Agence pour l'Enseignement Français à l'Etranger (AEFE) detected service unavailability affecting one of its applications, prompting an investigation by its service provider ELAP. ELAP identified a cyber intrusion on a server exclusively dedicated to AEFE operations, where ransomware had been deployed. Immediate containment measures were implemented to secure the platform. Following ELAP’s provision of security guarantees, AEFE authorized service restoration on November 15. ELAP continued supporting AEFE throughout the incident and collaborated with authorities by sharing available information. By November 19, ELAP and its partners confirmed AEFE was the sole affected client and verified that data exfiltration had occurred. The compromised dataset included personal information such as copies of identity documents and banking details.

Cyber Incident Image

AEFE formally reported the incident to France’s National Cybersecurity Agency (ANSSI), filed a legal complaint with judicial authorities, and notified the National Commission for Information Technology and Civil Liberties (CNIL). Ongoing forensic efforts focused on precisely cataloging exfiltrated personal data, which involved records from schools, AEFE central services, and detached personnel. Locally recruited staff and supplier data were also potentially exposed. AEFE disseminated precautionary measures to its network of institutions, advising vigilance against malicious activities, with instructions relayed to school staff. The agency emphasized the criminal nature of unauthorized data extraction, possession, or transmission under French law while acknowledging the time-intensive process of identifying all affected individuals. Public communications aimed to broadly inform communities and facilitate implementation of protective actions alongside localized advisories.

Sources
Sources available to members
1 source