CSIDB logo
Incident

Agence pour l'enseignement français à l'étranger

Incident posture

Attack window
Nov 2023
Location
France
Status
Historical
CIA posture
Available to members
Updated
2026-01-05 20:18

Linked entities

Victim
Agence pour l'enseignement français à l'étranger
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack targeted a server dedicated to the Agence pour l'Enseignement Français à l'Etranger, leading to service disruption and confirmed data exfiltration. The intrusion affected personal data including identification documents and banking details from schools, central services, detached staff, some locally recruited personnel, and suppliers. Security measures were implemented to restore services, and investigations remain ongoing to fully identify compromised individuals. The incident was reported to national cybersecurity authorities, judicial entities, and data protection regulators, with precautionary guidance disseminated to mitigate potential malicious activities.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On November 6, 2023, the Agence pour l'Enseignement Français à l'Etranger (AEFE) detected service unavailability affecting one of its applications, prompting an investigation by its service provider ELAP. ELAP identified a cyber intrusion on a server exclusively dedicated to AEFE operations, where ransomware had been deployed. Immediate containment measures were implemented to secure the platform. Following ELAP’s provision of security guarantees, AEFE authorized service restoration on November 15. ELAP continued supporting AEFE throughout the incident and collaborated with authorities by sharing available information. By November 19, ELAP and its partners confirmed AEFE was the sole affected client and verified that data exfiltration had occurred. The compromised dataset included personal information such as copies of identity documents and banking details.

AEFE formally reported the incident to France’s National Cybersecurity Agency (ANSSI), filed a legal complaint with judicial authorities, and notified the National Commission for Information Technology and Civil Liberties (CNIL). Ongoing forensic efforts focused on precisely cataloging exfiltrated personal data, which involved records from schools, AEFE central services, and detached personnel. Locally recruited staff and supplier data were also potentially exposed. AEFE disseminated precautionary measures to its network of institutions, advising vigilance against malicious activities, with instructions relayed to school staff. The agency emphasized the criminal nature of unauthorized data extraction, possession, or transmission under French law while acknowledging the time-intensive process of identifying all affected individuals. Public communications aimed to broadly inform communities and facilitate implementation of protective actions alongside localized advisories.

Sources

Sources available to members: 1 source.

CSIDB