Menu
Browse

Cyber Incident Victim: SONADEV

Date:

Apr 2024

Location:

France

Summary

A cyberattack targeting SONADEV, Saint-Nazaire agglomeration, and the city government disrupted IT systems, forcing employees to avoid computer and email use. The incident, involving a crypto-virus resembling previous large-scale attacks, prompted activation of a crisis team and ongoing diagnostic efforts to assess impacts on services, including public libraries. While digital tools remain unavailable with no confirmed data compromise or recovery timeline, operations continue via phone communications and in-person public reception. Teams are prioritizing critical functions like real estate services and project monitoring, maintaining client accessibility through alternative channels during the system restoration process.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On April 10, 2024, Saint-Nazaire agglomeration, the Ville de Saint-Nazaire, and SONADEV experienced a disruptive cyberattack that compromised their shared network infrastructure. Employees arriving for work that morning received immediate instructions not to power on computers or access email accounts via mobile devices, indicating a precautionary lockdown of IT systems. The attack impacted SONADEV, the agency responsible for territorial development in Saint-Nazaire, alongside the municipal and regional government networks. By early morning, crisis management protocols were activated as technical teams initiated diagnostic procedures to assess the intrusion's scope. Initial reports confirmed the attack affected multiple operational units, including municipal media libraries, though the full extent remained unverified during initial response efforts. Information technology departments prioritized network security reinforcement while working to determine the attack vector and potential data exposure.

Cyber Incident Image

The incident involved a crypto-virus resembling the 2021 attack against Angers, though attribution and precise malware characteristics remained undetermined. SONADEV confirmed its operational continuity measures, maintaining public access to physical offices and real estate listings via its unaffected website. Commercial operations continued via landline telephones at 02 40 22 96 90, while project management teams relied on smartphones for client communications. Despite these adaptations, full restoration of digital services faced indefinite delays, with recovery expected to occur incrementally. Personnel from all three entities remained mobilized to mitigate service disruptions, though the attack’s impact on personal data storage systems had not been conclusively evaluated. Diagnostic and containment activities persisted beyond the initial outbreak date, with no confirmed timeline for normalized operations.

Sources
Sources available to members
2 sources