CSIDB logo
Incident

Office d'Equipement Hydraulique de Corse

Incident posture

Attack window
Nov 2022
Location
France
Status
Historical
CIA posture
Available to members
Updated
2025-10-15 00:00

Linked entities

Victim
Office d'Equipement Hydraulique de Corse
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
Nov 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack by the Lockbit 3.0 group targeted a Corsican hydraulic infrastructure agency, encrypting its data and demanding a cryptocurrency ransom. The organization refused negotiations, adhering to national cybersecurity authority guidelines. Critical operational services remained functional, but client management and financial systems—including historical accounting data—were rendered inaccessible due to encryption. Thirty-three servers were paralyzed, forcing immediate shutdowns. While no confirmed data exfiltration occurred, the agency committed to notifying stakeholders of any potential breaches. Recovery efforts involved internal technicians, external providers, and national cybersecurity experts to restore full functionality promptly.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The cyberattack targeting the Office d’Equipement Hydraulique de Corse (OEHC) began during the night of November 2–3, 2022, when the Russophone ransomware group Lockbit 3.0 infiltrated the organization’s systems. Employees discovered the breach on the morning of November 3 upon encountering completely locked IT systems, rendering 33 servers inoperable. The attackers deployed ransomware, encrypting a significant portion of OEHC’s data, and demanded payment in cryptocurrency in exchange for a decryption key. The exact ransom amount was not disclosed publicly. Lockbit 3.0’s attack paralyzed core operations, though OEHC clarified it did not store customer banking data, limiting certain financial risks.

OEHC’s leadership initially remained silent for approximately two weeks to assess the damage and coordinate a response. On November 17, 2022, the agency issued a formal statement confirming it had refused all contact or negotiation with the attackers, aligning with French authorities’ recommendations against paying ransoms. Technical teams from OEHC, its IT service provider, and France’s National Agency for the Security of Information Systems (ANSSI) collaborated to evaluate the impact. Essential services, such as water management, remained operational, while customer-facing functions were prioritized for restoration and expected to resume full functionality swiftly. The most severe disruption affected support activities, particularly accounting and financial management systems, where historical data encryption caused prolonged inaccessibility. OEHC implemented contingency measures to facilitate recovery but did not specify technical details or timelines. The organization committed to informing clients, partners, and employees of any confirmed data leaks resulting from the attack, though no evidence of data exfiltration was confirmed at the time of reporting.

Sources

Sources available to members: 2 sources.

CSIDB