CSIDB logo
Incident

Métropole du Grand Paris

Incident posture

Attack window
Feb 2025
Location
France
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 16:53

Linked entities

Victim
Métropole du Grand Paris
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

In February, the Métropole du Grand Paris detected a cyberattack in which personal data stored on its servers was fraudulently extracted. Approximately 5,000 individuals were affected, including around 250 municipal employees, 208 elected officials, and various partner organizations. The compromised data potentially included names, surnames, phone numbers, and personal and/or professional email addresses, though bank details were not involved. The incident was initially flagged when certain employees reported receiving suspicious calls. A formal complaint was filed against an unknown perpetrator for fraudulent data collection, breach of trust, and unlawful extraction from an automated processing system. The intercommunal authority has since implemented enhanced security procedures to investigate the origin of the breach, mitigate its consequences, and prevent future incidents, with ongoing monitoring and remediation efforts underway.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In early 2025, the Métropole du Grand Paris (MGP), the most populous intercommunalité in France, became aware that personal data stored on its servers had been fraudulently extracted. The establishment publicly disclosed the incident through a communiqué transmitted to the press, stating that during the month of February 2025 it had observed unauthorized exfiltration of personal data from its information systems. The discovery of the breach was reportedly triggered by alerts from agents of the MGP who had received dubious phone calls, a circumstance that first brought attention to the fact that contact information held by the organization had been compromised and possibly misused.

According to reports, the scope of the incident reached approximately 5,000 individuals whose personal data was potentially exposed. This figure encompassed a wide cross-section of people associated with the intercommunalité, including 250 of its own agents, 208 elected officials, and the entirety of the partners that routinely interact with the MGP. The diversity of the affected population illustrates the breadth of the contact databases maintained by the metropolitan authority, spanning internal staff, political representatives, and external institutional or operational partners.

The nature of the data extracted, as described by the MGP, included first and last names, telephone numbers, and personal and/or professional email addresses. The organization specifically indicated that these were the categories of data that could be found in the compromised records. At the same time, the MGP clarified that banking details were not part of the information that had been exposed, limiting the immediate financial exposure for the individuals concerned. The exfiltration therefore centered on identifying and contact-related information rather than financial or deeply sensitive credentials.

Following the discovery of the data extraction, the Métropole du Grand Paris initiated formal legal proceedings by filing a complaint against X, a French legal procedure used when the perpetrator is unknown. The complaint targeted offenses described as fraudulent collection of personal data, breach of trust, and fraudulent extraction of data from an automated processing system. By framing the incident within these specific legal categories, the MGP signaled its intent to pursue accountability and to cooperate with judicial authorities in identifying those responsible for the attack.

In parallel with the legal response, the intercommunalité stated that it had implemented reinforced security procedures aimed at understanding the origin of the incident, limiting its consequences, and preventing potential further cyberattacks. The MGP also committed to conducting regular follow-up on the incident and on the corrective measures applied, indicating an ongoing process of monitoring and remediation rather than a one-time reaction. While the initial detection appears to have come from external signals — the dubious calls received by agents — the subsequent actions suggest a structured internal response combining technical investigation, procedural reinforcement, and judicial escalation.

This event places the Métropole du Grand Paris within a broader pattern of cyberattacks targeting French metropolitan and intercommunal authorities. In the months preceding the MGP incident, the websites of the metropolises of Nantes, Angers, and Dijon had been targeted in September 2024. Earlier still, the Métropole d'Aix-Marseille-Provence had suffered a major disruption in 2020 following a ransomware attack that paralyzed its operations. The recurrence of such incidents across different metropolitan structures underscores how local public administrations have become a sustained focus for threat actors seeking to exploit the data and systems held by these entities.

Sources

Sources available to members: 1 source.

CSIDB