Cyber Incident Victim: Mairie d'Ozoir-la-Ferrière
Date:
Dec 2023
Location:
France
Summary
The town hall of Ozoir-la-Ferrière suffered a cyberattack compromising its IT system and municipal Facebook page via a compromised computer and fake address, with the affiliated community of communes also impacted. Attackers encrypted data without confirmed leakage, causing prolonged system disruptions and operational paralysis while specialists investigate; recovery timelines remain uncertain despite engagement with a cybersecurity defense firm.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On December 9, 2023, attackers compromised the municipal computer systems of Ozoir-la-Ferrière, a commune in Seine-et-Marne, Île-de-France, with approximately 20,500 residents. The intrusion occurred through a municipal computer and a falsified address, enabling unauthorized access to the town hall's IT infrastructure. The cyberattack also affected the Communauté de Communes des Portes Briardes, an intercommunal structure associated with the municipality. By December 15, municipal operations remained severely disrupted, with Mayor Jean-François Oneto confirming the total loss of system functionality during a media interview. Technical specialists engaged by the municipality had not yet restored systems due to ongoing forensic examinations, with no estimated timeline for recovery provided. The attack additionally targeted the town hall’s Facebook page, though the extent of compromise to this platform was not detailed.

During a municipal council meeting on December 14, Mayor Oneto disclosed that cybersecurity experts had identified the incident as a data encryption attack, with preliminary investigations indicating no evidence of data exfiltration. A specialized cyberdefense firm was actively managing incident response and forensic analysis. Municipal authorities emphasized the absence of leaked sensitive information as a mitigating factor, though operational paralysis persisted across administrative functions. No ransomware claims or explicit attacker motives were disclosed in available reports. Recovery efforts remained contingent on completing the security firm’s investigation, with no secondary incidents or expanded compromises reported as of December 15. The attack’s operational impact included sustained disruption to municipal services and IT-dependent processes.
