Menu
Browse

Cyber Incident Victim: Mairie d'Ozoir-la-Ferrière

Date:

Dec 2023

Location:

France

Summary

The town hall of Ozoir-la-Ferrière suffered a cyberattack compromising its IT system and municipal Facebook page via a compromised computer and fake address, with the affiliated community of communes also impacted. Attackers encrypted data without confirmed leakage, causing prolonged system disruptions and operational paralysis while specialists investigate; recovery timelines remain uncertain despite engagement with a cybersecurity defense firm.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On December 9, 2023, attackers compromised the municipal computer systems of Ozoir-la-Ferrière, a commune in Seine-et-Marne, Île-de-France, with approximately 20,500 residents. The intrusion occurred through a municipal computer and a falsified address, enabling unauthorized access to the town hall's IT infrastructure. The cyberattack also affected the Communauté de Communes des Portes Briardes, an intercommunal structure associated with the municipality. By December 15, municipal operations remained severely disrupted, with Mayor Jean-François Oneto confirming the total loss of system functionality during a media interview. Technical specialists engaged by the municipality had not yet restored systems due to ongoing forensic examinations, with no estimated timeline for recovery provided. The attack additionally targeted the town hall’s Facebook page, though the extent of compromise to this platform was not detailed.

Cyber Incident Image

During a municipal council meeting on December 14, Mayor Oneto disclosed that cybersecurity experts had identified the incident as a data encryption attack, with preliminary investigations indicating no evidence of data exfiltration. A specialized cyberdefense firm was actively managing incident response and forensic analysis. Municipal authorities emphasized the absence of leaked sensitive information as a mitigating factor, though operational paralysis persisted across administrative functions. No ransomware claims or explicit attacker motives were disclosed in available reports. Recovery efforts remained contingent on completing the security firm’s investigation, with no secondary incidents or expanded compromises reported as of December 15. The attack’s operational impact included sustained disruption to municipal services and IT-dependent processes.

Sources
Sources available to members
1 source