Cyber Incident Victim: Alfortville town hall
Date:
Nov 2020
Location:
France
Summary
The municipal government of Alfortville suffered a ransomware attack that crippled its computer systems, rendering files inaccessible after hackers encrypted them. Attackers infiltrated the network, exfiltrated data prior to encryption, and demanded a Bitcoin ransom in exchange for decryption keys, paralyzing administrative operations. The incident was attributed to the Ranzy ransomware group, with the attack causing widespread disruption to town hall services.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On the evening of November 4, 2020, municipal computer systems at Alfortville town hall in Val-de-Marne, France, experienced sudden paralysis. Mayor Luc Carvounas described the event as a "general plantade," indicating widespread system failure across administrative operations. Forensic analysis revealed the cause as a ransomware attack, where threat actors infiltrated the network, exfiltrated data, and subsequently encrypted files to render them inaccessible. The attackers employed a double-extortion tactic by stealing sensitive information prior to deploying encryption across compromised systems. This disruption immediately halted standard municipal services, affecting internal communications, document processing, and public-facing operations. Staff discovered encrypted files accompanied by a ransom note demanding payment in Bitcoin cryptocurrency. The note stipulated that payment would trigger release of a decryption key to restore file accessibility.

The ransomware attack caused sustained operational paralysis throughout Alfortville’s city departments, preventing routine administrative functions and service delivery. No specific ransom amount or Bitcoin wallet details were publicly disclosed by municipal authorities in initial reports. Mayor Carvounas confirmed data exfiltration occurred prior to encryption, exposing potentially sensitive municipal or resident information. Recovery efforts focused on assessing system damage and evaluating decryption alternatives, though the article did not specify whether officials engaged cybersecurity firms or law enforcement. The incident underscored vulnerabilities in local government infrastructure, with prolonged downtime highlighting dependencies on digital systems for core civic operations. Public service continuity remained disrupted for an unspecified duration following the initial compromise.
