Menu
Browse

Cyber Incident Victim: City of Bourg-Saint-Maurice

Date:

Apr 2021

Location:

France

Summary

A cyberattack targeted the municipal servers of Bourg-Saint-Maurice, impacting tourism-related systems and those of Haute Tarentaise and Séez. The attack resulted in widespread encryption of data, though no evidence of personal data theft was identified during initial investigations. Online services remained suspended as recovery efforts were anticipated to require several weeks to restore normal operations. The incident's characteristics strongly suggest a ransomware attack due to the encryption of systems.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

A cyber-attack targeted the servers of the City of Bourg-Saint-Maurice during the weekend preceding April 24, 2021. The incident impacted servers supporting tourism operations, Haute Tarentaise, and the neighboring commune of Séez. A cybersecurity firm engaged in the investigation confirmed that attackers encrypted the affected systems but found no evidence of personal data exfiltration at that stage of analysis. While the reporting source did not explicitly classify the attack as ransomware, the comprehensive encryption of systems strongly indicated this type of malware-based compromise. Municipal authorities suspended all online services as a containment measure following the discovery. Technical recovery efforts were projected to require several weeks, with normal operations expected to resume gradually after this period.

Cyber Incident Image

The attack disrupted digital services critical to municipal functions and regional tourism coordination. Service suspensions affected public access to online platforms managed by the compromised servers, though the full scope of operational interruptions beyond tourism and inter-communal systems remained unspecified in initial reports. The cybersecurity firm focused on forensic analysis and system restoration without publicly identifying threat actors or detailing specific decryption methods. No ransom demands or communication channels with attackers were disclosed. Recovery timelines suggested significant infrastructure remediation, but physical municipal operations and non-digitally dependent services continued unaffected. The investigation remained ongoing with no supplementary updates confirming additional data exposure or system compromises beyond the initially encrypted servers.

Sources
Sources available to members
1 source