Cyber Incident Victim: Ville d'Angers
Date:
Jan 2021
Location:
France
Summary
The City of Angers experienced a ransomware attack similar to incidents affecting other municipalities, prompting its IT teams to activate a backup protocol in coordination with national cybersecurity authorities. Service disruptions occurred during the prolonged restoration process, though officials confirmed no data exfiltration took place. The incident degraded operational capabilities across municipal systems until recovery efforts were completed.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
The City of Angers experienced a ransomware cyberattack around January 15, 2021, joining other French municipalities like La Rochelle, Aix-Marseille, and Vincennes that faced similar incidents. Municipal IT teams detected the attack and activated a backup protocol on Saturday morning following the breach, coordinating their response with France's National Cybersecurity Agency (ANSSI). The ransomware caused significant operational disruptions, degrading municipal IT services and necessitating a prolonged restoration process. City officials confirmed no data exfiltration occurred during the incident, distinguishing it from attacks where threat actors steal information prior to encryption. Service degradation impacted routine administrative functions, though the exact scope of affected systems remained unspecified in public communications.

Restoration efforts proved time-intensive due to the ransomware's disruptive effects on infrastructure. Municipal teams prioritized system recovery while managing ongoing service limitations throughout the remediation phase. The collaboration with ANSSI provided standardized incident response protocols but did not prevent extended operational downtime. No ransom payment details or threat actor attribution were disclosed by city authorities. The incident highlighted recurring ransomware vulnerabilities across French local governments, following a pattern of attacks targeting municipal IT systems during the same timeframe. Angers maintained public transparency regarding the attack's containment progress while withholding technical specifics about the ransomware variant or initial attack vector.
