Menu
Browse

Cyber Incident Victim: Ville de Guingamp

Date:

May 2022

Location:

France

Summary

A municipal administration in France experienced a cyberattack targeting two servers, resulting in data loss within its digital archives. The organization recovered all data but required two months of manual re-entry work by staff, incurring recovery costs of €18,500 without paying a ransom demand—an initial extortion email was mistakenly deleted as spam. Following the incident, the entity migrated its systems from Windows 7 to Windows 10 to enhance security. Concurrent operational challenges included recruitment difficulties for public service roles and inflationary pressures influencing municipal pricing adjustments.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In May 2022, the municipality of Guingamp experienced a cyberattack targeting two of its servers, resulting in data loss within its digital archives. The incident was disclosed by Mayor Philippe Le Goff, who confirmed the compromise occurred the previous month. The attack disrupted archival systems but did not cripple municipal operations entirely. Guingamp engaged two external cybersecurity firms—one based in Fougères (Ille-et-Vilaine) and another in Vannes (Morbihan)—to assist with recovery efforts. Through this collaboration, the city successfully restored all lost data. However, the restoration process necessitated approximately two months of manual data re-entry by municipal staff to fully reintegrate the recovered information into operational systems. The attack did not involve ransomware payment, as a suspicious email received by the municipality was initially classified as spam and deleted without further engagement.

Cyber Incident Image

The financial impact of the incident totaled €18,500, covering recovery services and associated operational expenses. To prevent future vulnerabilities, Guingamp migrated its systems from Windows 7 to Windows 10 following the attack, addressing outdated software that may have contributed to the breach. While data integrity was fully restored, the manual recovery workload required significant effort from administrative personnel over the subsequent two months. The municipality emphasized that no ransom demands were fulfilled and that critical public services remained functional throughout the incident. No additional technical details regarding the attack vector or threat actor were disclosed by officials.

Sources
Sources available to members
1 source