CSIDB logo
Incident

La Banque Postale

Incident posture

Attack window
Dec 2025
Location
France
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 10:07

Linked entities

Victim
La Banque Postale
Threat actors
0 actors
Sources
3 sources

Timeline

Occurred
Dec 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A suspected distributed denial-of-service (DDoS) attack disrupted France's national postal service and its banking arm during the Christmas rush, rendering online services inaccessible for more than eight hours. The incident blocked package deliveries requiring tracking, halted online mail operations, and knocked offline the mobile app and online banking space used by millions of customers, forcing the bank to redirect payment approvals to text messages. Despite claims of responsibility by a Russian hacktivist group, no culprit was officially confirmed, and Paris prosecutors opened an examination into the case. The postal service stated the incident had no impact on customer data, and in-person postal and banking transactions remained available throughout the outage.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Monday, December 22, 2025, France's national postal service La Poste suffered what the company described as a "major network incident" that disrupted its information systems, including those operated by its online banking arm, La Banque Postale, as well as the laposte.fr website and mobile applications. A spokesperson for La Poste told the French news outlet BFMTV that the outage was caused by a distributed denial-of-service attack, a form of cyberattack in which malicious traffic is directed at websites or servers in order to overwhelm them and force them offline. The attack occurred during the Christmas holiday rush, with the company anticipating the handling of nearly 180 million parcels through November and December as part of its peak seasonal deliveries, according to a November press release cited in coverage of the event. La Poste, which delivered 2.6 billion packages in the previous year and had a workforce of more than 200,000 people, reported that the incident had no impact on customer data but did disrupt package delivery operations.

The scope of the disruption extended across multiple service channels. La Poste announced that its online mail and banking services, its official website, and its mobile application were temporarily unavailable, while specifying that customers could still carry out banking and postal transactions in person at physical locations. La Banque Postale published a separate announcement confirming that the cyberattack was temporarily preventing customer access to its mobile app and online banking space. Customers of the bank were blocked from using the application to approve payments or conduct other banking services, prompting the bank to redirect payment approvals to text messages as an alternative channel. Services at some post offices were also temporarily disrupted as a result of the network incident. Physical mail operations were partially preserved, with letters including holiday greeting cards still able to be mailed and delivered, but any transactions requiring tracking or access to the postal service's internal computer systems were rendered impossible. The laposte.fr website displayed a message indicating that it was currently unavailable.

The incident remained unresolved for an extended period on the day of the attack. According to reports, the disruption was still ongoing by Monday evening, more than eight hours after it was first reported. La Banque Postale communicated on social networks that its teams were mobilized to resolve the situation quickly. No one immediately claimed responsibility for the attack, and officials did not publicly identify the culprit. Paris prosecutors were reported to be examining the case. Despite claims made by a Russian hacktivist group, it was not yet clear who was behind the cyberattack, and speculation at a post office in southern Paris included possible links to Russia, a disgruntled customer, or a disgruntled colleague.

The attack on La Poste occurred within a broader pattern of cybersecurity incidents affecting French institutions in the weeks preceding the event. The week before the postal service attack, the French Interior Ministry disclosed a data breach in which hackers broke into email accounts and stole confidential documents, including criminal records. Shortly thereafter, local authorities announced the arrest of a 22-year-old suspect whose name was not disclosed, and Interior Minister Laurent Nunez, speaking on broadcaster France-Info, blamed "imprudence" at the ministry for the incident. Also in the week prior, prosecutors stated that France's counterespionage agency was investigating a suspected cyberattack plot involving software that would have allowed remote users to control computer systems of an international passenger ferry, with a Latvian crew member taken into custody on charges of having acted for an unidentified foreign power. France and other European allies of Ukraine alleged that Russia was waging "hybrid warfare" against them, employing sabotage, assassinations, cyberattacks, disinformation, and other hostile acts that were often difficult to quickly trace back to Moscow. It was not clear whether any of these incidents were connected to the attack on La Poste.

Sources

Sources available to members: 3 sources.

CSIDB