Chambre de commerce et d'industrie des Hauts-de-France
Incident posture
Linked entities
- Victim
- Chambre de commerce et d'industrie des Hauts-de-France
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A pro-Russian hacker group claimed responsibility for a second cyberattack against the Chambre de commerce et d'industrie des Hauts-de-France, just weeks after an initial intrusion. The attack disrupted the organization's official website and two associated platforms, taking services offline for approximately three hours during the early morning before systems recovered on their own by late morning. No data exfiltration or loss was reported in connection with the incident. In response, the organization filed a complaint with the gendarmerie and notified ANSSI, mirroring the response actions taken following the earlier attack attributed to the same threat actor.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
The Chambre de commerce et d'industrie des Hauts-de-France (CCI Hauts-de-France) was the target of a second cyberattack in early February 2025, following an initial intrusion at the very beginning of the year. The first attack occurred during the night of December 31, 2024 to January 1, 2025, setting a precedent for the renewed intrusion that took place only a few weeks later. The second cyberattack struck on Thursday, February 6, 2025, and was, like the first, attributed to a pro-Russian hacker group. The same threat actor claimed responsibility for both intrusions, according to reports. The repeat targeting of the regional chamber of commerce suggests a sustained adversarial interest in the organization rather than an isolated opportunistic strike.
The February 2025 attack affected the official CCI Hauts-de-France website as well as two associated web properties: laho.fr and lesaides.fr. All three sites were impacted by the intrusion, demonstrating that the scope of the attack extended beyond the primary institutional portal. As a direct consequence of the attack, the affected websites were taken offline between 6 a.m. and 9 a.m. on the morning of the incident, resulting in a roughly three-hour period during which these services were unavailable to users. By the end of the morning, the system reportedly recovered and restarted on its own, without any data loss being declared. The fact that services resumed independently suggests that the attack primarily affected availability rather than the integrity or confidentiality of stored information. Despite the disruption, no data breach or data exfiltration was reported in connection with this second incident.
The response actions taken by the CCI Hauts-de-France mirrored those deployed after the initial January attack. Following established procedure, the chamber filed a formal complaint with the gendarmerie, the French national law enforcement body, formally documenting the incident and initiating the judicial process. Additionally, the CCI made a notification to the Agence nationale de la sécurité des systèmes d'information (ANSSI), the French national cybersecurity agency responsible for overseeing the security of information systems across France. This dual notification process, involving both law enforcement and the national cybersecurity authority, reflects the standard protocol for handling significant cyber incidents affecting public-facing institutional infrastructure in France.
The characterization of the attacks as "pro-Russian" indicates attribution to threat actors operating within or aligned with the broader ecosystem of Russian-speaking or Russia-aligned hacktivist groups that have been active in targeting Western European institutions. The recurrence of attacks by the same group within a span of approximately five weeks points to an ongoing campaign rather than discrete, unrelated incidents. The CCI Hauts-de-France, as a public-interest organization supporting businesses across the Hauts-de-France region, represents a target of perceived symbolic value to such actors. The fact that the initial attack occurred during the transition between 2024 and 2025, and the follow-up took place in early February 2025, suggests the threat actor maintained persistent intent and capability throughout this period.
The immediate operational impact of the second attack was limited in duration, with services restored within a matter of hours rather than days. No data loss was reported, and the websites were able to resume operation without evident lasting damage to the underlying systems or databases. This rapid recovery, while positive in terms of operational continuity, nonetheless raises questions about the resilience measures in place and whether the underlying vulnerabilities exploited in the first attack were fully remediated before the second intrusion occurred. The information available indicates that both attacks targeted the publicly accessible web infrastructure of the organization, suggesting the attack vector likely involved web-facing applications or services rather than deep internal network penetration.
Sources
Sources available to members: 1 source.