Cyber Incident Victim: Service Départemental d'Incendie et de Secours des Pyrénées-Atlantiques
Date:
Oct 2023
Location:
France
Summary
A French fire and rescue service in Pyrénées-Atlantiques experienced a cyberattack compromising its office and IT infrastructure, disrupting administrative operations. Emergency call services remained functional, ensuring uninterrupted public access to critical response systems. The organization activated immediate containment measures to maintain operational continuity for rescue activities while addressing the technical breach. Internal systems faced significant disruptions, though core emergency response capabilities were preserved through contingency protocols. Investigations and mitigation efforts were underway to restore affected infrastructure.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On October 12, 2023, the Service Départemental d'Incendie et de Secours des Pyrénées-Atlantiques (SDIS 64) experienced a cyberattack disrupting its operational infrastructure. The attack began during the morning hours, targeting the organization's office and IT systems, as confirmed by the prefecture in an evening statement. Initial impacts affected "infrastructures bureautiques et informatiques," compromising administrative functions and internal communications. Emergency response capabilities involving the 18 emergency call line remained fully operational, ensuring public safety services were not interrupted. The prefecture implemented immediate containment measures to safeguard critical operations and maintain service continuity, though specific technical details of these actions were not disclosed. No information was provided regarding the attack vector, threat actor attribution, or data compromise at this initial stage.

The incident prompted an ongoing operational response focused on restoring affected systems while preserving core emergency response functions. The prefecture committed to providing additional details later in the day following the initial disclosure, though subsequent updates were not documented in the available source material. No disruptions to firefighting or rescue deployments were reported, indicating successful isolation of critical emergency systems from compromised infrastructure. The cyberattack represented a significant operational challenge for SDIS 64, requiring sustained mitigation efforts to address compromised administrative networks. Organizational priorities centered on maintaining public safety services while managing the technical and logistical consequences of the attack on non-emergency systems.
