CSIDB logo
Incident

Grand Est

Incident posture

Attack window
Feb 2020
Location
France
Status
Historical
CIA posture
Available to members
Updated
2025-11-01 00:00

Linked entities

Victim
Grand Est
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack targeted the Grand Est region in northeastern France, paralyzing its entire computer network by corrupting 80 servers and encrypting all system data. The attackers issued a ransom demand, which the regional administration did not engage with, instead focusing on restoring operations. The incident severely compromised the IT infrastructure, disrupting services and impacting the local community during the response efforts.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 13, 2020, the Grand Est region of northeastern France experienced a significant ransomware attack that paralyzed its computer infrastructure. The incident began in the evening when attackers successfully corrupted all 80 servers within the regional network. This resulted in the complete encryption of the region's system data, rendering critical operations inoperable. Following the encryption, the perpetrators issued a ransom demand to the regional administration. The Grand Est authorities did not comply with the ransom request and instead initiated efforts to restore their systems. By February 14, the full scope of the compromise became evident as the entire IT network remained non-functional, affecting governmental operations and public services across the territory.

The cyber attack caused widespread disruption to the region's administrative functions and community services due to the total network compromise. No specific details about operational impacts on hospitals, transportation, or other critical sectors were disclosed in available reports. Regional technicians worked systematically to recover encrypted data and rebuild corrupted servers without paying the extortion demand. The recovery process involved gradual restoration efforts rather than immediate full-system reactivation. Authorities did not publicly identify the ransomware variant used in the attack or disclose whether data exfiltration occurred alongside encryption. The incident highlighted vulnerabilities in regional government networks, though technical specifics about initial attack vectors or security shortcomings remained unconfirmed in source documentation.

Sources

Sources available to members: 1 source.

CSIDB