CSIDB logo
Incident

Ifag

Incident posture

Attack window
Feb 2023
Location
France
Status
Historical
CIA posture
Available to members
Updated
2025-11-19 00:00

Linked entities

Victim
Ifag
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeted the Maison de l'entreprise in Auxerre, affecting multiple educational entities including the Ifag management school by encrypting files and paralyzing its entire data system. The incident, described as part of an international campaign impacting hundreds of thousands of systems simultaneously, prompted an investigation involving France's national cybersecurity agency, cybercrime units, and local police, with jurisdiction transferred to Paris prosecutors due to the attack's nationwide scale. Response efforts included specialized police training and outreach to protect small businesses from similar threats, while the organization worked to resolve the ongoing disruption.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The cyberattack targeting the Maison de l'entreprise in Auxerre began during the night of February 20 to 21, 2023, crippling the data systems of multiple educational institutions housed at the Monéteau Road facility. The attack paralyzed the entire IT infrastructure of the Ifag management school along with four affiliated entities: EPSI, ITII, IET, and pôle formation 58-89. Attackers employed file encryption techniques that rendered all systems inaccessible, effectively halting operations. Claude Vaucouloux, Director of Ifag, publicly confirmed the incident on the morning of February 23, characterizing it as part of an "international attack" allegedly compromising hundreds of thousands of systems simultaneously. The cyber intrusion remained active as of the evening of February 23, with no restoration timeline provided. Vaucouloux declined to specify operational consequences for the management school but emphasized the comprehensive nature of the compromise, stating "nothing remains accessible" due to the encryption-based assault.

Authorities mobilized multiple investigative units in response to the breach. The National Cybersecurity Agency (ANSSI), National Sub-Directorate for Cybercrime Combat (SDLC), and local police initiated parallel investigations, reflecting the incident's perceived severity. By February 23, jurisdictional oversight shifted from the Auxerre prosecutor's office to Paris authorities, indicating recognition of the attack's national scope. Sébastien Halm, Departmental Director of Public Security for Yonne, contextualized the response within broader protective measures for regional businesses, referencing prior police initiatives to catalog vulnerable entities and specialized agent training programs conducted during 2022. The coordinated law enforcement engagement underscored institutional concerns about cyber threats targeting small and medium enterprises, though specific forensic findings or attribution details remained undisclosed at the time of reporting.

Sources

Sources available to members: 1 source.

CSIDB