Menu
Browse

Cyber Incident Victim: Province des îles Loyauté

Date:

Dec 2023

Location:

France

Summary

A ransomware attack targeted the provincial government of Îles Loyauté, encrypting files and demanding a $1 million ransom. Staff discovered inaccessible data overnight, with initial encryption occurring at 3 AM. Technical teams worked through the weekend to restore systems using recovered backups, prioritizing critical departments for service resumption. The province filed a formal complaint with local gendarmerie, triggering involvement of a specialized cybercrime unit. Recovery efforts focused on infrastructure restoration and data integrity assessments to achieve operational functionality.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On December 7-8, 2023, the Province des îles Loyauté in New Caledonia experienced a ransomware attack that disrupted its digital infrastructure. The malicious software encrypted files and blocked employee access to all data systems during the overnight hours, with initial encryption activity detected at 3:00 AM local time. Wacapo Taïn, the provincial director of digital systems, confirmed staff discovered the compromise when personnel could no longer access operational data on Friday morning. Attackers demanded a $1 million USD ransom (approximately 110 million XPF) to restore system access. Technical teams immediately mobilized on Friday and worked throughout the weekend to assess damage and restore services, prioritizing recovery efforts to achieve functional operations by Monday. Preliminary investigations revealed that attackers compromised at least one primary data site, though technicians successfully retrieved uncorrupted backups from another provincial infrastructure location.

Cyber Incident Image

The provincial government filed an official complaint with the Wé gendarmerie in Lifou on Friday afternoon, triggering involvement of the Public Prosecutor's Office and activation of the gendarmerie's cybercrime unit established in 2021. Recovery efforts focused on rebuilding infrastructure integrity while conducting comprehensive data audits to prioritize restoration of essential services. Technical personnel worked to sanitize recovered backups and prepare systems for partial reactivation, targeting optimal functionality by Sunday with acknowledgment that certain departments would receive priority. No data exfiltration was mentioned in initial reports, with impact confined to system accessibility and data encryption. The incident occurred during a period of heightened political sensitivity in New Caledonia, though no direct connection was established between the attack timing and the territory's historical referendum context within the available information.

Sources
Sources available to members
1 source