Cyber Incident Victim: Ville de Saumur
Date:
Mar 2022
Location:
France
Summary
A cyberattack targeted the Ville de Saumur and its regional agglomeration community, causing widespread infrastructure disruptions. Most systems, including servers, software, and network components, were rendered unavailable as part of security protocols, though schools and library access points remained operational. Authorities filed a formal complaint and activated contingency plans with support from national cybersecurity agencies and external partners. A dedicated crisis unit coordinated response efforts while maintaining physical and telephone services for citizens, including identity document appointments. All public facilities remained open despite technical limitations, with ongoing work to restore full functionality across affected services.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On March 23, 2022, at 8:00 AM, the Ville de Saumur and the Communauté d'Agglomération Saumur Val de Loire experienced a cyberattack that disrupted municipal operations. The attack rendered most infrastructure unavailable for the Ville de Saumur, with the exception of school systems, while the Communauté d'Agglomération maintained functionality at its library branches (points lectures). Information technology staff implemented security protocols that deliberately disabled compromised equipment, including servers, software applications, and segments of the network infrastructure, to contain the incident. Both municipal entities filed formal legal complaints regarding the attack. The disruption triggered immediate activation of contingency measures, including the engagement of national cybersecurity agency ANSSI, technology firm Capgemini, and data protection authority CNIL. A dedicated crisis management unit was established under the leadership of Jackie Goulet, the President-Mayor, to coordinate institutional responses.

Despite widespread technical outages, both organizations maintained public service continuity through physical and telephone access points. Critical citizen services such as national ID card and passport appointment processing continued without interruption, with all municipal offices remaining physically accessible to residents. Officials publicly acknowledged the incident and appealed for public understanding while emphasizing ongoing efforts to restore full functionality across affected public services. No additional technical specifics regarding attack vectors, threat actors, or data compromise were disclosed in the initial public statement. Restoration efforts focused on implementing adapted solutions to reinstate all public-facing systems through coordinated action with external cybersecurity partners and internal IT teams.
