Menu
Browse

Cyber Incident Victim: Ville de Saumur

Date:

Mar 2022

Location:

France

Summary

A cyberattack targeted the Ville de Saumur and its regional agglomeration community, causing widespread infrastructure disruptions. Most systems, including servers, software, and network components, were rendered unavailable as part of security protocols, though schools and library access points remained operational. Authorities filed a formal complaint and activated contingency plans with support from national cybersecurity agencies and external partners. A dedicated crisis unit coordinated response efforts while maintaining physical and telephone services for citizens, including identity document appointments. All public facilities remained open despite technical limitations, with ongoing work to restore full functionality across affected services.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On March 23, 2022, at 8:00 AM, the Ville de Saumur and the Communauté d'Agglomération Saumur Val de Loire experienced a cyberattack that disrupted municipal operations. The attack rendered most infrastructure unavailable for the Ville de Saumur, with the exception of school systems, while the Communauté d'Agglomération maintained functionality at its library branches (points lectures). Information technology staff implemented security protocols that deliberately disabled compromised equipment, including servers, software applications, and segments of the network infrastructure, to contain the incident. Both municipal entities filed formal legal complaints regarding the attack. The disruption triggered immediate activation of contingency measures, including the engagement of national cybersecurity agency ANSSI, technology firm Capgemini, and data protection authority CNIL. A dedicated crisis management unit was established under the leadership of Jackie Goulet, the President-Mayor, to coordinate institutional responses.

Cyber Incident Image

Despite widespread technical outages, both organizations maintained public service continuity through physical and telephone access points. Critical citizen services such as national ID card and passport appointment processing continued without interruption, with all municipal offices remaining physically accessible to residents. Officials publicly acknowledged the incident and appealed for public understanding while emphasizing ongoing efforts to restore full functionality across affected public services. No additional technical specifics regarding attack vectors, threat actors, or data compromise were disclosed in the initial public statement. Restoration efforts focused on implementing adapted solutions to reinstate all public-facing systems through coordinated action with external cybersecurity partners and internal IT teams.

Sources
Sources available to members
1 source