Direction des Infrastructures, de la Topographie et des Transports Terrestres
Incident posture
Linked entities
- Victim
- Direction des Infrastructures, de la Topographie et des Transports Terrestres
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A government agency responsible for infrastructure, topography, and land transport in New Caledonia was targeted by a cyberattack, with the intrusion detected on a Wednesday. Immediate measures were taken by the government's cybersecurity teams to contain the incident and secure external access to applications, preventing further propagation. The attack likely targeted data related to vehicle registrations and driving licenses, and an investigation was launched in coordination with the state to determine the exact origin of the breach, assess its potential impacts, and reinforce existing security measures. A formal complaint has been filed with the judicial authorities, and the institution has committed to communicating on the progress of the investigations as they advance.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On July 9, 2025, the Direction des Infrastructures, de la Topographie et des Transports Terrestres (DITTT) of New Caledonia fell victim to a cyberattack that specifically targeted systems handling vehicle registrations and driving licenses. The incident was disclosed publicly on Friday, July 11, 2025, through an official communication from the government of New Caledonia, which confirmed that the attack had taken place the preceding Wednesday. According to the government communiqué, the cyberattack was aimed at data related to vehicle registration records and driving permits of Caledonian residents, placing sensitive personal information of citizens at potential risk. The exact nature and origin of the intrusion were not specified in the initial public disclosure, and authorities indicated that an investigation was necessary to establish the precise circumstances of the breach.
Immediately upon detection of the incident, the cybersecurity teams of the New Caledonian government activated emergency response protocols designed to contain the threat and prevent further compromise. Specific measures included the securing of application access from outside the territorial boundaries of New Caledonia, effectively isolating the affected infrastructure from external network reach. This containment strategy was intended to halt any lateral propagation of the attack to other government systems and to preserve the integrity of data that had not yet been affected. The rapid mobilization of internal cybersecurity resources reflected the government's assessment of the seriousness of the incident and its commitment to limiting the damage caused by the intrusion.
The government of New Caledonia announced that an investigation had been formally launched in coordination with national French authorities to determine the exact origin of the attack. The objectives of this collaborative inquiry were threefold: identifying the source of the intrusion, assessing the potential impacts on the compromised data, and reinforcing existing security measures to prevent similar incidents in the future. As part of this process, a formal complaint was filed with the judicial authorities, in accordance with standard legal procedures applicable to cybercriminal activity. The government's commitment to transparency was underscored by its pledge to provide regular updates on the progress of the investigation as new information became available.
At the time of the initial disclosure, the full consequences of the cyberattack remained under evaluation. Government officials indicated that the primary focus of the attackers appeared to be the databases containing vehicle registration and driving license information, though the complete scope of data potentially exposed had not yet been quantified. The assessment phase involved determining whether personal identifying information, administrative records, or other sensitive data had been accessed, modified, or exfiltrated during the intrusion. Until this analysis could be completed, the government could not provide definitive figures regarding the number of individuals affected or the precise nature of the compromised information.
The incident highlighted vulnerabilities in the digital infrastructure supporting essential public services in New Caledonia, particularly those tied to transportation and identity documentation. Vehicle registration and driving license systems serve as critical repositories of personal data, including names, addresses, dates of birth, and license categories, making them attractive targets for cybercriminals seeking valuable identifying information. The DITTT's role as the custodian of these records placed it at the center of the attack, and the response effort required coordination across multiple governmental and technical domains to address both the immediate security concerns and the longer-term implications for data protection.
The communication strategy employed in the immediate aftermath of the incident reflected a measured approach, balancing the need for public awareness with the requirement to avoid compromising the ongoing investigation. By issuing a formal communiqué rather than responding to individual inquiries, the government sought to ensure that accurate, verified details reached the public while preventing the spread of misinformation or premature speculation. The pledge to communicate further developments as the investigation progressed demonstrated an institutional commitment to keeping affected citizens informed about the status of their personal data and the measures being taken to protect it.
While the immediate containment actions focused on external access controls, the broader investigation encompassed a review of internal security protocols, network architectures, and potential entry points that may have been exploited by the attackers. This comprehensive approach aimed not only to understand how the breach occurred but also to identify systemic weaknesses that could be addressed to strengthen the resilience of the DITTT's information systems. The collaboration with French national authorities brought additional expertise and resources to bear on the investigation, reflecting the seriousness with which the incident was treated at both the territorial and national levels.
The filing of a judicial complaint represented a significant step in the response process, signaling the government's intent to pursue accountability for the attack through legal channels. This action also served to formally document the incident for regulatory and investigative purposes, creating an official record that could inform future policy decisions and security enhancements. The intersection of technical investigation and legal proceeding underscored the multidimensional nature of responding to cyberattacks, where digital evidence must be preserved and analyzed in ways that meet both operational and judicial standards.
As the investigation continued beyond the initial disclosure period, the government of New Caledonia maintained its commitment to monitoring the situation and implementing additional protective measures as warranted. The incident served as a catalyst for examining the broader cybersecurity posture of government services in the territory, particularly those handling sensitive personal data. The lessons learned from the attack on the DITTT were expected to inform ongoing efforts to modernize and secure public infrastructure against evolving cyber threats, ensuring that the trust placed in government institutions by citizens regarding the protection of their personal information could be maintained and strengthened.
Sources
Sources available to members: 1 source.