CSIDB logo
Incident

Mairie d'Ostheim

Incident posture

Attack window
Feb 2025
Location
France
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 16:23

Linked entities

Victim
Mairie d'Ostheim
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

On a Sunday in early February, the mairie of a small Haut-Rhin commune of roughly 1,600 inhabitants was struck by a ransomware attack that encrypted around 95% of the data on its server. The incident was detected the following morning when the municipal secretary found an English-language ransom note on his computer, after which officials alerted the mayor, their IT contractor, and the gendarmerie, and filed complaints for extortion and for obstructing an automated data processing system. Because one of three backups had remained intact and uncompromised, staff were able to resume work in degraded mode within days while the accounting data were securely rehosted by the software vendor, and no ransom was paid to the attackers, who were likely to have gained access through an infected email. The recovery cost the commune about €2,500 in external expenses and roughly a day and a half of lost employee productivity, while a gendarmerie cybercell investigation continues into the possibility that data were also exfiltrated.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Sunday, February 2, 2025, a ransomware attack was launched against the IT server of the Mairie d'Ostheim, a commune of slightly more than 1,600 inhabitants located in the Haut-Rhin department, in the Colmar region of eastern France. The intrusion itself went unnoticed on the day it occurred and was only identified the following morning, Monday, February 3, 2025, when Frédéric Schmitt, the secretary of the mairie, powered up his computer and was confronted with an English-language ransom message. According to his account, the message stated in substance that all the municipality's data had been encrypted and that a ransom would have to be paid. The secretary immediately alerted the mayor, the commune's in-house computer technician, and the local gendarmerie. A formal complaint was subsequently filed by the mairie for "extortion, by violence, threat or constraint, of a signature, promise, secret, funds, value or goods," as well as for "obstruction to the functioning of an automated data processing system." No ransom payment was made by the municipality. The commanding officer of the Colmar gendarmerie company warned that paying would only be followed by further financial demands, a stance firmly upheld by the mairie.

The compromised server hosted approximately 95% of the commune's data, rendering the bulk of administrative information inaccessible at the moment the attack was discovered. The initial vector of the intrusion was, according to subsequent analysis, the inadvertent opening of an infected email, a message that had very likely been distributed to a large number of recipients, which is consistent with the mass-distribution tactics commonly associated with this type of campaign. Following the discovery of the encryption, the mairie found itself in a particularly vulnerable position, but one of the three backups held by the commune, described as nearly complete, had fortunately escaped the encryption and could be used to restore operations. This backup proved decisive in allowing the administrative staff to resume work as early as Tuesday morning, February 4, 2025, although for approximately one week the mairie operated in what was described as a "degraded mode." During this period, particular attention had to be paid to ensuring that no virus would be propagated across the restored network, a precaution that slowed the return to normal activity.

The restoration of accounting data, among the most sensitive and operationally critical records held by the commune, required several additional days before it could once again be made fully available. As an extra precaution, these records were subsequently rehoused with the publisher of the accounting software, in order to guarantee that they would no longer pose any risk of virus transmission within the mairie's own network. This intervention, which included the implementation of additional security measures designed to protect the data held by the various business software applications used by the commune, cost the municipality €1,500. A further €1,000 was required to compensate the work carried out by the commune's computer technician. Beyond these direct costs, the mairie also recorded an indirect loss estimated at roughly one and a half days of work by its employees, attributable to the disruption caused by the incident and the gradual restoration of services.

With regard to the possibility that data had been exfiltrated in addition to being encrypted, the mairie acknowledged that it had no certainty. The secretary of the mairie indicated that, according to the assessment provided by the commune's computer technician, it would have been technically very difficult for all of the data to have been genuinely siphoned off, and that any claim to the contrary was most likely intended as a bluff to strengthen the pressure to pay the ransom. The full body of information gathered locally was forwarded by the gendarmerie to the cybercrime cell based in Paris, and an investigation was opened to attempt to identify the perpetrators. The mairie for its part announced that prevention measures would be strengthened internally, with a particular emphasis on vigilance concerning email correspondence.

Beyond the immediate response, the incident also had a wider resonance across the Alsacien territory. Other communes, having learned of the attack against Ostheim, contacted the cybersecurity referent of the Haut-Rhin gendarmerie group, who, as in the Bas-Rhin, has been offering since 2023 free services ranging from simple exchanges and prevention sessions to preliminary diagnoses for local authorities and businesses. Although the gendarmerie was unable to disclose figures on the number of Alsatian local authorities already affected by ransomware, it reported significant outreach activity over the past year, with awareness sessions having been delivered to approximately 140 elected officials, 500 business leaders and around a thousand other individuals. The figures given concerning comparable incidents elsewhere in France underlined the scale of the financial risk involved: the city of Lille, with 236,200 inhabitants, had reportedly suffered costs in excess of one million euros following a similar attack in 2023, according to La Gazette des communes. The recommendations made publicly by the gendarmerie to limit the likelihood of such incidents emphasised the need to keep software and hardware constantly updated, to use sufficiently strong passwords, to plan and test multiple backups, and above all to guard against the human errors that enable 90% of attacks. The mairie of Ostheim, having weathered the incident without paying any ransom and with the bulk of its data preserved thanks to a robust backup policy, continued to operate normally after the one-week period of degraded activity, while the investigation entrusted to the Paris-based cybercrime cell remained ongoing at the time of reporting.

Sources

Sources available to members: 1 source.

CSIDB