Cyber Incident Victim: Ville de Gravelines
Date:
Apr 2024
Location:
France
Summary
The Ville de Gravelines experienced a cyberattack prompting precautionary measures including disconnecting all servers and restricting internet access for municipal services. While the origin remains undiagnosed, city hall and services remain reachable by telephone, though certain operational functions are temporarily unavailable. Authorities continue to monitor the situation.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On April 25, 2024, the municipal administration of Gravelines, a commune in northern France, publicly confirmed it was experiencing an active cyberattack. The incident prompted immediate containment measures, including the precautionary disconnection of all municipal servers and the restriction of internet access across communal services. City officials stated the technical response began upon detection of the attack, though they emphasized it remained impossible to diagnose its origin or nature at that initial stage. Municipal operations faced disruptions, with some digital services becoming unavailable despite core functions like telephony remaining operational. The city hall and its departments maintained telephone accessibility for public inquiries, though specific online or server-dependent actions were temporarily suspended. No details regarding the initial attack vector, data compromise, or threat actor were disclosed in public communications.

The cyberattack impacted routine administrative functions, though the city did not specify which services or systems were most severely affected beyond the generalized server and internet restrictions. Municipal authorities utilized social media platforms, including an official Facebook post, to notify residents of the incident and the operational limitations. They committed to providing updates as the situation evolved but did not offer a projected timeline for full service restoration. The incident response appeared focused on isolation and stabilization, with no mention of ransom demands, data exfiltration, or secondary impacts on critical infrastructure. Gravelines’ public communications emphasized continuity of basic operations through alternative channels while forensic analysis and recovery efforts proceeded under restricted conditions. The city maintained this posture through the initial disclosure period without further elaboration on technical specifics or long-term consequences.
