Menu
Browse

Cyber Incident Victim: Université de Rennes

Date:

Mar 2025

Location:

France

Summary

Université deRennes, with about 32 000 students, has been experiencing a cyberattack that is confined to a pedagogical subnetwork; the institution says it was alerted, took rapid measures, and its overall network remains operational. According to the ethical hacker SaxX, the ransomware group Funksec claims to have exfiltrated roughly 50 GB of diverse data including PDFs, CSV files, databases, Gmail addresses, phone numbers, invoices, passwords, SSH keys, student records and photos, and threatens to publish the material unless demands are met. Funksec, identified as a four‑member outfit that employs double extortion tactics, has previously targeted several governments.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On Saturday 8 March 2025, the Université de Rennes, which enrolls approximately 32 000 students, was notified of a cyberattack that had begun earlier that day. The university’s IT services confirmed that the intrusion was confined to a pedagogical subnetwork and that the broader institutional network remained operational. Upon receiving the alert, the IT department implemented immediate containment measures and commenced a preliminary diagnostic of the affected systems. The university stated that it had taken very rapid actions to limit the spread of the incident and to assess the scope of the compromise. The institution also indicated that it was cooperating with external cybersecurity experts to investigate the incident. No disruption to core services or to the overall availability of the university’s IT infrastructure was reported at that time.

Cyber Incident Image

According to the ethical hacker SaxX, the ransomware group Funksec claimed to have exfiltrated approximately 50 gigabytes of data from the compromised subnetwork, describing the material as comprising PDFs, CSV files, databases, Gmail addresses, telephone numbers, invoices, passwords, SSH keys for various servers, student records and photographs. The university has not yet confirmed the authenticity or the volume of the alleged data theft. Funksec further asserted that it would publish the stolen information unless its demands were met, setting a deadline of nine days after the initial notification, which corresponds to Wednesday 19 March 2025. SaxX noted that Funksec emerged at the end of 2024, consists of four members, employs double‑extortion tactics and has previously targeted several governmental entities.

Sources
Sources available to members
1 source