The French Interior Ministry confirmed a cyberattack that compromised its email servers, allowing attackers to access certain document files. In response, the ministry implemented enhanced security protocols and access controls, while an investigation was launched to determine the origin and scope of the breach. Authorities have not yet confirmed whether any data was stolen, and are considering multiple possible motives, including foreign interference, hacktivism, or cybercrime. The Interior Ministry, which oversees police, internal security, and immigration, is considered a high-value target for both state-sponsored and criminal actors.
The incident was reported in several news roundups, highlighting its significance within the broader context of European cybersecurity threats. While attribution has not been established for this specific attack, previous campaigns against French government entities have been linked to Russian state-sponsored groups such as APT28. The breach underscores ongoing concerns about the vulnerability of critical government infrastructure to sophisticated cyber threats and the need for robust incident response and investigation procedures.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
On December 15, 2025, the cyberattack on the ministry's email servers was publicly confirmed in reporting. The incident was described as affecting a high-value government target responsible for police, internal security, and immigration functions.
After discovering the intrusion, the ministry strengthened security protocols and access controls and launched an investigation to determine the attack's origin and scope. Authorities said attribution remained undetermined, with possibilities including foreign interference, activist hackers, or cybercriminals.
The French Ministry of the Interior detected a cyberattack overnight between December 11 and 12, 2025, affecting its email servers. Attackers gained access to some document files, indicating a compromise beyond email infrastructure alone.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcesherpaintelligence.substack.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.