Hackers breached the email servers of the French Ministry of the Interior, as confirmed by Interior Minister Laurent Nunez. The attack, detected between December 11 and 12, allowed threat actors to access certain document files, though there is no current evidence of serious data compromise. In response, the ministry has tightened security measures and reinforced access controls for all agents, while an investigation is underway to determine the origin and scope of the breach. Authorities are considering various scenarios, including foreign interference, hacktivism, or cybercrime, and have not yet released technical details about the attack.
Following the breach, there are indications that emails sent from the French Ministry of the Interior's domain were used to announce the reopening of BreachForums, a notorious cybercriminal marketplace. This suggests that the attackers may have leveraged their access to the ministry's email infrastructure for further malicious activity, potentially as part of a hacker honeypot or to lend credibility to their communications. The incident highlights the risks associated with compromised government email systems and the potential for such breaches to be exploited in broader cybercriminal operations.

See the actors and campaigns active against you right now.
7 events from the most recent confirmed update back to the earliest known activity.
French authorities arrested a 22-year-old suspect on December 17, 2025, in connection with the cyberattack on the Interior Ministry. The investigation, led by the Office for Combating Cybercrime, remained ongoing as officials worked to determine whether others were involved and to verify the attackers' claims.
BreachForums' reopening was announced through emails sent from the French Interior Ministry's domain, raising concerns that the government email infrastructure had been compromised or abused for spoofing. The messages linked the ministry breach to the cybercriminal forum's return.
The Interior Ministry tightened security controls in response to the incident, including password changes, reinforced access restrictions, and deployment of two-factor authentication. Officials said the attack was being handled with the highest level of vigilance because of the sensitivity of the affected systems.
Following discovery and publicization of the breach, the ministry's cybersecurity center, ANSSI, and judicial authorities began investigations to determine the origin, scope, and impact of the intrusion. A data breach notification was also filed with France's data protection regulator, CNIL.
A user tied to the relaunched BreachForums forum claimed responsibility for the Interior Ministry hack, posted screenshots as alleged proof, and asserted the breach was retaliation for prior arrests of forum members. The actor also claimed access to highly sensitive French law enforcement data, though authorities did not verify those claims.
During the intrusion, attackers accessed dozens of confidential documents and may have used compromised email accounts to reach internal business applications. Officials said there was no confirmed evidence at that stage of major data theft or a ransom demand.
France's Ministry of the Interior detected a cyberattack affecting its internal email infrastructure between December 11 and 12, 2025. Attackers gained unauthorized access to several ministry email accounts and some document files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
6 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcetherecord.media
Open sourcesecurityonline.info
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.