La Poste, France's national postal service, experienced a major disruption after a distributed denial-of-service (DDoS) attack knocked its information systems offline, affecting millions of customers. The incident rendered the main website, mobile app, digital identity service, and Digiposte document storage platform temporarily inaccessible, while also impacting La Banque Postale's online and mobile banking services. Despite the outage, core banking operations such as ATM withdrawals, in-store card payments, and transfers via WERO remained functional, with online payments still possible through SMS authentication. Some physical post office locations operated at reduced capacity, but counter services for banking and postal transactions continued.
The disruption occurred just days before Christmas, leading to delays in parcel deliveries and customer complaints about the potential for missed holiday packages. La Poste stated there was no evidence of customer data compromise and did not attribute the attack to any specific group. The company has not provided a timeline for full service restoration, but teams are working to resolve the issue. The incident follows a separate data breach at France’s Interior Ministry, though there is no indication the two events are connected.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
French authorities, including the DGSI and the Paris prosecutor's office, launched an investigation into the attack after the disruption and subsequent claim of responsibility. The inquiry is examining the incident as part of a broader pattern of pro-Russian DDoS activity targeting European organizations.
By 2025-12-26, the pro-Russian hacktivist group NoName057(16) publicly claimed responsibility for the DDoS attack on La Poste and La Banque Postale. The claim provided a possible attribution, though official confirmation of the group's role had not been established in earlier reporting.
Following the outage, La Poste said it had found no evidence of customer data compromise and began working to restore affected services. Essential functions such as in-person counter services, card payments, and ATM withdrawals remained available, though some offices operated at reduced capacity and online payment authentication shifted to SMS workarounds.
On 2025-12-22, France's national postal service La Poste experienced a major cyber incident, widely reported as a distributed denial-of-service attack, that took key information systems offline. The disruption affected its website, mobile app, digital identity service, Digiposte platform, parcel-related services, and La Banque Postale's online and mobile banking.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
7 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcetherecord.media
Open sourcetechrepublic.com
Open sourcesecurityaffairs.com
Open sourcetechcrunch.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.