France has publicly attributed the 2017 hack-and-leak operation against Emmanuel Macron’s presidential campaign to APT28, the GRU-linked group also known as Fancy Bear, marking its first formal accusation over the incident. French officials said the operation stole thousands of campaign emails and documents and released them shortly before the presidential runoff, part of a broader pattern of Russian cyber activity that Paris says has also targeted French media, public services, economic sectors, and organizations tied to the Olympic Games. Earlier reporting said U.S. intelligence had warned France about suspected Russian election hacking ahead of the leak, while researchers at the time pointed to indicators consistent with Moscow-linked operations but stopped short of definitive attribution.
The leak was amplified online through 4chan, Twitter/X, WikiLeaks, bots, and U.S. far-right activists backing Marine Le Pen, while French authorities and election regulators urged media and voters not to spread the material during the campaign blackout. Macron’s team said genuine files were mixed with forged or decoy documents, and French officials warned that fake news had been inserted to distort the vote. Analysts later assessed that the operation failed to significantly sway the election because French institutions had prepared for cyber-enabled interference, media outlets limited republication of the dump, and public messaging shifted attention from the leaked files to the attempted information warfare campaign itself.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
France publicly stated for the first time that Russia's GRU-linked APT28 group was responsible for the 2017 cyberattack on Emmanuel Macron's presidential campaign. The foreign ministry condemned Russia's use of APT28 and linked the group to a broader pattern of targeting French interests.
A later analysis argued that the 2017 Macron leaks resembled prior information warfare tactics but failed because French authorities and the Macron campaign anticipated the threat and reduced the credibility of the stolen material. The campaign's claim that some documents were forged helped shift attention from the contents to the attack itself.
Flashpoint said it assessed with moderate confidence that the hacking and leaking of Emmanuel Macron's campaign emails was tied to Fancy Bear/APT28, citing phishing activity, malware reporting, and the broader pattern of Russian targeting of Western elections. The assessment noted suggestive Russian-language metadata but cautioned that such artifacts could have been forged and were not conclusive proof.
NSA Director Mike Rogers said the United States had warned France about Russian hacking threats before the Macron-related leak. He did not directly attribute the incident to Moscow, though researchers had already raised suspicions of Russian involvement.
The hack-and-leak campaign failed to significantly influence the outcome of the French presidential election, according to later analyses. French institutional preparation, media restraint, and public messaging helped blunt the effect of the release.
American far-right activists, bots, WikiLeaks, and coordinated online communities amplified the leaked materials and related anti-Macron narratives across Twitter, 4chan, and Discord. French media largely refrained from reporting the contents because of electoral restrictions, limiting the operation's immediate impact.
France's election campaign commission said the leaked data appeared to come from Macron campaign systems and warned that fake news was likely mixed into the release. It urged media outlets and the public not to publish or relay the documents during the legally mandated campaign blackout before the vote.
Macron's team said the operation was a massive, coordinated hack affecting staff members' personal and professional accounts and campaign records. It also stated that genuine files had been mixed with falsified or decoy documents to sow confusion and disinformation.
Thousands of internal emails and documents from Macron's campaign were stolen and released online about 36 hours before the presidential runoff. The dump was circulated through links posted on 4chan and quickly spread under the hashtag #MacronLeaks.
Before the final leak, Emmanuel Macron's campaign said it had already been targeted by suspected Russia-linked hackers and that earlier intrusion attempts had been blocked. These warnings formed part of the broader concern over election interference.
Ahead of the 2017 presidential election, French authorities warned political parties about cyber-enabled interference risks and put response mechanisms in place based on lessons from earlier foreign election meddling cases. U.S. intelligence also shared warnings and lessons with France and other European allies amid fears of Russian hacking.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
10 references tracked. Mallory keeps watching after this page renders.
theguardian.com
Open sourcecsis.org
Open sourcecyberscoop.com
Open sourcepolitico.com
Open sourcenytimes.com
Open sourcefoxnews.com
Open sourcewashingtonpost.com
Open sourcetheguardian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.