Ransomware paralyzed Saint-Nazaire and four neighboring French communes

Organization
City of Saint-Nazaire
Exploit
Ransomware
Industry
Municipal Government

Municipal staff in Saint-Nazaire, on France's Atlantic coast, arrived on the morning of April 10, 2024 to find every one of the city's servers out of service after an overnight intrusion. Because the affected systems were shared across the agglomeration, the outage also hit the communes of Montoir-de-Bretagne, Donges, La Chapelle-des-Marais and Pornichet, along with the CARENE agglomeration authority and the local development bodies Sonadev and ADDRN.

Employees lost access to workstations, file shares, business applications, email and telephone lines, and were told not to switch on computers or open mobile inboxes. Payroll, finance, leave management, water billing, waste collection, childcare registration and school services were all disrupted. The public websites, hosted externally, stayed up. The affected authorities serve about 100,000 residents.

Officials described it as a large-scale attack and said its origin and the likely length of the outage were unknown. France's national cybersecurity agency ANSSI assisted, crisis meetings were held twice a day, and Mayor David Samzun warned of significant consequences, with early estimates that recovery could take months.

The incident was later confirmed as ransomware. Samzun said a ransom was demanded and refused, telling France Bleu it was out of the question to play that game with public money. By late May 2024 the city said roughly a third of the administration's servers had been compromised, services were being restarted on wired connections only, and no data had been stolen.

Sources