France’s Interior Ministry has confirmed it was hit by a cyberattack that compromised parts of its email infrastructure, with investigators still working to determine who was behind it and what—if anything—was taken.
Interior Minister Laurent Nuñez acknowledged the incident on Friday, December 12, 2025, after the intrusion was detected overnight between Thursday, December 11, and Friday, December 12. Nuñez said an attacker gained access to “a number of files,” prompting the ministry to activate its standard incident-response procedures and tighten access to internal systems.
So far, officials haven’t confirmed data theft and have cautioned that the scope of access is still being assessed.
What happened
According to Nuñez, the breach affected the ministry’s email servers and allowed unauthorized access to some documents. The ministry has since strengthened security protocols and access controls for the information systems used by personnel, while French authorities have opened an investigation into the origin, method, and impact of the intrusion.
Who might be responsible
Nuñez said investigators are exploring several possibilities, including:
- Foreign interference
- Activists attempting to demonstrate weaknesses in government systems
- Cybercrime, including theft or extortion-driven activity
At this stage, the ministry hasn’t attributed the incident to a specific group.
Why this target matters
France’s Interior Ministry oversees police forces and internal security, along with key immigration functions—making it a high-value target for both state-backed threat actors and financially motivated attackers.
The incident also lands in a broader context of heightened concern about state-linked cyber activity. On April 29, 2025, France publicly attributed a multi-year hacking campaign affecting French entities to APT28, a group linked to Russia’s military intelligence service (GRU), referencing operations tied to GRU Unit 20728. French cybersecurity authorities have also warned that APT28 activity has repeatedly targeted email infrastructure, including Roundcube servers, in efforts to collect strategic intelligence from government and related organizations.
