The 10 cyberattacks that marked France in 2024
Quick reply
Hospitals, local authorities and major retailers: a look back at the attacks that marked France in 2024 and how each one was handled.

In 2024, France was the target of a great many significant cyberattacks, across a range of sectors. In France, in 2023, 69% of cyberattacks were aimed at companies. 20% concerned local authorities and 11% healthcare facilities.
Healthcare, the year's first victim
Simone Veil hospital in Cannes
In January 2024, Simone Veil hospital in Cannes suffered a major cyberattack involving ransomware, which encrypted all of its medical and administrative data. The attackers demanded a ransom in exchange for the decryption key. The attack paralysed hospital services and forced staff back onto paper. It seriously disrupted patient care and called for additional measures to protect sensitive data.
In response, the hospital's management put a crisis plan into action with the help of cybersecurity experts and the relevant authorities, in order to contain the attack and restore the systems. The situation called for additional measures to secure sensitive data. The attack brought considerable financial costs along with prolonged delays to services.
Ramsay Santé group
On 25 January 2024, the Ramsay Santé group fell victim to a cyberattack that disrupted three healthcare facilities in Lyon and Bourg-en-Bresse. The attack affected the IT systems, forcing staff to manage patients and care by hand. Emergency measures kept care running and strengthened defences against future attacks.
"In the Toulouse area, only the Clinique de l'Union is affected by these anomalies," the Ramsay group confirmed in a press release. "Patient care may also have been slowed by the shutdown of external access and the temporary halt of certain servers."
But how do you actually protect yourself? Download our ebook for advice and recommendations on digital security.

37% of public sector organisations under threat in 2024
France Travail
In February 2024, France Travail, the national employment agency, fell victim to a large-scale cyberattack using sophisticated malware to infiltrate its IT systems. The attack compromised thousands of personal and professional records and disrupted the agency's services. France Travail put an emergency plan into action with the help of ANSSI, the national cybersecurity agency, to contain the attack and restore services.
Saint-Nazaire
In April 2024, a large-scale cyberattack hit the town of Saint-Nazaire and its surrounding authority, paralysing IT systems and municipal services. A crypto-virus infected around a third of the town's 450 servers, forcing a return to working by hand. The authorities estimate it will take several months to return to the level of service that existed before the attack.
Pont-à-Mousson
The local authority for the Pont-à-Mousson area fell victim to a cyberattack during the night of 4 April 2024. The attackers infiltrated the system, causing major disruption to public services. A crypto-virus, a type of malware that encrypts data and demands a ransom in exchange for the decryption key, was detected. The attack led the authorities to shut down every server in order to limit the damage, which meant a temporary return to manual working for certain administrative functions.
Orange brought in its cyberdefence subsidiary to resolve the situation. The council contacted the CNIL, France's data protection authority, and ANSSI, the national cybersecurity agency, and filed a complaint. The attackers have not yet formally issued a ransom demand.
How do you get support during a cyberattack? Plans exist. Business continuity and disaster recovery plans are there to put procedures in place for identifying and assessing risks. They guarantee that data is backed up and restored so that operations continue even during a cyberattack.
Cybercriminals target long-established names
Société Générale
Since the start of the year, Société Générale has been the target of a wide phishing campaign. Carried out by email and text message, it sought to steal the banking details of its customers. The attackers sent messages imitating the bank's official communications in order to mislead users and obtain their credentials. Société Générale quickly alerted its customers and took steps to limit the damage.
In response to the threat, Société Générale stepped up its awareness efforts. Information campaigns were launched to help customers recognise phishing attempts. Its website offers practical guides, and regular notifications remind people of good online security practice.
The bank also strengthened its fraud detection and prevention systems, working closely with the relevant authorities to track down and neutralise those behind the attacks.
ENGIE
In May 2024, ENGIE fell victim to a cyberattack claimed by the Lapsus group, behind a breach that leaked sensitive customer data. The information compromised included names, addresses and appointment details. ENGIE took steps to secure its systems and inform the customers concerned.
To deal with the situation, ENGIE immediately brought in a team of cybersecurity specialists to strengthen its infrastructure and prevent future intrusions. The company also worked with the authorities and regulators to investigate the incident. Alongside that, support services are helping affected customers protect their personal information and watch for any suspicious activity on their accounts.
Intersport
Intersport suffered a major cyberattack in which attackers stole 52 GB of sensitive data. The intrusion compromised the personal information of customers and employees, and raised serious concerns about data protection and the company's security.
A dedicated cybersecurity team investigated the incident and strengthened data protection measures. The company worked with IT security experts and the authorities to trace the origin of the attack and minimise the damage. Intersport also informed the customers and employees affected by the leak, giving them recommendations for protecting their personal information against possible fraudulent use.
SNCF
Early in 2024, a sophisticated phishing campaign targeted users of SNCF, the national railway operator, fraudulently offering substantial discounts on its Avantages card. The attackers used counterfeit emails and text messages to persuade victims to hand over sensitive banking details.
The Olympic Games, a goldmine for phishing
The Paris 2024 Olympic Games faced a significant cyber threat, with more than 4 billion cyberattacks expected during the event. Attacks could target various aspects of the games, ticketing, stadium access systems, television broadcasting and critical infrastructure among them. ANSSI therefore put a robust strategy in place to secure the event and prevent major disruption.
These cyberattacks highlight how vulnerable critical infrastructure is, and how important it is to strengthen cybersecurity at every level in order to protect sensitive data and keep services running.
Other articles you might like
Strengthening your resilience against cyberattacks
Ransomware and human error: the technical and organisational levers that build resilience and let you react quickly after an incident.


But let's be honest, our cloud-based file storage and sharing solution is much easier.


