Un pirate cible à nouveau les SDIS français
A series of coordinated cyberattacks targeting French fire and rescue services (SDIS) have been ongoing since July 2026, with a new wave of attacks occurring at the end of August. Multiple SDIS, including those in the Somme, Essonne, Bas-Rhin, Bouches-du-Rhône, Gard, Vosges, and Moselle departments, have been compromised, exposing sensitive data including personnel details, technical information, and access credentials. The attacks are part of a broader effort to map the French fire and rescue infrastructure for potential targeted phishing, impersonation, and reconnaissance purposes. The data is being aggregated to create a detailed profile of the services, potentially beyond simple financial gain.
A series of cyberattacks targeting French fire and rescue services (SDIS) have been ongoing since July 2026, with a new wave of attacks occurring at the end of August. Multiple SDIS, including those in the Somme, Essonne, Bas-Rhin, Bouches-du-Rhône, Gard, Vosges, and Moselle departments, have been compromised. These attacks are part of a longer-term campaign attributed to various actors, including ChimeraZ, Cybernox, and AplaGroup.
During the weekend of August 2026, a cybercriminal targeted several SDIS, continuing a trend revealed by ZATAZ in July. Previous publications linked to these attackers exposed databases, internal documents, personal information, and administrator access. The data is not simply being leaked; instead, it’s being strategically gathered to build a comprehensive understanding of the French fire and rescue system.
At least 166,376 people were exposed, with estimates potentially reaching 932,376 individuals based on reported volumes. This number represents a significant portion of the personnel involved in French fire and rescue services. The attackers are leveraging the data to create a detailed profile, including names, dates of birth, addresses, phone numbers, email addresses, service numbers, ranks, assignments, photographs, and badge information.
For example, on June 3, 2026, AplaGroup claimed to have leaked 2,637 public service agents and 54 private sector individuals, including details about their family contacts. On July 16, 2026, the same attacker announced a leak from Pompiers.fr, the membership platform of the French National Firefighters Federation, affecting 124,807 people. Furthermore, the same day, the attacker revealed a second leak directly targeting the French National Firefighters Federation, raising concerns due to the presence of minors in the data.
The ongoing attacks highlight the continued interest in French fire and rescue services. Individually, an address book exposes individuals. However, when combined with assignments, technical functions, family contacts, and digital access, it becomes a valuable asset for targeted phishing campaigns, impersonation attempts, or reconnaissance of infrastructure. ZATAZ emphasizes that the central objective is aggregation – each new claim contributes to a growing map of the French fire and rescue services, both human and technical.
