Hackers launched a cyberattack against France’s Interior Ministry that lasted several days, Interior Minister Laurent Nuñez said.
The attackers focused on email accounts within the Place Beauvau ministry, which employs nearly 300,000 people.
Nuñez publicly confirmed the incident on Wednesday after investigators identified the breach.
The cyberattack compromised internal email accounts and exposed sensitive police information.
Nuñez said the attackers accessed protected systems connected to law enforcement operations.
He discussed the incident during an interview with the Franceinfo news outlet.
Authorities immediately opened a judicial investigation to identify those responsible.
Email Access Opened the Door to Sensitive Files
Attackers infiltrated several professional email inboxes used by ministry employees.
They obtained access codes that allowed deeper entry into internal networks.
Nuñez said the intruders viewed several highly sensitive police databases.
These systems included the Criminal Records Processing System, known as the TAJ.
They also accessed the Wanted Persons File, referred to as the FPR.
Officials still cannot determine the full scale of the data exposure.
Nuñez said attackers may have removed several dozen files from the systems.
The minister said he could not confirm any impact on ongoing investigations.
However, he stressed that the breach did not endanger public safety.
Authorities received no ransom demand from the attackers, he added.
Security Lapses and the Ongoing Investigation
Nuñez attributed the intrusion to failures to follow basic cybersecurity rules.
He said staff members receive frequent reminders about security procedures.
Even a few careless actions can expose entire systems, he warned.
The attack targeted the ministry’s email infrastructure over several consecutive days.
Last week, BFMTV reported suspicious activity affecting the ministry’s email servers.
After those reports, a hacker group claimed access to data from over 16 million people.
The group offered no evidence to support its claim.
Nuñez dismissed the allegation and called it false.
The ministry reported the breach to the CNIL, as the law requires.
Nuñez also ordered an internal administrative review.
France’s Anti-Cybercrime Office now leads the investigation into the attack.
