2026-08-31 · view entry permalink →
A recurring wave of data-leak claims against French departmental fire-and-rescue services (SDIS) hits seven more units, with the first board-level victim confirmation
Over the last weekend of August 2026 a criminal actor published fresh data-leak claims against seven more French Services départementaux d'incendie et de secours (Somme, Essonne, Bas-Rhin, Bouches-du-Rhône, Gard, Vosges and Moselle) extending a campaign ZATAZ first documented in late July 2026 against five other SDIS (Aisne, Alpes-de-Haute-Provence, Landes, Marne, Alpes-Maritimes), where postings were attributed to three separate criminal-forum handles: ChimeraZ, Cybernox and AplaGroup (ZATAZ.COM, 2026-08-30). Of the August wave, Objectif Gard names only ChimeraZ, tying the same handle to five of the seven units (Gard, Bouches-du-Rhône, Moselle, Bas-Rhin and Vosges); no source names an actor for the Somme or Essonne claims, or ties Cybernox or AplaGroup to this wave. This is not merely a criminal claim: contacted directly on 30 August, the president of SDIS du Gard's governing board confirmed the cyberattack and theft of personal data on personnel, including copies of identity documents and bank details, with the full scope and intrusion method still under investigation (Objectif Gard, 2026-08-30).
No common intrusion vector has been established across the incidents in this campaign. The one case with a stated mechanism is from the July wave: SDIS de l'Aisne, where a claimed administrator-level access credential was posted in cleartext by the actor; ZATAZ notes its current validity cannot be established from the post alone, since access can be disabled or changed after disclosure, but the posting itself is a more critical indicator than a plain directory extraction (ZATAZ.COM, 2026-07-26). The July wave's cumulative claims, spanning the Landes, Marne (2,167 people), Alpes-Maritimes (2,325 people), Alpes-de-Haute-Provence and Aisne SDIS, plus separate claims against SDIS d'Indre-et-Loire (2,637 public-service agents plus 54 individuals linked to private structures) and the Pompiers.fr / Fédération nationale des sapeurs-pompiers de France membership platform (ZATAZ.COM, 2026-07-26), totalled at least 166,376 exposed individuals, with a potential total exceeding 932,376 depending on the volumes claimed; ZATAZ is explicit that this estimate is a straight sum of announced record counts and does not mean each line was technically verified or maps to a distinct person (ZATAZ.COM, 2026-08-30). Each publication in the campaign otherwise appears to be a distinct claim rather than evidence of one coordinated technical compromise.
SDIS du Gard was indeed the victim of a cyberattack and data theft. Contacted this Sunday 30 August by Objectif Gard, Alexandre Pissas, chairman of SDIS 30's board, confirms the computer attack and the theft of personal data concerning personnel.
Among the stolen information are said to be particularly sensitive data, notably copies of identity documents and bank details.
this data can help map personnel, roles, technical structures, hierarchical relationships and digital infrastructure of the French rescue services