CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

SDIS 66 data theft (September 2026)

incident · incident:sdis-66-data-theft-2026-09 single-source

SDIS 66, the fire and rescue service of the Pyrénées-Orientales, confirmed on 2026-10-01 that data was stolen from a provider-maintained server, including patient rescue forms with medical data and identity-document copies; crews moved to handwritten forms and radio, and a forum user's claim of nearly 120,000 records is unverified (ICI / Radio France, 2026-10-01).

Aliases: SDIS des Pyrénées-Orientales data theft

Coverage
1
first 2026-08-31 → last 2026-08-31
Latest activity
2026-10-02
SDIS 66 confirms theft of patient rescue forms; crews are back to paper and radio
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector · regions: europe
Sources cited
4
3 hosts

Defender insights

What each entry about SDIS 66 data theft (September 2026) tells a defender to do, newest first.

2026-08-31NOTABLESDIS 66 confirms theft of patient rescue forms; crews are back to paper and radio

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

related to

Story timeline

  1. 2026-08-31A recurring wave of data-leak claims against French departmental fire-and-rescue services (SDIS) hits seven more units, with SDIS du Gard confirming a theft; separately, SDIS 66 confirms a theft that forced crews back to paper and radio
    active-threatsSDIS 66 confirms theft of patient rescue forms; crews are back to paper and radio

Hunting pivots

ATT&CK techniques (2 across 5 tactics)

2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessValid Accounts
  • PersistenceValid Accounts
  • Privilege EscalationValid Accounts
  • StealthValid Accounts
  • CollectionData from Information Repositories

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-31/france-sdis-fire-rescue-data-leak-campaign · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-31/france-sdis-fire-rescue-data-leak-campaign · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-31/france-sdis-fire-rescue-data-leak-campaign · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-31/france-sdis-fire-rescue-data-leak-campaign · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-08-31/france-sdis-fire-rescue-data-leak-campaign · ATT&CK page ↗

Entries about SDIS 66 data theft (September 2026) (1)

2026-08-31 · view entry permalink →

NOTABLEupdatedNATOB2

A recurring wave of data-leak claims against French departmental fire-and-rescue services (SDIS) hits seven more units, with SDIS du Gard confirming a theft; separately, SDIS 66 confirms a theft that forced crews back to paper and radio

Over the last weekend of August 2026 a criminal actor published fresh data-leak claims against seven more French Services départementaux d'incendie et de secours (Somme, Essonne, Bas-Rhin, Bouches-du-Rhône, Gard, Vosges and Moselle), extending a campaign ZATAZ first documented in late July 2026 against five other SDIS (Aisne, Alpes-de-Haute-Provence, Landes, Marne, Alpes-Maritimes), where postings were attributed to three separate criminal-forum handles: ChimeraZ, Cybernox and AplaGroup (ZATAZ.COM, 2026-08-30). Of the August wave, Objectif Gard names only ChimeraZ, tying the same handle to five of the seven units (Gard, Bouches-du-Rhône, Moselle, Bas-Rhin and Vosges); no source names an actor for the Somme or Essonne claims, or ties Cybernox or AplaGroup to this wave. This is not merely a criminal claim: contacted directly on 30 August, the president of SDIS du Gard's governing board confirmed the cyberattack and theft of personal data on personnel, with copies of identity documents and bank details said to be among it, and the full scope and intrusion method still under investigation (Objectif Gard, 2026-08-30).

No common intrusion vector has been established across the incidents in this campaign. The one case with a stated mechanism is from the July wave: SDIS de l'Aisne, where a claimed administrator-level access credential was posted in cleartext by the actor; ZATAZ notes its current validity cannot be established from the post alone, since access can be disabled or changed after disclosure, but the posting itself is a more critical indicator than a plain directory extraction (ZATAZ.COM, 2026-07-26). The July wave's cumulative claims, spanning the Landes, Marne (2,167 people), Alpes-Maritimes (2,325 people), Alpes-de-Haute-Provence and Aisne SDIS, plus separate claims against SDIS d'Indre-et-Loire (2,637 public-service agents plus 54 individuals linked to private structures) and the Pompiers.fr / Fédération nationale des sapeurs-pompiers de France membership platform (ZATAZ.COM, 2026-07-26), totalled at least 166,376 exposed individuals, with a potential total exceeding 932,376 depending on the volumes claimed; ZATAZ is explicit that this estimate is a straight sum of announced record counts and does not mean each line was technically verified or maps to a distinct person (ZATAZ.COM, 2026-08-30). Each publication in the campaign otherwise appears to be a distinct claim rather than evidence of one coordinated technical compromise.

SDIS du Gard was indeed the victim of a cyberattack and data theft. Contacted this Sunday 30 August by Objectif Gard, Alexandre Pissas, chairman of SDIS 30's board, confirms the computer attack and the theft of personal data concerning personnel.

Among the stolen information are said to be particularly sensitive data, notably copies of identity documents and bank details.

Objectif Gard 2026-08-30

this data can help map personnel, roles, technical structures, hierarchical relationships and digital infrastructure of the French rescue services

ZATAZ.COM

SDIS 66 confirms it was the victim of a data theft. (translated from French)

the forms are now written by hand and transmissions are made by radio (translated from French)

ICI / Radio France 2026-10-01
Updaterun 2026-10-02T0404Z-inteltitleheadlinesummaryentitiessourcesevidencesourcing_notebody

SDIS 66, the fire and rescue service of the Pyrénées-Orientales, confirmed to Radio France on 2026-10-01 that data was stolen from one of its servers, which is maintained by a technical provider (ICI / Radio France, 2026-10-01). The data includes the rescue forms crews fill in at a patient's home or an accident scene, which can hold medical data, intervention reports, contact details and copies of identity documents or Vitale health-insurance cards, and SDIS 66 says the nature and extent are still being identified (ICI / Radio France, 2026-10-01). A crisis cell was opened and the system that transmits the documents was blocked to stop further leakage, so the forms are now written by hand and transmitted by radio to keep rescue operations running (ICI / Radio France, 2026-10-01). On 2026-09-30 a forum user claimed nearly 120,000 records and 100,000 documents, figures ICI says cannot be verified, and ICI notes the incident comes a month after the SDIS du Gard attack (ICI / Radio France, 2026-10-01). The reporting names no intrusion vector and no actor, and no source links the SDIS 66 theft to the SDIS du Gard attack or to the forum claims against other units.

threat31 Aug 05:00Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • zataz.com2 (50%)
  • ici.fr1 (25%)
  • objectifsud.fr1 (25%)