DDoS incident disrupts France’s postal and banking services ahead of Christmas

France’s national postal service, La Poste, confirmed that a suspected cyberattack disrupted its websites and mobile applications days before Christmas, slowing deliveries and knocking some online services offline.

In a statement on Monday, La Poste said that a distributed denial-of-service (DDoS) incident knocked key digital systems offline. The company said there was no evidence that customer data had been compromised, but acknowledged that postal operations, including parcel distribution, had been affected.

The disruption extended to La Banque Postale, the banking service, which warned customers that access to online banking and its mobile app was affected. Card payments at in-store terminals and cash withdrawals from ATMs continued to function, and online payments remained possible if authenticated by text message, the bank said.

La Poste said some post offices were operating at reduced capacity, though customers were still able to carry out banking and postal transactions at counters. “Our teams are fully mobilised to restore services as quickly as possible,” the company said in a statement.

The disruption came at a busy time for the postal service. Customers complained on social media that delays could prevent them from receiving packages in time for Christmas, while French media reported that some people attempting to send or collect parcels were turned away from post offices.

The incident follows a separate data breach disclosed last week at France’s Interior Ministry, where attackers gained unauthorized access to email accounts and confidential documents. French authorities later arrested a 22-year-old suspect in connection with that incident.

It is not immediately clear who was responsible for the attack on La Poste, and the company did not attribute it to any specific group.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

 

Total
0
Shares
Previous Post

Cyber spies use fake New Year concert invites to target Russian military

Next Post

FCC Bans Foreign-Made Drones and Key Parts Over U.S. National Security Risks

Related Posts

Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP Update

Microsoft has announced plans to improve the security of Entra ID authentication by blocking unauthorized script injection attacks starting a year from now. The update to its Content Security Policy (CSP) aims to enhance the Entra ID sign-in experience at "login.microsoftonline[.]com" by only letting scripts from trusted Microsoft domains run. "This update strengthens security and adds an extra
Read More

Ukraine Warns of CABINETRAT Backdoor + XLL Add-ins Spread via Signal ZIPs

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of new targeted cyber attacks in the country using a backdoor called CABINETRAT. The activity, observed in September 2025, has been attributed to a threat cluster it tracks as UAC-0245. The agency said it spotted the attack following the discovery of software tools taking the form of XLL files, which refer to Microsoft Excel
Read More

GitHub Mandates 2FA and Short-Lived Tokens to Strengthen npm Supply Chain Security

GitHub on Monday announced that it will be changing its authentication and publishing options "in the near future" in response to a recent wave of supply chain attacks targeting the npm ecosystem, including the Shai-Hulud attack. This includes steps to address threats posed by token abuse and self-replicating malware by allowing local publishing with required two-factor authentication (2FA),
Read More