Back

Nachrichten.fr · July 21, 2026

National Rally reports cyberattack and announces criminal complaint

Paris – July 21, 2026: The National Rally (RN) announced that it had been the victim of a cyberattack and stated that it intends to file a criminal complaint. The party initially did not disclose details about which IT systems were affected, when the unauthorized access was discovered, or whether the operation of its digital infrastructure had been disrupted. There is currently no public information about the suspected attackers.

Party representatives explained that there is currently no indication that personal data was stolen. However, this assessment is explicitly provisional. It remains unclear whether the incident was limited to unauthorized access to internal systems, whether data was altered or copied, or whether the technical investigation is ongoing. RN has also not commented on the scale of the incident or the security measures implemented.

The announced criminal complaint is a legal measure by which the party seeks to involve investigative authorities. In attacks on automated data processing systems, unauthorized access, possible denial of service, and the theft or alteration of data may in particular be subject to investigation. However, a legal assessment of the specific case will only be possible after technical and criminal-law review.

For political parties, incidents involving digital security have particular significance. IT systems may contain data relating to party members, donors, events, and communications, and are also used for political outreach and the organization of election campaigns. Therefore, an attack can have consequences even if no theft of personal data is initially confirmed. These may include operational disruptions, the loss of internal documents, or later attempts to exploit compromised access credentials.

If it becomes apparent that personal data has been affected and that this creates a risk to the rights and freedoms of the individuals concerned, the requirements of the General Data Protection Regulation apply. The responsible organization must document such incidents and, as a rule, report them to the French data protection authority, CNIL. In cases of high risk, the affected individuals must also be notified.

CNIL states that an initial report of a significant personal data breach should be made, where possible, within 72 hours of becoming aware of it. This deadline does not mean that all technical questions must have been conclusively clarified by then. The authority permits additional information to be submitted as soon as the investigation produces more reliable findings. For RN, the forensic investigation of the incident is therefore of primary importance.

Politically, the announcement comes at a time of growing attention to the digital resilience of French public institutions and private organizations. At present, no conclusions can be drawn from the incident regarding possible motives, links to political activity, or the scale of the damage. What is certain at this stage is that RN has reported the attack, announced a criminal complaint, and stated that no theft of personal data has so far been confirmed.

Sources

  • Franceinfo
  • National Commission on Informatics and Liberty (CNIL)

Artikel mit Hilfe künstlicher Intelligenz erstellt (Transparenzhinweis im Sinne von Artikel 50 der Verordnung (EU) 2024/1689 – EU AI Act).