Back

Nachrichten.fr · July 21, 2026

Rassemblement National reports a cyberattack and announces it will file a police complaint

Paris – 21 July 2026: Rassemblement National (RN) says it has been the victim of a cyberattack and intends to file a police report. The party initially did not disclose which IT systems were affected, when the access was discovered, or whether the incident impacted the operation of its digital infrastructure. There is also currently no public information about possible perpetrators.

A source within the party stated that, according to current information, no personal data was stolen. This assessment is explicitly described as preliminary. It does not answer whether the incident was limited to unauthorized access to internal systems, whether data was altered or copied, or whether the technical investigation is still ongoing. RN provided no information about either the scale of the incident or the security measures taken.

The announced police report is a legal step through which the party seeks to involve investigative authorities. In the event of attacks on automated data processing systems, the investigation may concern, among other things, unauthorized access, possible disruption of services, as well as the theft or alteration of data. However, a legal classification of the specific case will only be possible after a technical and criminal-law assessment.

For political parties, incidents involving digital security are of particular importance. Their IT systems may contain data on party members, donors, events, and communications; moreover, they are part of political public activity and the organization of election campaigns. An attack can therefore have consequences even if, at an early stage, personal data is not believed to have been stolen: possible outcomes include operational disruptions, the loss of internal documents, or further attempts to misuse compromised credentials.

If it later emerges that the incident affected personal data and creates a risk to the rights and freedoms of affected individuals, the requirements of the General Data Protection Regulation apply. Responsible organizations must document such an incident and, as a rule, report it to the French data protection authority CNIL. In the event of a high risk, affected individuals must also be informed.

CNIL notes that an initial notification should be submitted, where possible, within 72 hours of discovering a significant personal data breach. This deadline does not mean that all technical questions must be conclusively clarified by then. The authority allows additional information to be provided as soon as the investigation produces more reliable results. For RN, the forensic determination of the circumstances of the incident is the primary issue.

In the political context, this report comes at a time of increased attention to the digital resilience of public and private organizations in France. The current case does not yet allow conclusions to be drawn about a possible motive, a connection to political activity, or the extent of the damage caused. For now, the only confirmed facts are that RN reports an attack, announces that it will file a police report, and has not yet confirmed the theft of personal data.

Sources

  • Franceinfo
  • National Commission on Informatics and Liberty (CNIL)

Artikel mit Hilfe künstlicher Intelligenz erstellt (Transparenzhinweis im Sinne von Artikel 50 der Verordnung (EU) 2024/1689 – EU AI Act).