Paris – July 21, 2026: According to the National Rally (Rassemblement National, RN), the party has fallen victim to a cyberattack and will file a criminal complaint. The party initially did not disclose which IT systems were affected, when the access was discovered, or whether the operation of its digital infrastructure was disrupted. There is currently no public information about possible perpetrators either.
A party source said that, according to the current situation, no personal data has been stolen so far. This assessment is explicitly still preliminary. The statement did not clarify whether the unauthorized access was limited to internal systems, whether data was altered or copied, or whether the technical investigation is still ongoing. RN commented neither on the scale of the incident nor on which security measures have been taken.
The announcement of a criminal complaint is a legal step through which the party seeks to involve investigative authorities. In the case of attacks on automated data processing systems, the investigation may particularly concern unauthorized access, possible service disruption, and the theft or alteration of data. However, a classification of the specific case can only be made after the technical and criminal law review has been completed.
For political parties, digital security incidents are of particular importance. Their IT systems may contain data on members, donors, events, and communications; moreover, they are part of political public communication and campaign organization. Therefore, even if no personal data theft is initially identified, an attack may have consequences: for example, operational disruptions, the loss of internal documents, or later attempts to misuse compromised access credentials.
If it is subsequently confirmed that personal data was affected and this creates a risk to the rights and freedoms of the individuals concerned, the provisions of the General Data Protection Regulation apply. The responsible entity must document such incidents and, in principle, report them to the French data protection authority CNIL. If the risk is high, affected individuals must also be notified.
CNIL states that an initial report should be submitted, where possible, within 72 hours of discovering the relevant data protection breach. This deadline does not mean that all technical questions must be conclusively clarified by then. The authority allows information to be supplemented once the investigation has produced more reliable results. For RN, the key priority is therefore to conduct a forensic investigation and establish the facts.
Politically, the news comes at a time of heightened public attention in France to the digital resilience of public and private organizations. The current case does not yet allow conclusions about possible motives, whether it is connected to political activities, or the extent of the damage. What can currently be confirmed is only this: RN has reported an attack, announced that it will file a criminal complaint, and stated that no theft of personal data has been confirmed so far.
Sources
- Franceinfo
- National Commission on Informatics and Liberty (CNIL)
Artikel mit Hilfe künstlicher Intelligenz erstellt (Transparenzhinweis im Sinne von Artikel 50 der Verordnung (EU) 2024/1689 – EU AI Act).