Back

Nachrichten.fr · July 31, 2026

Rassemblement National denounces cyberattack and announces criminal complaint

Paris – 21 July 2026: The Rassemblement National (RN) claims to have been the victim of a cyberattack and intends to file a criminal complaint. The party initially did not publish information on which IT systems were affected, when the access was detected, or whether the operation of its digital infrastructure has been impaired. There is also no public information so far about possible perpetrators.

An internal party source stated that, according to the current status, no personal data has been stolen. This assessment is explicitly provisional. It leaves open the question of whether there was only unauthorized access to internal systems, whether data was modified or copied, or whether the technical investigation is ongoing. The RN did not comment on either the scope of the incident or the security measures taken.

The announced criminal complaint is the legal step through which the party intends to involve investigating authorities. In attacks against automated data processing systems, investigations may concern, in particular, unauthorized access, a possible disruption of services, and the theft or alteration of data. However, the legal classification of the specific case will only be possible after a technical and criminal-law assessment.

For political parties, digital security incidents are of particular importance. Their IT systems may contain data on members, donors, events, and communications; in addition, they are part of public political communication and the organization of election campaigns. Therefore, an attack can have consequences even if no personal data is initially believed to have been stolen: operational disruptions, the loss of internal documents, or subsequent attempts to misuse compromised access are possible, for example.

If, in the course of further investigation, it is found that personal data has been affected and that this creates a risk to the rights and freedoms of the persons concerned, the provisions of the General Data Protection Regulation will apply. Responsible entities must document such an incident and, as a rule, notify the French data protection authority, the CNIL. In cases of high risk, the persons concerned must also be informed.

The CNIL notes that an initial notification must be made, where possible, within 72 hours of becoming aware of a relevant personal data breach. This deadline does not mean that all technical issues must have been conclusively resolved by then. The authority allows supplementary information to be provided when the investigation yields more reliable findings. For the RN, it is therefore crucial to clarify the incident forensically.

Politically, the news comes at a time of increased attention to the digital resilience of public and private organizations in France. The current case does not yet allow conclusions to be drawn about a possible motive, a connection to political activities, or the extent of the damage. For now, it is only confirmed that the RN reports an attack, announces a criminal complaint, and currently does not confirm the theft of personal data.

Sources

  • Franceinfo
  • National Commission on Informatics and Liberty (CNIL)

Dieser Artikel wurde mit Hilfe künstlicher Intelligenz erstellt.