France’s Rassemblement National (RN) says it has become the target of a cyberattack. On July 21, 2026, the party confirmed that it had fallen victim to a hacking attack and announced that it would file a criminal complaint. However, the extent of the incident remains largely unclear. While technical investigations are underway, experts are urging caution regarding unverified information already circulating in relevant cybercriminal forums.
Many Questions Still Open
The party leadership has so far remained tight-lipped about details. The RN has provided neither information about the exact nature of the attack nor comments on possible perpetrators or their motives. It also remains unclear whether internal IT systems were fully compromised or whether only individual areas were affected.
According to a party-internal source cited by French media, there are currently no indications that personal data was stolen. However, this assessment explicitly applies only on the basis of the investigation’s current status. Specialists are continuing to analyze the affected systems to determine whether data was accessed or extracted from the party’s networks.
Unconfirmed Claims on the Darknet
At the same time as the official confirmation of the cyberattack, initial claims of responsibility for the attack appeared in relevant forums used by cybercriminals. Among other things, it was claimed that internal RN documents, as well as information on candidates and party officials, had been obtained.
However, there has so far been no official confirmation whatsoever of these claims. Neither the party nor the relevant authorities have confirmed such a data breach. In the cybersecurity industry, it is considered common for attackers to exaggerate their actual successes or even fabricate them entirely in order to pressure their victims or enhance their own reputation within the hacking scene.
Criminal Complaint Intended to Enable Investigation
With the announced criminal complaint, the French judiciary is likely to open a formal investigation. Several key questions will be at the center of the inquiry.
Investigators will first seek to determine how the attackers were able to penetrate the systems. They will also clarify who was behind the attack and whether it involved ordinary cybercriminals, politically motivated hackers, or state-supported actors. In addition, they will examine whether data was merely accessed or actually copied and removed from the systems.
Ultimately, the results of these investigations will also determine what consequences the incident will have for the party and potentially for affected individuals.
Political Parties Remain Attractive Targets
The incident is part of a trend that security authorities have been observing for years. Political parties have now become preferred targets of cyberattacks worldwide. They hold sensitive membership data, internal strategy papers, campaign materials, and communications data that may be of great interest to criminal groups, political opponents, or foreign intelligence services.
The risk of such attacks rises significantly, especially during election campaigns. Beyond the theft of sensitive information, attackers often seek to undermine public trust in political institutions or influence political debate through targeted disclosures.
In addition, modern cyberattacks are no longer aimed exclusively at data theft. Increasingly, attackers rely on so-called extortion strategies: merely claiming to possess confidential documents can generate considerable political and media pressure, regardless of whether the data in question actually exists.
The current case once again shows how vulnerable even major political organizations remain to professional cyberattacks. Whether sensitive information at Rassemblement National was actually compromised or whether the incident will prove relatively harmless will only be determined by the ongoing technical investigations and criminal inquiries. Until then, caution is warranted when assessing alleged data leaks. Unconfirmed claims from hacker forums should not be mistaken for established findings. Only the results of the investigating authorities will reveal the true scale of this cyberattack.