forumNew topic

We fell victim to a cybercrime: file a complaint or notify first, and who do we contact in France?

İİlker K***Expert
Job title
Software developer
Sector
Freight
Organization type
300-person organization
Joined
Nov 2022
Message
42
#1

We're a wholesale and e-commerce business with 22 employees in the Paris suburbs. Yesterday morning, we found out our accounting and warehouse management server had been hit with ransomware. The attackers encrypted the local database and left a text file on the desktop demanding crypto assets. Luckily, we have weekly offline backups, but right now we aren't sure if our customer lists and employee data were exfiltrated.

We're completely lost regarding the legal obligations and official steps in France. Should our first move be going to the police, writing to the public prosecutor, or reporting to the data protection authority first? Still in shock from the attack, we're terrified of making a wrong move that destroys evidence or lands us legal penalties.

In a forensic incident like this, how should systems be isolated without tampering with evidence, in what order should the complaint and notification process be handled in France, and what needs to happen in the first 48 hours regarding cyber insurance and business continuity?

HHilal Ö***Member
Job title
Social media manager
Sector
Tourism
Organization type
boutique agency
Joined
Apr 2024
Message
215
Most Helpful#2

Short answer: Your first step is to isolate the system by unplugging network cables without shutting down or pulling the power on compromised machines, then file a preliminary breach notification with the CNIL within 72 hours max. Simultaneously, lodge a formal criminal complaint with the local police or gendarmerie and immediately inform your cyber insurance provider if you have one.

Evidence preservation is critical in the first 24 hours. Under no circumstances should you restart or shut down the servers; traces left by the attacker and encryption keys might reside in volatile system memory (RAM). Only disconnect ethernet cables turn off Wi-Fi, and take a read-only copy of existing logs onto an external drive. Do not negotiate with the attackers, and do not pay the ransom.

The legal notification process should run in this order: 1) If there's a risk personal data was leaked, submit a formal breach notification via the CNIL portal within 72 hours under RGPD rules; even if you don't have all the details upfront you can file an initial notice and state that supplemental info will follow. 2) File a formal complaint (plainte) at the nearest 'Commissariat de Police' or 'Gendarmerie', or via registered letter directly to the Public Prosecutor (Procureur de la République). 3) Call your cyber insurance within the first 24-48 hours; in France, insurers usually dispatch their own digital forensics teams, and prompt notification is mandatory for policy coverage.

MMerve T***ExpertCommunity member
Joined
Feb 2024
Message
13
#3

Right now, literally just pull the ethernet cables and shut off wifi on the machines. Never turn the system off. Then check the initial response steps tailored to your business size on the official French cyber support platform Cybermalveillance and open a ticket; they will also point you to accredited tech specialists in your area.

OOsman T***Member
Job title
Technical service technician
Sector
Furniture manufacturing
Organization type
a company within a holding
Joined
Jan 2022
Message
3
#4

Bring your technical staff along when filing the complaint with the prosecutor. Police officers often struggle to interpret technical logs. Put the logs, the ransom note, and a list of impacted systems on a USB stick and make sure it's formally entered into the police report as forensic evidence. Without that official report, you won't see a single cent from insurance.

HHasan G***Member
Job title
QA Tester
Sector
Printing
Organization type
cooperative
Joined
Mar 2022
Message
8
#5

We dealt with a similar incident last year and barely made the CNIL notification at the 68th hour. Even though the suspected breach wasn't confirmed, no penalty was issued because we reported on time. On the other hand, an acquaintance who informed their insurer after 72 hours got their 30,000 Euro recovery costs denied because they blew past the policy deadline. Timing is everything.

MMeryem A***Expert
Job title
Store Manager
Sector
Media and publishing
Organization type
boutique agency
Joined
Dec 2025
Message
99

Doki · Brand identity · 2026

#6

Your first 48 hours checklist should look like this: 1) Physically disconnect network cables and isolate systems. 2) Call your cyber insurance agency's emergency hotline. 3) Fill out the data breach notification form on the CNIL website. 4) Go to the police station and file an official complaint (plainte) to get the report. 5) Try restoring your clean backups in an isolated test environment.

ZZerrin G***MemberCommunity member
Joined
Jul 2023
Message
260
#7

Filing a police report is a legal requirement and a must for insurance, but don't expect them to recover your systems. The police collect evidence and track down the culprits. What will actually save your business is whether your offline backups really work; test immediately on an external network to see if those backups are corrupted.

DDoruk D***Member
Job title
IT manager
Sector
Freight
Organization type
a company within a holding
Joined
Jun 2022
Message
11

Doki · Incident response support · 2026

#8

Keeping an internal crisis log regarding the potential compromise of personal data will work in your favor legally. The moment the incident was discovered, the technical measures taken, and the official filings made should all be recorded hour by hour. These records serve as primary evidence of due diligence before CNIL auditors.

UUğur Y***VeteranCommunity member
Joined
Oct 2024
Message
3
#9

definitely do not pay the ransom there are already regulations in france preventing insurance from covering ransom payments anyway. even if u pay there's no guarantee they'll give u the key, focus on restoring from backup.

AAhmet M***MemberCommunity member
Joined
Jan 2024
Message
27
#10

So sorry to hear this, I understand you're in a huge panic right now, but try to stay calm. Having weekly offline backups is your biggest saving grace. Once you go through the legal steps by the book, you should be able to resume operations in a controlled manner within a few days.

NNazlı A***Member
Job title
Clinic manager
Sector
Machinery manufacturing
Organization type
medium-sized business
Joined
Dec 2023
Message
353
#11

I'm curious too.

SSerkan Ş***Member
Job title
Data entry clerk
Sector
Healthcare services
Organization type
family business
Joined
Dec 2025
Message
3
#12

there are three things to check when doing this. mistakes made on the what to do cybercrie side are usually reversible but expensive.

if you post the result here, it will help others too.

İİlker G***Member
Job title
Production planning
Sector
Jewelry
Organization type
family business
Joined
Jul 2023
Message
13
#13

I think it's hard to be that definitive about what to do cybercrime. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

Correct me if I'm wrong.

AAhmet G***MemberCommunity member
Joined
Apr 2022
Message
30
#14

yes, thaats exactly how it is with what to do cybercrime but most time waste accumulates in tasks waiting for approval.

just leaving this note, it might be useful.

ÖÖzge C***Expert
Job title
Purchasing manager
Sector
Cosmetics
Organization type
300-person organization
Joined
Mar 2023
Message
141
#15

There's a trap here, let me mention it... Payment information changes are never verified through the channel they came from.

If you have questions, write them; I'll answer as best I can.

VVeli Z***MemberCommunity member
Joined
Dec 2023
Message
253
#16

There are three things to check when doing this. btw if 2FA is on, a stolen password alone is useless.

BBurak A***Member
Job title
IT manager
Sector
E-commerce
Organization type
early-stage startup
Joined
May 2023
Message
126
#17

let me summarize the topic, since several different answers were given. like the real issue isn't the number but what it's based on.

trying to do this alone is the most expensve way... honestly if you have questions write them; I'll answer as best I can.

SSenaMember
Job title
Graphic Designer
Organization type
two-branch business
Joined
Jul 2024
Message
86
#18

let me summarize the topic, since several different answers were given and if permission and scope aren't in writing, don't start that test.

taking measures without an inventory leaves doors you havent seen open. i mean if you post the result here it will help others too.

HHavva M***Expert
Job title
Front office accounting
Sector
Media and publishing
Organization type
chain store
Joined
Sep 2022
Message
197
#19

I'll try it. When making decisions, write down the worst-case scenario too, not just the best.

TTülay K***ExpertCommunity member
Joined
May 2023
Message
182
#20

Saved. The real issue isn't the number, but what it's based on.

If 2FA is on, a stolen password alone is useless.

Reply