On 9 March 2023, around 9 p.m., the phone rang at the Brest University Hospital (CHU de Brest): ANSSI, France’s national cybersecurity agency, had spotted suspicious communications between one of the hospital’s servers and an attacker’s infrastructure. In most of the cases in this series, that kind of call comes too late — after the exfiltration, after the encryption, after the ransom. Not this time. “The attackers did not exfiltrate data and did not manage to deploy their final payload,” CERT-FR would write six months later (our translation).
The third installment of our “Attack autopsies” series after France Travail and the ANTS, this case file has one distinguishing feature: it is the story of a thwarted attack. And it rests on a source that is one of a kind — report CERTFR-2023-CTI-007 of 18 September 2023, the public technical account in which CERT-FR, exceptionally, names the French victim and details the attack step by step: initial access, tooling, the attacker’s failures, attribution to the FIN12 intrusion set. To it we add the hospital CISO’s testimony in the specialist press, ANSSI’s Cyber Threat Overview 2023 and the Cour des comptes’ report on the IT security of healthcare establishments.
One framing point, and an essential one: this attack does not begin with a phishing email. It begins with stolen credentials — probably harvested by an infostealer, a password-stealing malware. The two vectors are cousins, not twins; we will come back to this, because it is precisely the lesson of the case.
Key takeaways
- The alert: “On Thursday 9 March 2023, ANSSI issued an alert concerning the compromise of one of the servers of the Brest university hospital (CHU). This alert was made possible by investigations conducted by ANSSI over several years” (CERT-FR, 18 September 2023, our translation).
- The vector: “the valid credentials of a healthcare professional”, used on “a remote desktop service exposed and accessible on the internet”. CERT-FR deems it “likely” that these credentials came “from the compromise of the user’s workstation by an information stealer, as part of an opportunistic distribution campaign”. This is not a phishing email: it is credential theft by malware — a sibling vector, not the same one.
- The response: alert received “about 10 minutes before 9 p.m.”, decision to cut off the internet taken in “2h30”, investigations until 3 a.m. with ANSSI (the CISO’s account, LeMagIT, 27 March 2023). “The responsiveness of the healthcare establishment made it possible to quickly isolate the information system from the internet and to hinder the progression of the attackers’ intrusion set” (CERT-FR, our translation).
- The outcome: zero data exfiltrated, zero machines encrypted, near-normal care activity — at the cost of two weeks of degraded operation, without internet access.
- The attribution: ANSSI associates the attack with the cybercriminal intrusion set FIN12 — an analysts’ designation, not identified individuals — linked “to the encryption of some thirty entities between 2020 and 2023”, with marked targeting of the healthcare sector (at least 20% of victims according to Mandiant, cited by ANSSI). No one has been arrested.
- The lesson: the credentials of a single professional, probably harvested from a workstation by malware, were enough to open up a university hospital. At sector level, the Cour des comptes recalls that the malicious email was “the leading source of incidents reported to Cert Santé in 2022” — the human factor remains the way in, whatever the tool that exploits it.
The case in numbers
9 March 2023
ANSSI's alert to the Brest University Hospital
CERT-FR, CERTFR-2023-CTI-007, 18/09/2023
2h30
between the alert and the decision to cut off the internet
Hospital CISO, LeMagIT interview, 27/03/2023
~30
encrypted entities linked to the same intrusion set (2020-2023)
CERT-FR, CERTFR-2023-CTI-007
0
data exfiltrated, zero servers encrypted: the attack thwarted
CERT-FR, CERTFR-2023-CTI-007
Timeline
Timeline
How events unfolded
Around 20 February 2023
Early warning signs on a hospital employee's accounts
"The investigation points to the involvement, prior to the start of the cyberattack, of a stealer malware, an infostealer: the employee whose account was compromised had, separately, had social media accounts hijacked around 20 February" (our translation).
Source — LeMagIT, account with the hospital's CISO, 27/03/2023
9 March 2023
ANSSI reports the compromise
"On Thursday 9 March 2023, ANSSI issued an alert concerning the compromise of one of the servers of the Brest university hospital (CHU). This alert was made possible by investigations conducted by ANSSI over several years" (our translation).
Source — CERT-FR, CERTFR-2023-CTI-007, 18/09/2023
9 March 2023, in the evening
The alert reaches the hospital's teams
"About 10 minutes before 9 p.m., the IT teams of the Brest CHRU receive a notification: the hospital's information system may be the victim of an intrusion" (our translation). Qualification is swift: the flagged account "had indeed been used to fraudulently access the information system" (our translation).
Source — LeMagIT, account with the hospital's CISO, 27/03/2023
Night of 9-10 March 2023
The internet disconnection
"In all, it took us 2h30 to decide that, to be at ease, to be sure of stopping the attack at the right moment and not missing anything, we had to cut off the internet", recounts Jean-Sylvain Chavanne, the hospital's CISO (our translation). Investigations continue until 3 a.m. with ANSSI's support.
Source — LeMagIT, the CISO's words, 27/03/2023
10 March 2023
The relief: no privilege escalation
An incident-response provider is at work by 8 a.m. "By midday, the good news lands: the attacker did not manage to escalate privileges" (our translation). Their capacity for harm remained "well below what they would have needed to succeed in widely deploying ransomware" (our translation).
Source — LeMagIT, account with the hospital's CISO, 27/03/2023
24 March 2023
Reconnection begins
At a press briefing, the hospital's management explains that reconnection to the internet has begun, "after two weeks of operating in degraded mode" (our translation). The electronic patient record "was still available": consultations, the emergency department and the maternity ward were maintained.
Source — LeMagIT, 27/03/2023
21 June 2023
The counter-example: Rennes University Hospital
"On 21 June 2023, the Rennes university hospital (CHU) detected malicious actions on its information system and informed ANSSI" (our translation). The investigations revealed "an in-depth compromise of the IS as well as a data exfiltration carried out by the cybercriminal group BianLian" — but there too, no encryption: "the attack having been detected in its initial phase" (our translation).
Source — ANSSI, Cyber Threat Overview 2023 (CERTFR-2024-CTI-001), 27/02/2024
18 September 2023
CERT-FR publishes its official autopsy
ANSSI publishes report CERTFR-2023-CTI-007, "FIN12: a cybercriminal group with multiple ransomwares": initial access, tooling, failed exploitation attempts, infrastructure, attribution. Exceptionally rare for a French incident: the victim is named.
Source — CERT-FR, CERTFR-2023-CTI-007, 18/09/2023
7 November 2024
The threat landscape for the healthcare sector
CERT-FR publishes its healthcare-sector threat assessment: "A third of the incidents affecting healthcare establishments observed by ANSSI in 2022 and 2023 concern compromises of email accounts, sometimes coupled with the sending of phishing emails" (our translation). The sector's share of incidents handled by the agency rose "from 2.87% in 2020 to 11.4% in 2023".
Source — CERT-FR, CERTFR-2024-CTI-010, 07/11/2024
14 October 2024
The Cour des comptes points to the human factor
In its final observations on the IT security of healthcare establishments (S2024-1456, deliberated on 14 October 2024, published online in January 2025), France's supreme audit institution writes that "the leading source of incidents reported to Cert Santé in 2022, and the second in 2023, is the malicious email […] also known as phishing", and that "the vulnerability of hospital information systems therefore essentially originates in user behavior" (our translation).
Source — Cour des comptes, S2024-1456
Act 1: the stolen key — an infostealer, not phishing
It all starts with a sentence CERT-FR places at the head of its analysis: “Initial access to the information system was performed from a remote desktop service exposed and accessible on the internet. The operators of the intrusion set used the valid credentials of a healthcare professional to log in” (our translation).
Read it slowly, because everything is there. No exotic flaw, no zero-day: a remote desktop service exposed on the internet — the door — and valid credentials — the key. The attacker forces nothing at the entrance; he logs in, just as the healthcare professional whose digital identity he stole would have done.
Where did the key come from? CERT-FR answers with an analyst’s caution: “It is likely that the account’s credentials came from the compromise of the user’s workstation by an information stealer, as part of an opportunistic distribution campaign” (our translation). And the report defines the tool in a footnote: “an information stealer is a type of malicious code used to collect identification information on a compromised machine”.
The account published by LeMagIT on 27 March 2023, based on the words of the hospital’s CISO, Jean-Sylvain Chavanne, adds a troubling clue: “the employee whose account was compromised had, separately, had social media accounts hijacked around 20 February” (our translation). In other words, nearly three weeks before the attack, this employee’s personal digital life was already showing signs of compromise — the typical signature of a machine infected by a credential stealer, whose loot (professional and personal passwords mixed together) ends up for sale on criminal marketplaces.
CERT-FR draws a structural hypothesis from this: “Two actors could therefore be involved in the incident, an initial access broker and the attacker in charge of lateral movement and ransomware deployment” (our translation). This is the economics of modern ransomware: the one who steals the key is not the one who burgles. ANSSI confirmed it at scale in its 2023 overview: “the democratization of information-stealing tools (infostealers)” has “made it easier for cybercriminals with limited technical skills to acquire initial access”.
One framing point, once and for all: nothing in the public sources says this employee clicked on a phishing email. An infostealer typically arrives via a booby-trapped download, cracked software, or malicious advertising — an “opportunistic distribution campaign”, says CERT-FR, that is, trawler fishing that targeted neither this employee nor this hospital. Conflating credential theft by malware with phishing would be factually wrong. They are, however, two branches of the same tree: attacks that go through humans and their credentials rather than through pure technique. One infects the machine to siphon off passwords; the other builds a fake page to have them typed in. The defense, meanwhile, is largely shared — we come to it below.
Act 2: the night the hospital won
ANSSI’s alert
CERT-FR’s summary dates the turning point precisely: “On Thursday 9 March 2023, ANSSI issued an alert concerning the compromise of one of the servers of the Brest university hospital (CHU). This alert was made possible by investigations conducted by ANSSI over several years” (our translation).
That last sentence deserves a pause: the hospital did not detect the intrusion on its own, and it did not have to. It was the national agency’s long-term tracking of an attacker’s infrastructure — command-and-control servers, technical habits, accumulated indicators — that made it possible to spot, from the outside, communications between the hospital’s information system and the attacker. Threat knowledge, capitalized over years, turned into an operational alert on a Thursday evening.
2h30 to decide
On the hospital’s side, the account published by LeMagIT reconstructs the evening: “About 10 minutes before 9 p.m., the IT teams of the Brest CHRU receive a notification: the hospital’s information system may be the victim of an intrusion” (our translation). The notification is sparse — the credentials of a compromised account — but it is enough: the firewall logs confirm fraudulent connections, the EDR has recorded reconnaissance actions. Doubt is dispelled: someone is inside the walls, and he is exploring.
Then comes the decision that tips the case, as told by the CISO: “In all, it took us 2h30 to decide that, to be at ease, to be sure of stopping the attack at the right moment and not missing anything, we had to cut off the internet” (our translation). Cutting a university hospital off from the internet is no trivial act — the CISO cites losing the geolocation of ambulances for emergency dispatch among the side effects. Yet it is this deliberate containment that smothers the attack: the assailant loses his command channel, while the investigations continue “until 3 a.m.”, with ANSSI’s support.
The next day, an incident-response provider takes over from 8 a.m. By midday, the verdict: “the attacker did not manage to escalate privileges” (our translation). Without extended privileges, no massive ransomware deployment is possible. The game is over.
Two weeks in an airlock, not two months in ruins
The price paid is real but contained: “two weeks of operating in degraded mode”, without internet, before the start of the reconnection announced at a press briefing on 24 March. But the essentials held, and the CISO sums it up in one sentence: “the electronic patient record was still available. That is why we were able to keep the consultations, the emergency department, the maternity ward, in particular” (our translation). No white plan, no mass cancellation of procedures, no return to paper — everything that France’s encrypted hospitals from Rouen to Corbeil-Essonnes endured, Brest avoided.
The attack chain: what CERT-FR documents
Attack chain
How the intrusion unfolded
Defensive reconstruction — every link you understand is a link you can break.
Credentials stolen upstream, by an infostealer
According to CERT-FR, it is "likely that the account's credentials came from the compromise of the user's workstation by an information stealer, as part of an opportunistic distribution campaign" (our translation) — malware that harvests the credentials stored on an infected machine. The press reports that the employee concerned had had social media accounts hijacked around 20 February (LeMagIT, 27/03/2023).
Login with valid credentials on an exposed remote-access service
"Initial access to the information system was performed from a remote desktop service exposed and accessible on the internet. The operators of the intrusion set used the valid credentials of a healthcare professional to log in" (CERT-FR, 18/09/2023, our translation). No exploit, no break-in: a stolen key in a legitimate lock.
Reconnaissance of the directory and the network
The attackers map the environment with public tools: Softperfect Network Scanner for network discovery, PingCastle and BloodHound "to identify misconfigurations of the Active Directory" (CERT-FR, 18/09/2023, our translation).
Escalation and lateral movement attempted — and failed
Attempted exploitation of LocalPotato (CVE-2023-21746) and CVE-2022-24521 to escalate privileges; then, "without success", of PrintNightmare, BlueKeep and ZeroLogon to move laterally; Mimikatz, SharpRoast and AccountRestore against authentication data (CERT-FR, 18/09/2023). None of these attempts succeeded.
Command-and-control tooling
Two backdoors are executed from the remote desktop access: Cobalt Strike and SystemBC, deployed 20 minutes apart from the same directory — the standard toolkit of modern ransomware operations (CERT-FR, 18/09/2023).
Detection and containment before encryption
ANSSI's alert on 9 March, internet cut-off decided in 2h30: "the attackers did not exfiltrate data and did not manage to deploy their final payload" (CERT-FR, our translation). "The responsiveness of the healthcare establishment made it possible to quickly isolate the information system from the internet and to hinder the progression of the attackers' intrusion set."
What is striking in the CERT-FR report is the number of verbs ending in failure. The operators “attempted, without success” to create a “supp” account to persist. They “attempted to exploit” LocalPotato (CVE-2023-21746) and CVE-2022-24521 to escalate their privileges. They “attempted, without success, to exploit the PrintNightmare (CVE-2021-34527), BlueKeep (CVE-2019-0708), then ZeroLogon (CVE-2020-1472) vulnerabilities” to move laterally (our translation). They deployed the classic toolkit — Cobalt Strike and SystemBC as backdoors, Mimikatz, SharpRoast and AccountRestore against authentication data, BloodHound and PingCastle to map the Active Directory — without ever reaching their goal. A revealing detail noted by ANSSI: in the comparative table of incidents attributed to the same intrusion set, the “2023-03 CHU de Brest” row is the only one where the encryptor column stays empty.
A ransomware attack is not a lightning strike, it is a progression: access, reconnaissance, escalation, lateral movement, then encryption. Each stage takes time — Mandiant, cited by ANSSI, puts FIN12’s “Time-To-Ransom” at about 4 days. It is in that window that everything played out: the 9 March alert arrived during the reconnaissance phase, and the internet cut-off closed the window before the irreparable.
FIN12: who the hospital escaped
The CERT-FR report does not merely describe the incident: it attributes it. “The discovery of links with a set of incidents observed within the French perimeter and reported in open sources allowed ANSSI to associate this attack with the cybercriminal intrusion set FIN12” (our translation). An important precision: FIN12 designates an attackers’ modus operandi (an intrusion set), a technical signature tracked by analysts — Mandiant calls it FIN12, Microsoft PISTACHE TEMPEST (DEV-0237) — and not identified persons. No one has been arrested for this attack, and no judicial proceedings against suspects have been made public.
The pedigree reconstructed by ANSSI gives the measure of what Brest escaped: “ANSSI’s analyses established links between the Brest CHU incident and the encryption of some thirty entities between 2020 and 2023” (our translation). The operators of this intrusion set “are believed to be responsible for a substantial number of ransomware attacks on French territory”, successively using “the Ryuk then Conti ransomwares, before taking part in the Ransomware-as-a-Service (RaaS) programs of the Hive, BlackCat and Nokoyawa ransomwares”, as well as Play and Royal.
Two traits of the profile make the Brest case particularly significant. First, the targeting: according to Mandiant, cited by ANSSI, the FIN12 intrusion set is characterized by “significant targeting of the healthcare sector (at least 20% of the group’s victims)” — up to and including the 2020 Ryuk campaign against American hospitals. Second, the method: its operators “seem to favor the rapid encryption of compromised networks over the exfiltration of the victim’s data”, with that Time-To-Ransom of about 4 days. Against an adversary whose specialty is speed, it was the defense’s speed that made the difference.
Three months later, the scenario nearly replayed 250 kilometers away: on 21 June 2023, “the Rennes university hospital (CHU) detected malicious actions on its information system and informed ANSSI”, writes the 2023 overview. The toll there was heavier — “an in-depth compromise of the IS as well as a data exfiltration carried out by the cybercriminal group BianLian” — but there again, no encryption: “the responsiveness of the teams nevertheless made it possible to avoid heavier consequences, the attack having been detected in its initial phase” (our translation). Brest then Rennes, three months apart, draw the same moral: you do not choose whether you are targeted, you choose whether you are ready to detect.
The sector: why hospitals, why credentials
The Brest case is not an anomaly, it is a sample. CERT-FR, in its healthcare-sector threat assessment (November 2024), measures the pressure: the sector’s share of the incidents and reports handled by the agency rose “from 2.87% in 2020 to 11.4% in 2023”. And it specifies the dominant mechanism: “A third of the incidents affecting healthcare establishments observed by ANSSI in 2022 and 2023 concern compromises of email accounts, sometimes coupled with the sending of phishing emails” (our translation). Accounts, always accounts.
The Cour des comptes, in its final observations on the IT security of healthcare establishments (S2024-1456, deliberated on 14 October 2024), drives the point home on the human factor: “the leading source of incidents reported to Cert Santé in 2022, and the second in 2023, is the malicious email, an attack launched at random on the internet, with no defined target, also known as phishing” (our translation). And it draws the uncomfortable conclusion: “The vulnerability of hospital information systems therefore essentially originates in user behavior, whatever the functions performed and the level of responsibility” (our translation).
The same report documents the other side: underinvestment. Healthcare establishments devote to IT “1.7% of their operating budget on average, against 9% in banking and 2% in the consumer goods industry”, with more than 20% of equipment obsolete. A hospital information system means thousands of users — nearly 8,000 at the Brest hospital, for 350 servers, according to LeMagIT’s account —, hundreds of applications, biomedical equipment that cannot be updated. In that environment, a single professional’s credentials are often the shortest path to everything else. That is why health data remains attackers’ number one target — and why credential theft, by malware or by phishing, has become the upstream economy of every ransomware attack.
What an SMB (or a hospital) should take away
1. Your credentials are your perimeter
The Brest attack exploited no vulnerability to get in: it used a genuine login and password on an exposed remote-access service. CERT-FR notes, moreover, that at the scale of the FIN12 intrusion set, “the preferred infection vector seems to be the use of valid credentials” (our translation). The direct consequence: any remote access exposed on the internet without multi-factor authentication is a door waiting for its stolen key. Inventory those services, remove the ones you can, and enforce MFA on the rest — our guide to deploying MFA in a company (in French) walks through it, prioritizing precisely those accesses.
2. Your employees’ personal machines concern you
The clue of the social media account hijackings three weeks before the attack tells an uncomfortable truth: the border between personal digital life and professional credentials no longer exists for an infostealer. A work password saved in the browser of an infected personal machine ends up in the same resold “logs” as the Netflix accounts. Minimum rules: a company password manager, a ban on reusing work passwords elsewhere, and awareness training that explicitly covers booby-trapped downloads — not just suspicious emails.
3. Infostealers and phishing: two faces of the same risk, one defense
This case is not a phishing story, and we will not twist it into one. But the defense against the two vectors is largely shared: MFA (which devalues the stolen credential, whatever its origin), password hygiene, a reporting culture, and training teams to recognize the traps. The human factor is involved in 62% of data breaches (Verizon DBIR 2026 — see our phishing statistics for France), and in the healthcare sector, the malicious email was the leading source of Cert Santé incidents in 2022 according to the Cour des comptes. Training your teams against phishing means strengthening exactly the link the infostealer attacks by another route.
4. Early detection changes the end of the story
Brest and Rennes both suffered intrusions; neither was encrypted, because the attack was “detected in its initial phase”. The ingredients are reproducible at any scale: logs you can query fast (the hospital qualified the alert the same evening thanks to its firewall logs and EDR), a channel for receiving external alerts — ANSSI, CERT Santé, researchers —, and above all a containment decision prepared in advance. Cutting off the internet in 2h30, on a Thursday evening, while weighing the impact on emergency dispatch: that is not improvised, it is rehearsed. Your response plan must name who has the right to pull the plug, on what criteria, and what must keep working unplugged.
5. Transparency is a defense multiplier
This case file exists only because two actors chose to tell the story: CERT-FR, by publishing a technical report that names the victim — an exception in its output —, and the hospital, whose CISO detailed the crisis management in the press. The result: shared indicators of compromise, documented TTPs, and a textbook case the whole sector could learn from. A thwarted attack kept secret protects only its victim; a thwarted attack told protects everyone. Find this incident and over 100 others in our French cyberattack database.
Verdict
The Brest University Hospital case will stand as the French counter-example: the demonstration, sourced line by line in a public ANSSI report, that a ransomware attack run by a seasoned intrusion set — some thirty encrypted entities to its record, healthcare as its hunting ground — can be stopped between intrusion and encryption. It took the sum of two vigilances: that of a national agency which had been watching the adversary’s infrastructure for years, and that of a hospital able to qualify an alert on a Thursday evening and cut itself off from the internet in 2h30.
But the case also says something else: the way in was neither a flaw nor an exploit — the exploits, the attacker failed at every one of them once inside. It was the key of a healthcare professional, probably siphoned from a workstation by credential-stealing malware, resold and then used on an exposed remote access. Credential theft by infostealer, mass phishing flagged by the Cour des comptes, email compromises recorded by CERT-FR: the paths differ, the target is the same — humans and their accounts. Brest won the race against the clock. The best race is still the one you never have to run: the one where the key was never stolen.
FAQ
How did the attackers get into the Brest University Hospital? Through “a remote desktop service exposed and accessible on the internet”, with “the valid credentials of a healthcare professional”, probably stolen by an infostealer “as part of an opportunistic distribution campaign” (CERT-FR, CERTFR-2023-CTI-007, 18 September 2023, our translation). No exploit was used to get in.
What is an infostealer? “A type of malicious code used to collect identification information on a compromised machine” (CERT-FR, our translation). It siphons passwords and cookies, which are then resold on criminal forums to initial access brokers.
Why did the attack fail? ANSSI’s alert on 9 March 2023, the alert qualified the same evening, the internet cut off within 2h30: “the attackers did not exfiltrate data and did not manage to deploy their final payload”, and all their privilege-escalation and lateral-movement attempts failed (CERT-FR; LeMagIT, 27 March 2023).
Does phishing play a role? Not directly in this case: the documented vector is credential theft by malware. But phishing and infostealers are sibling vectors — same human link, same credentials — and at sector level, the malicious email was the leading source of Cert Santé incidents in 2022 (Cour des comptes, S2024-1456).
Who is FIN12? The designation, by Mandiant’s analysts, of an attackers’ intrusion set that ANSSI linked “to the encryption of some thirty entities between 2020 and 2023” — Ryuk, Conti, then Hive, BlackCat, Nokoyawa, Play and Royal. It is not a group of identified persons: no one has been arrested for the Brest attack.
Was patient data stolen? No: “during the incident, the attackers did not exfiltrate data and did not manage to deploy their final payload” (CERT-FR, 18 September 2023, our translation).
Sources:
- CERT-FR / ANSSI, “FIN12 : un groupe cybercriminel aux multiples rançongiciels”, report CERTFR-2023-CTI-007, 18 September 2023: cert.ssi.gouv.fr — PDF — archived version (accessed 05/09/2026)
- LeMagIT, “Cyberattaque contre le CHRU Brest : ce qu’il s’est passé”, account with Jean-Sylvain Chavanne, CISO of the Brest CHRU, 27 March 2023: lemagit.fr — archived version (accessed 05/09/2026). The hour-level details (alert around 9 p.m., decision within 2h30, investigations until 3 a.m.) come from this press account and the CISO’s words, not from the CERT-FR report.
- ANSSI, “Panorama de la cybermenace 2023” (Cyber Threat Overview 2023), CERTFR-2024-CTI-001, 27 February 2024: cert.ssi.gouv.fr — archived version (accessed 05/09/2026)
- CERT-FR / ANSSI, “Secteur de la santé — état de la menace informatique”, CERTFR-2024-CTI-010, 7 November 2024: cert.ssi.gouv.fr — archived version (accessed 05/09/2026)
- Cour des comptes, “La sécurité informatique des établissements de santé”, final observations S2024-1456, deliberated on 14 October 2024, published online in January 2025: ccomptes.fr (PDF) — archived version (accessed 05/09/2026)
- Verizon, Data Breach Investigations Report 2026: verizon.com (accessed 05/09/2026)
Note: FIN12 (like PISTACHE TEMPEST at Microsoft) is an intrusion-set designation used by threat analysts; it does not refer to any identified person, and no one had been arrested or publicly prosecuted for this attack as of publication. The technical elements cited (tools, attempted vulnerabilities) come exclusively from the public report CERTFR-2023-CTI-007 and are reproduced for descriptive and defensive purposes. French official quotes are our translations; the original French wording is authoritative. This article contains nothing that could identify the healthcare professional whose account was compromised — who is a victim, not a culprit.
Exhibits
The case exhibits
CERT-FR (ANSSI)18 September 2023
Exhibit 01
“Initial access to the information system was performed from a remote desktop service exposed and accessible on the internet. The operators of the intrusion set used the valid credentials of a healthcare professional to log in. It is likely that the account's credentials came from the compromise of the user's workstation by an information stealer, as part of an opportunistic distribution campaign. (our translation)”
CERT-FR (ANSSI)18 September 2023
Exhibit 02
“The discovery of links with a set of incidents observed within the French perimeter and reported in open sources allowed ANSSI to associate this attack with the cybercriminal intrusion set FIN12. […] ANSSI's analyses established links between the Brest CHU incident and the encryption of some thirty entities between 2020 and 2023. (our translation)”
Cour des comptes14 October 2024
Exhibit 03
“The leading source of incidents reported to Cert Santé in 2022, and the second in 2023, is the malicious email, an attack launched at random on the internet, with no defined target, also known as phishing. (our translation)”
ANSSI27 February 2024
Exhibit 04
“This trend is further reinforced by the democratization of information-stealing tools (infostealers), distributed in particular on forums and within private groups. Their growing use has made it easier for cybercriminals with limited technical skills to acquire initial access. (our translation)”