LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Ville de Chevilly-Larue Listed by noescape Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Ville de Chevilly-Larue Listed by noescape Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·July 24, 2023
Ville de Chevilly-Larue Listed by noescape Ransomware Group

Reported July 24, 2023.

HIGH
Severity
July 24, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Ville de Chevilly-Larue Listed by noescape Ransomware Group (reported July 24, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severity claimedUnverified claim
Exposes government-ID data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On July 24, 2023, the French municipality Ville de Chevilly-Larue was listed by the ransomware group noescape. Public reporting indicates the group claimed to have encrypted and compromised the organisation’s network and to have exfiltrated internal files. The number of people affected remains unknown, and independent confirmation of the full scope is limited.

For residents, staff and anyone who has dealt with the town administration, the listing raises clear questions about what material may have left the network and what practical steps follow. Detail so far rests largely on the group’s own statements rather than verified disclosures from the municipality.

What happened

According to the information made public with the listing, noescape asserted that Ville de Chevilly-Larue’s network had been successfully encrypted and compromised. The group further claimed it had taken internal files and would release them if the organisation did not enter into dialogue. The reported summary names categories the attackers said were among the material: banking, finance, budget, passports and contracts, among other items indicated by an ellipsis in the original claim.

No public figure has been given for the volume of data, the precise date of initial access, or the technical method used. The number of individuals whose information may be involved is recorded as unknown. Beyond the group’s leak-site listing and the short accompanying description, further operational detail has not been disclosed in the available record.

The group behind it: noescape

noescape is a ransomware operation that has appeared in public threat reporting as a double-extortion actor. In this model, operators encrypt systems to disrupt operations and simultaneously claim to have copied data, then threaten to publish or auction the material if a payment or negotiation does not occur. The group has maintained a leak site on which it names organisations and posts samples or fuller archives when it asserts that talks have failed.

Like other groups in this category, noescape has historically targeted a range of sectors rather than a single industry, using the pressure of both operational downtime and potential data exposure. Claims made on such sites are assertions by the attackers; they are not independent verification that every file listed was in fact taken or that every named organisation suffered the full impact described. In this case, the listing of Ville de Chevilly-Larue and the description of encrypted systems and exfiltrated internal files should be read as the group’s claim pending any fuller official account.

Ville de Chevilly-Larue and its sector

Ville de Chevilly-Larue is a municipal administration in France, responsible for local public services, civil records, urban planning, local finances and day-to-day contact with residents and businesses. Municipalities of this kind routinely hold identity-related documents, financial and budgetary records, contracts with suppliers and service providers, and correspondence tied to administrative procedures.

A breach affecting a town hall matters because the data is often tied to real people who have little choice about interacting with the authority—births, residences, local taxes, permits and social or community services. Disruption of municipal systems can also slow public services even when personal data is not the primary concern. The combination of operational impact and the sensitivity of administrative files is why listings of local governments draw attention beyond the immediate organisation.

The information in question

The available facts state that internal files were exfiltrated in a ransomware attack. The group’s own description, as reported, lists banking, finance, budget, passports and contracts among the material it claimed it would release absent dialogue. No confirmed inventory, file counts or independent validation of those categories has been provided in the public record summarised here.

Organisations of this type typically maintain citizen identity documents or copies, financial ledgers, budget working papers, vendor contracts, human-resources files for staff, and varied internal correspondence. Whether any specific subset of that typical holdings was actually copied in this incident remains unconfirmed beyond the attackers’ assertions. Exact contents and the total number of affected individuals are therefore not established in the disclosed facts.

What's at stake

If the claimed categories are accurate, residents and employees could face risks that include misuse of identity documents, exposure of financial or contractual details, and targeted fraud that leverages knowledge of local administrative dealings. Passports and similar identity material, if present, raise classic identity-theft concerns; banking and budget data can aid social-engineering attempts against individuals or against the municipality itself.

For the organisation, the stakes include restoration of systems, possible regulatory notification duties under applicable data-protection rules, and the longer task of determining what left the network. Because the count of affected people is unknown and the precise contents unconfirmed, the practical impact on any single person cannot yet be stated with certainty. The situation nonetheless warrants caution from anyone who has supplied personal or financial information to the town administration.

What to do if you're exposed

If you have had dealings with Ville de Chevilly-Larue—residency records, local taxes, contracts, employment or other administrative processes—monitor bank and credit activity for unfamiliar transactions and treat unexpected messages that reference municipal business with scepticism. Consider placing fraud alerts where available and retain copies of any official correspondence that may help dispute misuse of your details. If you are a staff member or contractor, follow any guidance issued by the municipality’s IT or security contacts.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That step does not confirm involvement in this specific incident, but it provides a practical starting point for understanding whether your credentials or personal details appear elsewhere in circulating collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyVille de Chevilly-Larue security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Ville de Chevilly-Larue’s full breach history →

More recent breaches

Action Santé Travail Listed by noescape Ransomware GroupOctober 29, 2023LDLC ASVEL Listed by noescape Ransomware GroupOctober 9, 2023GEACAM Listed by noescape Ransomware GroupOctober 6, 2023Seattle Housing Authority Listed by noescape Ransomware GroupOctober 5, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Ville de Chevilly-Larue Listed by noescape Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by noescape — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram