The case most often called the first cyberattack in history took place in France between 1834 and 1836. Twin brothers François and Louis Blanc, speculators in Bordeaux, bribed operators of the state-run Chappe optical telegraph at Tours to hide market signals inside official dispatches, so they learned how Paris bond prices had moved before anyone else.
In 1998 Tom Standage of The Economist called the electric telegraph "the Victorian Internet". Years later, writing for the paper's 1843 Magazine, he went further back. Before any wire was strung, France already ran a national data network of semaphore towers, and it had already been compromised by insiders selling access to the highest bidder. The Blanc affair has everything a modern incident report needs: a critical channel, trusted staff who could be bought, data hidden in control traffic, and a legal system with no offence to charge.
What was the Chappe network?
Claude Chappe's optical telegraph linked French cities through a chain of towers set between 5 and 15 kilometres apart. On top of each stood a pivoting beam with two smaller arms, and their positions encoded 98 combinations. Six of those were reserved for operational use, such as end of message or error. An operator watched the previous tower through a telescope, copied its position, and the next tower did the same. A message could cross the country in hours; a mounted courier took days.
The network belonged to the government and private use was forbidden. Financial news from Paris reached the provinces by mail coach, which gave anyone who knew the latest price of the rente (French government bonds paying 3 %) a trading edge in Bordeaux.
How did the Blanc brothers game it?
The twins could not send messages over the network, so they bought the people who ran it. The scheme, as reconstructed from court reporting of the time and Maxime Du Camp's 1867 account, relied on a handful of accomplices and a very low-tech code.
An agent in Paris watched the bond market and sent a parcel to Tours by stagecoach. Its contents were the message: gloves meant the rente had risen, socks meant it had fallen, and some accounts mention coloured ties or scarves. At Tours, a station on the Paris to Bordeaux line, two bribed employees named Guibout and Lucas inserted an agreed symbol into an official dispatch heading south, then immediately sent the service signal for an error. When the dispatch was transcribed at the end of the line, the cancelled symbol was dropped and the government's text arrived intact.
In Bordeaux, Pierre Renaud, a former telegraph official from Lyon, watched the city's tower through a telescope and noted the symbol that every clerk down the line had been told to ignore. Standage compares the trick to typing a character and hitting backspace: the character still travels, it just never appears in the final document. According to La France pittoresque, Guibout received 300 francs a month plus 50 francs per signal, against an official wage of 1.50 francs a day.
Was it insider trading?
Not in the modern sense. The Blancs did not trade on confidential corporate information; the bond price in Paris was public the moment it was set. What they bought was time. They paid insiders to move public information faster than the market could, which makes the affair closer to latency arbitrage than to insider dealing, and a distant ancestor of the private fibre routes and microwave links that high-frequency traders build today.
The distinction matters for risk teams. The asset the Blancs stole was not the data itself but the integrity and exclusivity of a channel. Many organisations still classify and protect information while treating the pipes it travels through as neutral.
How was it caught, and why did they walk free?
The scheme ran from roughly August 1834 to the summer of 1836. La France pittoresque counts 121 false transmissions, a figure we have not been able to check against the court records. It unravelled through people, not technology. Lucas fell ill and died in early 1836, and before he died he confided the secret to a colleague, Cailleteau, hoping he would take over the arrangement. The story reached the management at Tours, who had also noticed that Guibout was living far more comfortably than his colleagues could explain. The Blancs were arrested in August 1836 and spent about seven months in custody.
The trial opened before the assize court at Tours on 11 March 1837. The jury accepted that the signals had been sent and the bribes paid, but found that Guibout had not been corrupted to perform an act of his office, which was what articles 177 and 179 of the 1810 Penal Code required. No law prohibited private use of the telegraph. On 14 March 1837 Renaud was acquitted and the Blancs and Guibout were ordered only to pay costs; one English-language source also mentions fines. The brothers kept their profits, and François Blanc went on to run the casinos of Bad Homburg and, from 1863, Monte Carlo.
Parliament moved within weeks. A law of 2 May 1837 punished anyone who transmitted signals from one place to another without authorisation, "by telegraphic machines or by any other means", with one month to one year in prison and a fine of 1,000 to 10,000 francs. It enshrined the state monopoly on telecommunications, and its open wording outlived the towers.
The pattern has repeated since. In the UK, Robert Schifreen and Stephen Gold broke into British Telecom's Prestel service in 1984 and 1985; the House of Lords upheld their acquittal in 1988 because forgery law did not fit, and Parliament passed the Computer Misuse Act 1990. In the US, Van Buren v. United States (2021) turned on a police sergeant paid to run a licence-plate search with his own valid credentials. The Supreme Court held, 6 to 3, that misusing access you legitimately hold does not "exceed authorized access" under the Computer Fraud and Abuse Act. Spain's criminal code has a similar shape: its computer-intrusion offence (article 197 bis) requires acting without authorisation. Close to two centuries after Tours, the bribed insider remains the hardest case for cybercrime law.
What should a CISO take from the Blanc affair?
Insider risk is a people problem with technical symptoms. No perimeter was breached; the attackers rented legitimate access. The signal that gave Guibout away was lifestyle, not logs. Guidance such as the CISA Insider Threat Mitigation Guide and Carnegie Mellon's Common Sense Guide to Mitigating Insider Threats both pair technical monitoring with screening, segregation of duties and attention to financial pressure or unexplained wealth, the same controls ISO/IEC 27001:2022 lists in Annex A as 6.1 (screening) and 5.3 (segregation of duties). Our glossary entry on insider threat covers the main indicators.
Protect the channel, not only the payload. Every official dispatch arrived word-perfect. A control that validates only the final document would have passed every manipulated message. The modern equivalent is data exfiltration hidden in headers, metadata, padding or traffic a protocol is designed to discard.
Covert channels live in what the system ignores. Strictly speaking, Tours was less steganography than a covert storage channel: a control signal repurposed to carry data. The same idea reappears in DNS tunnelling, image least-significant bits and packet timing, catalogued in MITRE ATT&CK under techniques such as T1048 (exfiltration over alternative protocol) and T1001.002 (steganography). NIST SP 800-53 even has a dedicated control, SC-31, for covert channel analysis in high-assurance systems.
Error rates are telemetry. Nothing suggests the telegraph administration compared how many cancellations each station sent. A simple count per tower might have flagged Tours long before a dying man's confession did. Today that means centralised, protected logs that someone actually reviews, as described in ISO/IEC 27001:2022 controls 8.15 (logging) and 8.16 (monitoring activities) and NIST SP 800-53 AU-6, usually through a SIEM and behavioural analytics (UEBA) that treat "benign noise" as data. If you are deciding what to feed that SIEM, our guide on which logs to send is the practical next step.
Regulation now expects the controls the law once lacked. In the EU, the NIS2 Directive lists human resources security and supply-chain security among the minimum cybersecurity risk-management measures (article 21(2)). Compliance does not catch a Guibout, but it forces the questions that would have.
Sources
- RetroNews (BnF), contemporary press
- Wikipédia FR «Piratage du télégraphe Chappe»
- La France pittoresque
- Maxime Du Camp, Revue des Deux Mondes, 1867 (Wikisource)
- Roger Errera, Communications no. 21, 1974 (Persée)
- Archives départementales d'Indre-et-Loire
- Tom Standage, 1843 Magazine (The Economist)
- Tom Standage, 1843 Magazine (The Economist)
- Wikipedia «Chappe telegraph»
- Wikipedia «François Blanc»
- https://en.wikipedia.org/wiki/Robert_Schifreen
- US Supreme Court opinion
- BOE-A-1995-25444
- Directive (EU) 2022/2555
- https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final
- https://attack.mitre.org/techniques/T1048/
- https://attack.mitre.org/techniques/T1001/002/
- https://www.cisa.gov/resources-tools/resources/insider-threat-mitigation-guide
- https://insights.sei.cmu.edu/library/common-sense-guide-to-mitigating-insider-threats-seventh-edition/
Frequently asked questions
I teach the history of technology and want to use this in class: what is usually called the first cyberattack in history?
▾
Most accounts point to the Blanc brothers, who between 1834 and 1836 paid operators of France's Chappe optical telegraph to smuggle bond-market signals from Paris to Bordeaux. Tom Standage described it as the world's first cyberattack. The label is a modern reading of a 19th-century fraud, but the mechanics fit it well.
I'm building an insider-risk briefing for our board: why is the Blanc case a useful example?
▾
Because the attackers broke nothing. They bribed staff with legitimate access, hid their data inside normal operations, and were exposed by a confession and one employee's unexplained wealth, not by any technical control. It shows why insider programmes combine screening, segregation of duties and log review rather than relying on technology alone.
I work in compliance and I'm surprised they were acquitted: why weren't the Blanc brothers convicted in 1837?
▾
The jury accepted the facts but found the bribed operator had not acted within his official duties, which the corruption articles of the 1810 French Penal Code required, and no law banned private use of the telegraph. They paid only court costs. Parliament passed a law on 2 May 1837 criminalising unauthorised signalling.
I'm a network security engineer and curious about the mechanics: how did they hide data in a semaphore network?
▾
The Tours operator inserted an agreed symbol into an official dispatch and immediately followed it with the error signal. The symbol travelled down the whole line, but was discarded at transcription, so the dispatch arrived clean. An accomplice read it from the Bordeaux tower with a telescope. Today we would call it a covert storage channel.
As a CISO, which modern controls would have caught this?
▾
Counting cancellation signals per station would probably have flagged Tours as an outlier. The modern version is centralised, tamper-protected logging, correlation in a SIEM, and behavioural analytics that treat repeated "harmless" errors as worth a look, combined with personnel screening and segregation of duties for anyone who can touch a critical channel.