news.mlab.sh
Back to the feed
threat-intel

Cyberattack encrypts systems at Bavarian municipal utility

High
Summary

A Bavarian municipal utility, Stadtwerke Landsberg, experienced a cyberattack last week that encrypted its central IT network, disrupting office systems but not impacting essential services like electricity and water. The incident led to a potential data breach, with the utility warning that attackers may have accessed customer information including names, addresses, and bank details. This follows a similar attack on another municipal utility in North Rhine-Westphalia, highlighting a growing trend of cyberattacks targeting German critical infrastructure.

A municipal utility in Bavaria, Stadtwerke Landsberg, announced Monday that hackers had encrypted its central IT network in a cyberattack that occurred overnight on September 1st. The attack disrupted office systems but did not affect essential services such as electricity and water distribution. The utility stated that it disconnected the affected systems from the internet, activated a crisis team, and brought in external cybersecurity specialists to investigate.

Despite not identifying a specific ransomware group, Stadtwerke Landsberg warned customers that attackers may have accessed or stolen their personal data, including names, addresses, phone numbers, email addresses, and bank details. The operator described an encryption event, but did not indicate whether an extortion demand was made.

This incident follows a similar attack on another municipal utility serving Kamen, Bönen, and Bergkamen in North Rhine-Westphalia, where internal systems were disrupted for weeks, and attackers may have accessed older backups containing personal data. The recent attack occurred during a period of heightened tension for Germany’s critical infrastructure operators, coinciding with a drone attack at Leipzig/Halle airport and sabotage attempts at two power substations in Brandenburg, North Rhine-Westphalia, and Saxony.

Investigators in Brandenburg found improvised devices near a substation, one of which successfully caused a short circuit without significant disruption to the public supply. Simultaneously, an attack at the Amprion substation at Rommerskirchen briefly knocked several power-plant units offline, but did not threaten grid stability. Two handwritten letters claiming responsibility for the attacks cited the perpetrator’s opposition to electricity generation from fossil fuels.

Germany’s cabinet recently approved legislation allowing intelligence agencies to hack foreign systems, sabotage adversaries’ supply chains, and feed false information to extremists within Germany, citing a rapidly changing threat environment including the Russian invasion of Ukraine, Islamist terrorism, and political extremism.

Read the full article at The Record