A municipal utility in Bavaria said Monday that hackers encrypted its central IT network in a cyberattack last week. In a notice to customers, Stadtwerke Landsberg said the attack disrupted office systems but is not affecting electricity, water and other essential services. The incident began overnight on September 1, the utility said, prompting it to disconnect the affected systems from the internet, activate its crisis team and bring in external cybersecurity specialists. Although the operator described an encryption event, it did not identify a specific ransomware group that may have committed the attack nor say whether it has received an extortion demand. The city-owned utility said its staff “are currently only available to a limited extent by phone and email” and that the specialists’ forensic investigation is ongoing. Stadtwerke Landsberg warned customers that it could not rule out whether attackers accessed or stole their personal data. The potentially affected information includes names, addresses, phone numbers, email addresses and bank details. Ransomware and other disruptive cyberattacks remain a persistent problem for German companies and public-sector organizations. Germany’s federal cybersecurity agency, the BSI, has repeatedly identified ransomware as one of the country’s most serious cyber threats. A similar attack impacting another municipal utility — serving Kamen, Bönen and Bergkamen in North Rhine-Westphalia — took place in late June. Internal systems were disrupted for weeks in that case, with the operator later saying attackers may have accessed older backups containing personal data. The recent attack occurred during an unusually tense day for Germany’s critical infrastructure operators. It coincided with the German government formally blaming Russia for a drone attack at Leipzig/Halle airport and with saboteurs striking two power substations on opposite sides of the country. Despite concerns about the Russian government leveraging the cybercrime ecosystem in “hybrid” attacks, there is no indication the Landsberg hack is connected to any other incident. In Brandenburg, investigators found improvised devices near the Turnow-Preilack substation. One device successfully caused a short circuit but no significant disruption to the public supply. Hours later, an attack at the Amprion substation at Rommerskirchen, in the west, briefly knocked several power-plant units offline without threatening the stability of the grid. On Tuesday, Police arrested a 48-year-old man in connection with acts of sabotage at power installations across Brandenburg, North Rhine-Westphalia and Saxony, the three regions where Germany still mines and burns lignite — a form of coal considered to be a particularly high polluter. Two handwritten letters claiming sole responsibility for the attacks, which investigators say contain detailed knowledge of what took place, cite the perpetrator’s opposition to electricity generation from fossil fuels. Last month, Germany’s cabinet approved legislation that would let its intelligence agencies hack foreign systems, sabotage adversaries’ supply chains and feed false information to extremists inside Germany, in the biggest overhaul of the country’s spy laws of the postwar era. The government has pointed to a rapidly changing threat environment to justify the legislation, including the Russian invasion of Ukraine, Islamist terrorism and political extremism.
No previous article
No new articles
Alexander Martin
is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79