CSIDB logo
Incident

Austrian Ministry of Health

Incident posture

Attack window
Dec 2020
Location
Austria
Status
Historical
CIA posture
Available to members
Updated
2025-12-07 00:00

Linked entities

Victim
Austrian Ministry of Health
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Austrian Ministry of Health experienced a cyberattack and data breach shortly after launching a website for COVID-19 mass test registrations, causing significant disruptions. Unknown attackers overwhelmed the system with a flood of requests, paralyzing the platform and preventing user access during critical initial operations. The incident triggered widespread complaints about service outages while compromising both system functionality and data security.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On December 2, 2020, the Austrian Ministry of Health launched www.österreich-testet.at, a website enabling registration for COVID-19 mass testing in Vienna, with initial testing scheduled to begin at three locations on December 4. The site became operational at midnight but experienced widespread accessibility issues within hours. Users reported systemic failures by Wednesday morning, preventing access to registration services. Ministry officials attributed the disruption to a cyber attack, specifically noting that unidentified threat actors had attempted to overwhelm the system with a flood of requests. This volumetric attack method paralyzed the website’s functionality during a critical public health initiative. The incident occurred during the site’s initial operational phase, limiting service availability exclusively to Vienna residents at launch. No technical details regarding attack vectors, mitigation measures, or attacker origins were disclosed by authorities at this stage.

The cyber attack caused immediate operational disruption, halting public access to COVID-19 test registration during a high-demand period. Ministry spokeswoman confirmed the incident to Austrian newspaper KURIER but did not specify whether user data was compromised beyond acknowledging a concurrent "data breach." System paralysis persisted for an unspecified duration, directly impacting Vienna’s testing rollout timeline. Public reports indicated significant user frustration due to the abrupt service interruption. The ministry did not disclose remediation timelines, forensic findings, or whether law enforcement was engaged. Consequences included delayed public health preparedness and reputational damage to the digital infrastructure supporting pandemic response. The incident highlighted vulnerabilities in critical health service platforms during emergency deployments.

Sources

Sources available to members: 1 source.

CSIDB