Menu
Browse

Cyber Incident Victim: Austrian Ministry of Health

Date:

Dec 2020

Location:

Austria

Summary

The Austrian Ministry of Health experienced a cyberattack and data breach shortly after launching a website for COVID-19 mass test registrations, causing significant disruptions. Unknown attackers overwhelmed the system with a flood of requests, paralyzing the platform and preventing user access during critical initial operations. The incident triggered widespread complaints about service outages while compromising both system functionality and data security.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On December 2, 2020, the Austrian Ministry of Health launched www.österreich-testet.at, a website enabling registration for COVID-19 mass testing in Vienna, with initial testing scheduled to begin at three locations on December 4. The site became operational at midnight but experienced widespread accessibility issues within hours. Users reported systemic failures by Wednesday morning, preventing access to registration services. Ministry officials attributed the disruption to a cyber attack, specifically noting that unidentified threat actors had attempted to overwhelm the system with a flood of requests. This volumetric attack method paralyzed the website’s functionality during a critical public health initiative. The incident occurred during the site’s initial operational phase, limiting service availability exclusively to Vienna residents at launch. No technical details regarding attack vectors, mitigation measures, or attacker origins were disclosed by authorities at this stage.

Cyber Incident Image

The cyber attack caused immediate operational disruption, halting public access to COVID-19 test registration during a high-demand period. Ministry spokeswoman confirmed the incident to Austrian newspaper KURIER but did not specify whether user data was compromised beyond acknowledging a concurrent "data breach." System paralysis persisted for an unspecified duration, directly impacting Vienna’s testing rollout timeline. Public reports indicated significant user frustration due to the abrupt service interruption. The ministry did not disclose remediation timelines, forensic findings, or whether law enforcement was engaged. Consequences included delayed public health preparedness and reputational damage to the digital infrastructure supporting pandemic response. The incident highlighted vulnerabilities in critical health service platforms during emergency deployments.

Sources
Sources available to members
1 source