CSIDB logo
Incident

Enercon

Incident posture

Attack window
Aug 2023
Location
Germany
Status
Historical
CIA posture
Available to members
Updated
2026-07-14 08:59

Linked entities

Victim
Enercon
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeted multiple government institutions in Mecklenburg-Vorpommern, including state ministries, subordinate authorities, and the state police website, through coordinated attempts to overload servers with massive requests. IT security experts from the state's data processing center and computer emergency team detected significantly increased activity early in the morning, identifying it as another deliberate disruption effort. Security measures proved effective, rendering the attacks largely unsuccessful by early afternoon. The responsible minister acknowledged the possibility of renewed attacks during the weekend, confirming specialists remained on high alert to respond if necessary. All affected websites were maintained by the state's centralized IT service provider.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On August 17, 2023, IT security experts from the Mecklenburg-Vorpommern state government detected intensified cyberattacks targeting multiple web services within the state’s digital infrastructure. The attacks commenced in the early morning hours, with the state’s IT service provider, Datenverarbeitungszentrum (DVZ) MV, and the state computer emergency response team (CERT M-V) observing a sharp surge in anomalous traffic directed at the Regierungsportal MV platform. Affected systems included websites of state ministries, subordinate agencies, the public homepage of the Mecklenburg-Vorpommern state police, and the MV-Serviceportal—all centrally managed and maintained by DVZ MV. Initial analysis confirmed the activity constituted a deliberate attempt to overwhelm servers through mass automated requests, characteristic of a distributed denial-of-service (DDoS) attack. Security teams activated heightened monitoring protocols and placed DVZ and CERT personnel on standby to mitigate potential disruptions.

By early afternoon, authorities confirmed defensive measures had successfully neutralized the attack’s impact, preventing significant service degradation or downtime. State Interior Minister Pegel acknowledged the attack’s scale as unprecedented for the state administration’s web infrastructure but emphasized its ultimate ineffectiveness due to robust security protocols. No data breaches or unauthorized access to backend systems were reported. Despite the containment, Pegel warned that attackers might launch follow-on assaults over the upcoming weekend, prompting CERT M-V and DVZ to maintain continuous alert status. The incident concluded without operational interruptions to government services or public-facing portals, though it highlighted persistent threats to critical digital assets managed by regional authorities. Monitoring systems remained active to detect any resurgence of malicious activity targeting the state’s web infrastructure.

Sources

Sources available to members: 1 source.

CSIDB