Cyber Incident Victim: Municipality of Herselt
Date:
Mar 2022
Location:
Belgium
Summary
A distributed denial-of-service (DDoS) attack targeted Belnet, the research and education network serving French-speaking universities, causing widespread website inaccessibility across multiple academic institutions. The attack flooded the network with excessive access requests to disrupt operations, though IT teams from affected universities like Liège and Mons responded swiftly to restore functionality within minutes. No data theft occurred according to officials, with Louvain explicitly confirming no breach of information. Impacted institutions coordinated through their cybersecurity teams to analyze the incident, though the attackers' motives remained unclear at the time. This marked the second such disruption to these universities within a six-month period.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On March 21, 2022, Belgian francophone universities experienced significant disruptions to their online services following a distributed denial-of-service (DDoS) attack targeting Belnet, the national research and education network connecting these institutions. The attack commenced around 15:00 local time, flooding Belnet's infrastructure with excessive access requests that overwhelmed systems and rendered affiliated university websites nearly inaccessible. This deliberate disruption prevented users from accessing critical online resources across multiple academic institutions simultaneously. The University of Mons characterized the incident as an intentional attempt to paralyze network functionality through traffic saturation. At the University of Liège, the acute phase of the attack lasted only minutes, though broader service interruptions persisted longer across the shared network infrastructure.

IT teams from affected universities implemented immediate countermeasures to restore functionality. The University of Liège's technicians successfully mitigated the attack through rapid intervention, enabling normal website operations to resume while maintaining ongoing surveillance for additional anomalies. No data breaches or information theft occurred during the incident, as explicitly confirmed by the Catholic University of Louvain. Coordination efforts between chief information security officers (RSSIs) from impacted institutions were established to develop a comprehensive understanding of the attack's scope and mechanisms, with the University of Namur acknowledging this collaborative response. The incident marked the second cybersecurity event targeting francophone universities within six months, though no attribution or motive for the attack was identified during initial assessments. Service restoration timelines varied across institutions depending on their individual network configurations and mitigation implementations.
