CSIDB logo
Incident

Kantonsschule Frauenfeld

Incident posture

Attack window
May 2024
Location
Switzerland
Status
Historical
CIA posture
Available to members
Updated
2025-12-31 13:06

Linked entities

Victim
Kantonsschule Frauenfeld
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack targeted the IT infrastructure of Kantonsschule Frauenfeld, causing an internet outage that primarily affected the school's operational systems while sparing administrative IT. Despite the disruption, the school maintained continuity of classes, and WLAN services were subsequently restored. The institution's IT specialists detected the incident immediately and responded promptly, with the situation remaining under control throughout. The Thurgau Cantonal Police cybercrime unit is investigating the attack, though the motive remains undetermined at this stage.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

A ransomware attack disrupted internet services at Kantonsschule Frauenfeld, targeting the school's IT infrastructure while leaving administrative systems unaffected. The incident caused a complete internet outage, forcing the institution to operate without network connectivity during the attack. Despite the disruption, school officials maintained classroom instruction without interruption by implementing contingency measures. Technical personnel detected the intrusion immediately and initiated containment protocols, with Rektorin Chantal Roth confirming that specialists retained control throughout the incident. Restoration efforts progressed sufficiently to reactivate the school's WLAN systems following the attack, though the timeline for full recovery remains unspecified.

The Thurgau Cantonal Police's cybercrime unit assumed investigative responsibility, indicating the severity warranted specialized forensic attention according to police spokesperson Miguel Lopez. No threat actor identification, ransom demands, or data compromise details were disclosed by investigators. Authorities have not determined the attack's motivation or origin as of the last reported update. The school administration emphasized their operational continuity throughout the incident, with no reported academic schedule disruptions or collateral damage to non-IT facilities. Police continue examining potential attack vectors and forensic evidence from compromised systems.

Sources

Sources available to members: 1 source.

CSIDB