Menu
Browse

Cyber Incident Victim: Germany

Date:

Apr 2025

Location:

Germany

Summary

A Russian hacking group targeted several German cities, including Dresden, aiming to disrupt online services such as e‑ticketing and appointment systems; the city’s website became intermittently accessible with delayed response times before defenses restored normal operation, and authorities linked the group to a prior attack on the same site. The same campaign also affected the municipal websites of Berlin and Nürnberg, though Dresden’s services were reported as fully functional again after the incident.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 3 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On the weekend of April 2025, a Russian hacking group launched a coordinated cyber attack against several German municipal websites, including the online presence of Dresden. The attackers aimed to disrupt the city’s internet services, such as e‑parking permits and online appointment scheduling, by targeting the dresden.de domain. During the assault, the Dresden website experienced restricted accessibility, with users reporting intermittent availability. The city’s administration confirmed that the attack occurred between 10:00 and 14:00 on Friday, causing a noticeable delay in response times for some applications while the core pages and services remained reachable.

Cyber Incident Image

According to a statement from Dresden’s town hall, the attack was successfully repelled by the city’s IT security teams, and normal operation was restored by the following Monday. Throughout the incident, the affected services continued to function, albeit with slowed performance during the specified window. The same Russian hacking group had previously been identified by federal cybersecurity authorities as responsible for a breach of dresden.de in October 2023. In addition to Dresden, the municipal websites of Berlin and Nuremberg were also impacted during the same wave of attacks.

Authorities have not disclosed further technical details about the methods used or the extent of data exposure, if any, in the public statements released. The city’s administration emphasized that, after the defensive measures were taken, all online services have been operating without problems since Monday. No additional disruptions have been reported in the aftermath of the incident.

Sources
Sources available to members
1 source