CSIDB logo
Incident

City of Liège

Incident posture

Attack window
Jun 2021
Location
Belgium
Status
Historical
CIA posture
Available to members
Updated
2026-07-15 22:51

Linked entities

Victim
City of Liège
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jun 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The City of Liege in Belgium experienced a disruptive ransomware attack targeting its municipal IT infrastructure, severely impacting administrative and online services. Civil status operations, population management, and event-related functions—including birth registrations, marriage ceremonies, burial services, permit applications, and paid parking systems—were rendered inaccessible, forcing cancellations and service interruptions. Belgian media attributed the incident to the Ryuk ransomware gang, though officials confirmed only a generalized "computer attack." The event underscores systemic vulnerabilities in local government networks, which often operate with outdated technology and limited cybersecurity resources, making them frequent targets for such intrusions.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 21, 2021, the City of Liege, Belgium’s third-largest municipality, experienced a ransomware attack that severely disrupted its IT network and online services. The incident rendered most civil status and population services inoperable, forcing officials to cancel appointments for town halls, birth registrations, weddings, and burial services due to employees’ inability to access critical systems. Online platforms for event permits and paid parking were also disabled. City authorities established a status page to communicate service disruptions, acknowledging broader impacts beyond these initial systems and pledging to publish a comprehensive list of affected services later that day to prevent unnecessary visits to city offices. The municipality’s official Twitter account confirmed the inaccessibility of neighborhood town hall services, among others, attributing the outages to a "computer attack."

Belgian radio and television outlets reported the Ryuk ransomware gang as responsible for the attack, though Liege officials did not publicly confirm this attribution. The incident highlighted systemic vulnerabilities in municipal IT infrastructure, with the article noting that local governments frequently face ransomware attacks due to limited budgets for advanced security measures, outdated hardware, and understaffed IT departments. While Liege represented a significant target, the attack aligned with a pattern of ransomware incidents affecting major cities globally, including recent breaches in Tulsa, Atlanta, Baltimore, and New Orleans. The city’s response focused on service disruption notifications and appointment cancellations, with no additional containment or recovery actions detailed in available reports. Operational consequences persisted through the initial attack day, impacting essential civic functions and resident access to administrative services.

Sources

Sources available to members: 1 source.

CSIDB