Cyber Incident Victim: Liège
Date:
Jun 2021
Location:
Belgium
Summary
The City of Liege in Belgium experienced a disruptive ransomware attack targeting its municipal IT infrastructure, severely impacting administrative and online services. Civil status operations, population management, and event-related functions—including birth registrations, marriage ceremonies, burial services, permit applications, and paid parking systems—were rendered inaccessible, forcing cancellations and service interruptions. Belgian media attributed the incident to the Ryuk ransomware gang, though officials confirmed only a generalized "computer attack." The event underscores systemic vulnerabilities in local government networks, which often operate with outdated technology and limited cybersecurity resources, making them frequent targets for such intrusions.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On June 21, 2021, the City of Liege, Belgium’s third-largest municipality, experienced a ransomware attack that severely disrupted its IT network and online services. The incident rendered most civil status and population services inoperable, forcing officials to cancel appointments for town halls, birth registrations, weddings, and burial services due to employees’ inability to access critical systems. Online platforms for event permits and paid parking were also disabled. City authorities established a status page to communicate service disruptions, acknowledging broader impacts beyond these initial systems and pledging to publish a comprehensive list of affected services later that day to prevent unnecessary visits to city offices. The municipality’s official Twitter account confirmed the inaccessibility of neighborhood town hall services, among others, attributing the outages to a "computer attack."

Belgian radio and television outlets reported the Ryuk ransomware gang as responsible for the attack, though Liege officials did not publicly confirm this attribution. The incident highlighted systemic vulnerabilities in municipal IT infrastructure, with the article noting that local governments frequently face ransomware attacks due to limited budgets for advanced security measures, outdated hardware, and understaffed IT departments. While Liege represented a significant target, the attack aligned with a pattern of ransomware incidents affecting major cities globally, including recent breaches in Tulsa, Atlanta, Baltimore, and New Orleans. The city’s response focused on service disruption notifications and appointment cancellations, with no additional containment or recovery actions detailed in available reports. Operational consequences persisted through the initial attack day, impacting essential civic functions and resident access to administrative services.
