CSIDB logo
Incident

Bycyklen

Incident posture

Attack window
May 2018
Location
Denmark
Status
Historical
CIA posture
Available to members
Updated
2025-11-29 00:00

Linked entities

Victim
Bycyklen
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Copenhagen bike-sharing system suffered a cyberattack disrupting operations for most of its fleet, leaving only a small fraction functional during peak hours. Hackers with detailed system knowledge erased databases, forcing a prolonged service outage and requiring manual updates to each bicycle. While the attackers did not compromise user data—including encrypted PINs, emails, and phone numbers—the operator advised customers to change their access codes as a precaution. Service was largely restored following the incident, which remained under police investigation.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On May 3-5, 2018, Copenhagen's Bycyklen electric bicycle-sharing system suffered a cyberattack that disrupted operations across the city. Unknown hackers with detailed knowledge of the system compromised the company's operational infrastructure, erasing databases and forcing a complete service outage lasting most of Saturday. The attack impacted 1,860 GPS-equipped bicycles, leaving only 200 functional units available during peak hours. Riders were unable to access bicycles through the iOS and Android apps that controlled the GPS routing and booking system. Bycyklen confirmed the malicious activity caused total system failure, with only a brief temporary restoration mid-Saturday before services collapsed again. No bicycles could be unlocked or managed through the platform during the outage period.

Bycyklen's technical team manually updated each bicycle to restore functionality following the database deletion. Forensic analysis revealed no evidence of data exfiltration, with the company confirming user payment details were not stored and asserting email addresses, phone numbers, and encrypted PINs remained secure through salted password hashing. Despite the encryption measures, Bycyklen proactively advised all users to change their PINs as a precaution. Copenhagen police initiated an investigation into the attack, which exclusively targeted business operations rather than customer data. Service recovery progressed throughout the week, with system status indicators showing near-full availability by May 8 when public reports confirmed operational restoration. The incident highlighted critical infrastructure vulnerabilities in urban mobility systems without compromising user information.

Sources

Sources available to members: 1 source.

CSIDB