CSIDB logo
Incident

Landkreis München-Land

Incident posture

Attack window
Feb 2025
Location
Germany
Status
Unknown
CIA posture
Available to members
Updated
2026-08-28 11:38

Linked entities

Victim
Landkreis München-Land
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Landkreis München-Land experienced a distributed denial‑of‑service attack that rendered its website inaccessible for several hours, with the city of Garching’s online portal suffering the same outage. The disruption was part of a broader wave of DDoS incidents targeting Bavarian government sites, which authorities linked to suspected pro‑Russian hacktivist activity. Although the attacks caused temporary service interruptions, officials confirmed that no data were compromised or damaged and that normal operation was restored after mitigation efforts.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On the morning of 13 February 2025 the homepage of the Munich district office (Landkreis München‑Land) became unavailable as part of a distributed denial‑of‑service attack that also targeted the city of Garching’s website. According to the district office’s press service the site had been intermittently inaccessible since the previous day and remained unreachable under the address www.landkreis‑muenchen.de throughout the morning, with its availability depending on the actions of the network operator. The attack was described by officials as a classic DDoS effort in which a server was flooded with requests until it could no longer respond, thereby denying service to legitimate users. The technical service provider that hosts both the district office’s and Garching’s homepages was reported to be working intensively to restore normal operation, and for Garching a temporary redirect was put in place so that entering www.garching.de displayed the municipal homepage while the underlying issue was being resolved. No mention was made of a similar redirect for the district office, and the outage persisted into the evening of 13 February, with intermittent problems noted again on the morning of 14 February.

The incident formed part of a broader wave of cyber activity that also affected the Bavarian state government’s online presence. On Thursday, the state chancellery and the state ministry for digital were targeted, though officials confirmed that no data were exfiltrated, encrypted, or otherwise damaged and that the affected websites were only temporarily unreachable. Irregularities were also observed on the internet presence of the Bavarian police, a fact confirmed by the Bavarian State Criminal Office to the Bavarian Radio. The Bavarian State Office for Security in Information Technology characterized the attacks as distributed denial‑of‑service operations and stated that, with high probability, they were linked to prorussian hacktivist activity. Investigations were said to be ongoing, and after analysis the matter would be handed over to the police for potential prosecution. No evidence of data loss or lasting harm was reported for any of the affected entities.

The primary impact on the Munich district office was the loss of public access to its online information and services, which relied entirely on the availability of the hosted website. Response actions centered on the technical service provider’s efforts to mitigate the traffic overload and restore connectivity, with the district office noting that the speed of recovery depended on the underlying network provider’s actions. While no data breach or service disruption beyond website inaccessibility was identified, the episode contributed to a heightened awareness of DDoS threats across Bavarian governmental web presences and prompted ongoing coordination between IT security authorities, law enforcement, and the involved service providers to address the attacks and prevent recurrence.

Sources

Sources available to members: 2 sources.

CSIDB