Cyber Incident Victim: Frankfurter Entsorgungs- und Service GmbH
Date:
Jun 2022
Location:
Germany
Summary
Frankfurter Entsorgungs- und Service GmbH was affected by a cyberattack on a Darmstadt-based IT service provider that it uses, leading the company to disconnect its connected servers and cut the link to the provider as a precaution. Although customer data remained uncompromised and essential services such as waste collection, street cleaning and the waste-to-energy plant continued without interruption, online bulk waste registration and access to the customer portal were temporarily unavailable, requiring orders to be placed only by email, fax or phone, and other organizations sharing the same provider—including a regional energy utility and a municipal works group—experienced comparable disruptions to their online services.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 5 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On Sunday June 12 2022 the IT‑attack on a Darmstadt data‑center operator became known and it was reported that the Frankfurter Entsorgungs‑ und Service‑Gruppe (FES) was also affected because the same IT service provider was used by both organisations. As a precautionary measure FES took all servers that were connected to the service provider offline and severed the connection to the provider. The company stated that, according to the information available at that time, no customer data had been compromised. FES emphasized that it was prepared for such an incident and that the reachability of the corporate group remained ensured.

All municipal services provided by FES, including waste collection, street cleaning and the operation of the waste incineration plant (MHKW) as well as other disposal facilities, continued to function without restriction. However, the online registration for new bulky waste orders and access to the customer portal KundenPlus were temporarily unavailable, forcing customers to place orders only by e‑mail, fax or telephone. FES warned that, in the following days, delays could occur for commercial services. The same IT service provider is also used by Mainzer Stadtwerke, which reported that its websites for Mainzer Mobilität and the Taubertsbergbad swimming pool as well as internal e‑mail servers were not reachable, although its separately protected critical infrastructure for electricity, gas and water remained unaffected. The Darmstadt energy provider Entega disclosed that the attack had mainly affected the e‑mail accounts of roughly 2000 employees and its corporate websites, while its electricity, gas and water supplies were secured and no risk of supply outages existed.
FES reiterated that the duration of the current situation depends on when the Darmstadt data‑center operator can resume normal operations and that the existing restrictions are expected to last at least until the end of the week. The company confirmed that it remained in contact with its customers and that all communication channels stayed open. No further details about the attackers or their motives were provided in the sources.
