Cyber Incident Victim: Sveriges lantbruksuniversitet
Date:
Jan 2024
Location:
Sweden
Summary
Sveriges lantbruksuniversitet experienced technical disruptions affecting internal systems including Primula, Besched, and employee web platforms, marked as urgent. The incident involved accessibility issues requiring users to enable JavaScript for proper functionality, with resolution statuses documented but no explicit details on root causes or data compromise provided.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 6 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On January 20, 2024, Sveriges lantbruksuniversitet (SLU) publicly acknowledged an operational disruption affecting its Primula and Besched systems through an internal IT communication platform. The incident prompted an urgent status designation, indicating significant disruption to university operations. Technical details confirmed the Medarbetarwebben (Employee Web) platform as a directly impacted system, though the full scope of affected services remained unspecified in the available documentation. Users attempting to access university resources encountered technical obstacles requiring JavaScript activation and browser configuration adjustments, suggesting potential authentication or service delivery failures. No explicit reference to malicious activity appeared in the published notice, leaving the incident's root cause undefined in the public record.

SLU's IT department responded by issuing procedural guidance for affected personnel, instructing them to enable scripting functionality and refresh browser sessions to restore access. The institution confirmed resolution of the incident with a status marker indicating completion, though no specific restoration timestamp or detailed containment methodology was disclosed. The communication framework utilized SLU's established Driftinfo (Operational Info) reporting system to disseminate incident details, adhering to predefined fields for reporting timelines, affected systems, and resolution status. No quantitative impact assessments regarding operational downtime, compromised data, or user productivity loss were included in the primary source material. The absence of subsequent updates or severity escalations within the provided documentation suggests the incident was resolved without further public escalation through this channel.
