CSIDB logo
Incident

Lotto Berlin

Incident posture

Attack window
Dec 2022
Location
Germany
Status
Historical
CIA posture
Available to members
Updated
2025-10-15 00:00

Linked entities

Victim
Lotto Berlin
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeting Lotto Berlin's website resulted in temporary downtime following suspicious access attempts observed around New Year's Eve and New Year's Day. The organization took its website offline preemptively to safeguard player data after detecting repeated unauthorized efforts to access personal information using email addresses and password brute-forcing attempts. The incident also disrupted lottery websites in Rheinland-Pfalz, Sachsen-Anhalt, and Schleswig-Holstein. Service was restored after the malicious activity was mitigated.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Lotto Berlin website experienced a cyberattack that disrupted operations between late December 2022 and January 1, 2023. Suspicious access attempts were first detected following the Christmas holidays, with intensified activity occurring specifically on New Year's Eve and New Year's Day. These anomalous login attempts involved repeated password entry efforts and targeted email addresses, indicating attempts to compromise user accounts. On January 1, Lotto Berlin's website became completely inaccessible as the company proactively took their systems offline in response to the security incidents. The outage lasted several hours before service restoration. Company spokesperson Thomas Dumke confirmed the defensive measure was implemented to protect player data, citing the unusual access patterns as justification for the temporary shutdown.

The attack affected multiple regional lottery platforms beyond Berlin, including operations in Rhineland-Palatinate, Saxony-Anhalt, and Schleswig-Holstein. Attackers focused on obtaining personally identifiable information through credential-based attacks against customer accounts. No data breaches were confirmed, though the intrusion attempts specifically targeted sensitive player information. Lotto Berlin maintained service interruption as their primary containment measure against the ongoing attack vectors. The incident resulted in temporary loss of online lottery services across affected regions during the peak holiday period, with normal operations resuming after security interventions. Financial impacts and exact attacker methodologies were not disclosed in initial reports.

Sources

Sources available to members: 1 source.

CSIDB