CSIDB logo
Incident

Braunau am Inn

Incident posture

Attack window
Dec 2020
Location
Austria
Status
Historical
CIA posture
Available to members
Updated
2025-12-07 00:00

Linked entities

Victim
Braunau am Inn
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeted the municipal IT servers of Braunau am Inn, encrypting all stored data and rendering systems inaccessible. The perpetrators did not respond to decryption demands, leaving the scope of compromised information unclear, though potential exposure of personal data to third parties could not be ruled out. Local authorities immediately notified relevant agencies while maintaining operational continuity through existing backup copies. The identity and motives of the attackers remained undetermined at the time of reporting.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around December 6, 2020, the municipal IT servers of Braunau am Inn, Austria, experienced a disruptive cyberattack confirmed by Mayor Johannes Waidbacher and City Office Director Andreas Reiter. The attackers encrypted all data stored on the compromised servers, rendering it inaccessible to town hall operations. Municipal authorities immediately notified relevant law enforcement and regulatory bodies about the incident, though neither the identity of the perpetrators nor specific technical details of the attack vector were disclosed publicly. The hackers did not engage with the municipality’s attempts to communicate regarding decryption demands, leaving data restoration efforts dependent on internal recovery processes. Officials acknowledged the attack caused operational chaos within town hall functions but emphasized continuity measures were activated to mitigate disruptions.

The incident raised concerns about potential unauthorized access to sensitive information, with the city office stating it could not rule out that personal data had been exfiltrated or obtained by third parties. Despite the encryption of primary systems, Mayor Waidbacher assured the public that backup copies of data remained intact, enabling the municipality to maintain access to essential records and resume services. No further details regarding the scope of affected systems, the duration of downtime, or specific types of compromised personal data were provided in initial confirmations. The investigation remained ongoing with authorities at the time of reporting, focusing on attribution and forensic analysis of the attack. Recovery efforts prioritized restoring operational capabilities through backup data while addressing potential data exposure risks.

Sources

Sources available to members: 1 source.

CSIDB