Cyber Incident Victim: Hochschule Kempten
Date:
Feb 2024
Location:
Germany
Summary
A cyberattack compromised portions of Hochschule Kempten's IT infrastructure, prompting immediate containment measures including system access restrictions and communication limitations. External email remains inoperable while telephony functions, and student-facing platforms like Zoom, evasys, and Moodle are inaccessible—though the "Mein Campus" portal remains operational. Authorities were notified, and restoration timelines remain undetermined as response teams work to mitigate the incident. Updates are disseminated via the institution's homepage and internal channels for stakeholders.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On February 27, 2024, Hochschule Kempten experienced a cyberattack targeting its IT infrastructure. Despite the institution's implementation of what it described as "very high security precautions," unauthorized actors successfully compromised portions of its systems. The attack prompted immediate containment measures, including the lockdown of multiple IT systems and restrictions on communication infrastructure to prevent further unauthorized access. University officials notified law enforcement and relevant regulatory authorities following the breach. At the time of reporting, technical teams were actively working to contain the intrusion, though the full scope of compromised systems and data remained unconfirmed. External email communications became completely inaccessible, while telephone systems maintained functionality throughout the incident.

The cyberattack disrupted critical academic platforms, preventing student access to Zoom video conferencing, the evasys evaluation system, and the Moodle learning management system. The "Mein Campus" portal remained operational as an exception, serving as a primary information channel alongside the university's main website. Internal communications for faculty and staff shifted to the PIIPE intranet platform due to email outages. University administrators explicitly stated they could not estimate restoration timelines for affected services, citing the ongoing investigation and remediation efforts. Continuous updates were promised through designated digital channels, with no secondary communication methods referenced in the initial disclosure. The institution maintained its operational status for non-IT-dependent functions while forensic analysis continued to determine the attack's origin and full impact.
