CSIDB logo
Incident

Bayerische Staatsregierung

Incident posture

Attack window
Feb 2025
Location
Germany
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 12:19

Linked entities

Victim
Bayerische Staatsregierung
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A distributed denial-of-service attack disrupted the websites of the Bavarian state government, primarily affecting the State Chancellery and the Ministry for Digital Affairs, as well as the Bavarian Police web presence, the Munich District Office, and the city of Garching. The State Office for Information Security assessed the incident as highly likely linked to pro-Russian hacktivism, though the State Criminal Police Office stated it could not determine any connection to the Munich Security Conference. The affected sites were temporarily unavailable for roughly one day, but no damage occurred, and no data was exfiltrated or encrypted. The incident has been handed over to law enforcement for criminal investigation and prosecution.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Thursday, the websites of the Bavarian State Government were targeted in a cyberattack that authorities later attributed with high probability to "pro-Russian hacktivism." According to the Bavarian State Office for Information Security (Landesamt für Sicherheit in der Informationstechnik), the Staatskanzlei (State Chancellery) and the Staatsministerium für Digitales (State Ministry for Digital Affairs) were both affected. The attack was identified as a Distributed Denial-of-Service (DDoS) attack, in which malicious traffic is directed at a target to overwhelm its infrastructure and make services temporarily unavailable. As a result, the affected websites were unreachable for a limited period, but no data or information was exfiltrated, and no systems were encrypted. Authorities confirmed that no actual damage occurred as a consequence of the intrusion. The Landesamt für Sicherheit in der Informationstechnik disclosed these findings in response to a dpa inquiry on Sunday evening, February 16.

In addition to the disruption of the State Chancellery and the State Ministry for Digital Affairs, irregularities were also observed on the internet presence of the Bavarian Police, as confirmed by the Landeskriminalamt (LKA) to Bayerischer Rundfunk. The websites of the Munich Landratsamt (district office) and the city of Garching were also unreachable for approximately one day, indicating that the impact of the attack extended beyond the directly named state institutions. The LKA stated that it could not assess whether the attack was connected to the Munich Security Conference, which was taking place around the same period, and noted that investigations were ongoing at the time of reporting. The broadening scope of affected public-facing services suggested a coordinated effort rather than an isolated incident, even though the technical mechanism employed was a disruption-oriented attack rather than a data-destructive operation.

The response to the incident was led by the Bavarian State Office for Information Security, which conducted the analysis of the attack and confirmed its classification as a Distributed Denial-of-Service event. Once the analysis was complete, the matter was to be handed over to law enforcement authorities for criminal prosecution, as the office stated. The involvement of the Landeskriminalamt reflected the criminal dimension attributed to the activity, given that DDoS attacks against public infrastructure constitute prosecutable offenses under German law. While the article did not specify the exact duration of the initial disruption to the State Chancellery and State Ministry for Digital Affairs websites, it confirmed that service was restored without lasting impact. The Bavarian State Government's digital services continued to function normally following the restoration, and the authorities maintained that no sensitive or personal information had been compromised during the incident. The investigation remained open, with authorities working to identify the specific actors behind the pro-Russian hacktivist activity that was suspected of orchestrating the attack.

Sources

Sources available to members: 1 source.

CSIDB