CSIDB logo
Incident

Brekom

Incident posture

Attack window
Feb 2025
Location
Germany
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 13:46

Linked entities

Victim
Brekom
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

In a series of cyber incidents targeting Bremen-based authorities, a pro-Russian hacker group called NoName057(16) carried out a successful Distributed Denial-of-Service attack against the Bremen Police website, bombarding its contact form with up to 18,000 requests per minute and rendering the broader Bremen administration websites largely unreachable for approximately an hour and a half. The federal criminal police (BKA) subsequently took over central investigations into the group, which had claimed responsibility on Telegram and is known for targeting perceived Ukraine supporters. Two earlier DDoS attempts in January against the Health Senator's and economic development agency websites had no impact, while a separate phishing attack later compromised two email accounts within the school administration, enabling spam distribution from an official address. Another incident involving botnet-related spam abuse through manipulated contact forms had also occurred previously. No data theft, loss, or compromise resulted from the DDoS attack, and automated throttling measures have since been implemented.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

Between January and February 2025, public authorities in Bremen, Germany, were targeted by a series of cyberattacks, with five incidents recorded over a four-month period. The earliest attempts took place in January 2025 and consisted of two Distributed Denial-of-Service (DDoS) attacks directed at the websites of Bremen's health senator and the local economic development agency. Both attempts failed to produce any noticeable impact. In these DDoS attacks, the targeted servers are overwhelmed by a high volume of simultaneous requests, causing them to cease functioning and rendering the affected web pages inaccessible to legitimate users. A third unsuccessful DDoS attempt occurred later in January, and a fourth failed attack targeted another Bremen authority site during the same period. Bremen authorities did not identify a connection between these four unsuccessful incidents and later events, nor did they interpret them as specifically directed against the Bremen administration. According to the Senate, Germany as a whole is a frequent target of diverse cyber operations, and the attacks were understood as part of broader hostile activity rather than as focused action against Bremen in particular.

The most consequential incident occurred on 12 February 2025, when a DDoS attack successfully disrupted the website of the Bremen Police. At approximately 07:00, the contact form hosted on the police website was bombarded with up to 18,000 requests per minute, and the underlying server ultimately failed under the load. As a consequence, web pages belonging to the broader Bremen administration became partially unreachable or only intermittently accessible until roughly 08:30 that morning. The attack itself continued into the evening, but the Senate reported that the assault was repelled after about two hours. The IT service provider Dataport, which is responsible for information technology across Bremen's authorities, identified the contact form and the local search function on the police website as the entry points used to overwhelm the system and disabled both features. Shortly after nine o'clock on the same morning, while the attack was still in progress, Bremen received a warning from the German Federal Office for Information Security (BSI) regarding the ongoing assault. On the same day, the pro-Russian hacker group NoName057(16) publicly claimed responsibility for the cyberattack. NoName057(16) has been active since the beginning of the Russian invasion of Ukraine and has conducted attacks against targets in Ukraine, the United States, and several other European countries. The group typically targets websites of government agencies, media organizations, and private companies, and it publishes current attack targets on the Telegram messaging service, which was likely the source of the BSI's prior knowledge. The group's stated objective is to disrupt supporters of Ukraine while disseminating Russian propaganda. Central investigations into NoName057(16) are now being conducted by the German Federal Criminal Police Office (Bundeskriminalamt). The Senate emphasized that the February attack did not result in any data theft, data loss, or compromise of information.

In response to the successful February DDoS attack, a software update was rolled out later that month with the aim of preventing similar future incidents. The update introduced an automatic throttling mechanism that activates when repeated attacks target internal search functions or contact forms, gradually reducing the number of accepted requests and, if necessary, deactivating the affected function entirely. Beyond the DDoS activity, Bremen authorities also faced additional cyber incidents in the same general timeframe, though the Senate did not link these to the DDoS campaign. In late February, a phishing attack against employees of the school administration was successful, enabling the attackers to take over two accounts within the mail system. The compromised accounts were then used to send out spam using the sender address @schulverwaltung.bremen.de. Earlier, in mid-December 2024, a separate incident described as botnet spamming had already been publicly known. In that case, manipulation of contact forms on the affected websites was used to distribute large volumes of spam, the collective term covering mass unsolicited emails, electronic chain letters, and unwanted advertising posts. Details of the five attacks, including the timeline, the successful February police website disruption, and the subsequent defensive measures, became publicly known through the Senate's responses to a parliamentary inquiry (Kleine Anfrage) submitted by the CDU parliamentary group regarding the February incident.

Sources

Sources available to members: 1 source.

CSIDB