Cyber Incident Victim: Högskolan Väst
Date:
Jan 2024
Location:
Sweden
Summary
Högskolan Väst experienced a service disruption affecting access to its Primula system due to an outage at an external provider. The institution confirmed the operational impact while acknowledging that vendor TietoEvry was actively working to resolve the technical issue, though no further details about the cause or restoration timeline were disclosed.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On January 20, 2024, Högskolan Väst experienced a service disruption affecting access to Primula, a critical system utilized by the university community. The interruption stemmed from an outage at an external service provider, TietoEvry, which manages or supports aspects of Primula's infrastructure. This dependency on third-party infrastructure directly prevented users from accessing Primula's functionalities during the incident timeframe. The university promptly acknowledged the disruption through a public statement on its official website, confirming the operational impact and attributing the cause to the external provider's technical failure. No further technical details regarding the nature of TietoEvry's outage—such as its root cause, duration, or specific infrastructure components affected—were disclosed in the initial communication.

TietoEvry assumed responsibility for troubleshooting and resolving the underlying issue causing the Primula service interruption. Högskolan Väst's public communication focused solely on confirming the provider's engagement in remediation efforts without elaborating on collaborative incident response protocols, internal mitigation steps, or interim workarounds for affected users. The university's statement did not specify the operational scope of the disruption, such as whether all Primula functions were impaired or if partial access remained available. Similarly, no details were provided regarding the incident's detection timeline, potential data or process impacts on academic or administrative operations, or expected resolution timeframe. The public notification emphasized transparency regarding the outage's existence and external origin but maintained minimal technical or procedural specificity throughout the disclosed information.
