CSIDB logo
Incident

AbfallWirtschaftsGesellschaft mbH

Incident posture

Attack window
Apr 2024
Location
Germany
Status
Historical
CIA posture
Available to members
Updated
2025-12-31 18:09

Linked entities

Victim
AbfallWirtschaftsGesellschaft mbH
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Apr 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyber attack targeted a waste management company, causing a two-week disruption to phone services and online functions including bulk waste registration. The organization implemented extensive security measures, isolating affected systems and taking the entire network offline while establishing temporary mobile contacts for limited customer support. Initial communication was intentionally restricted to deny attackers operational insights. Forensic analysis confirmed the firewall successfully repelled the intrusion, with no compromise of customer data. Internal crisis management teams coordinated technical and operational responses across departments, maintaining service continuity while preventing data exfiltration. Customer interactions during the outage reportedly demonstrated widespread understanding of the imposed limitations.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In early May 2024, AbfallWirtschaftsgesellschaft (AWG) Bassum experienced a two-week operational disruption caused by a cyber attack. The incident rendered all company landline phones unreachable and disabled online services, including the ability to schedule bulky waste pickups. AWG spokesperson Dominik Albrecht confirmed the cyber attack’s role in the outage but emphasized that extensive preemptive security measures and rapid response actions prevented any compromise of customer data. The organization deliberately avoided public transparency during the incident to deny attackers insights into their mitigation efforts, though limited customer service was maintained via newly established mobile phone lines. AWG immediately convened a crisis management team and disconnected the entire corporate network as a precautionary containment measure. IT Director Lennart Pleuß isolated the targeted firewall and initiated forensic analysis by external experts. Investigators determined the attack failed to penetrate the firewall, validating the effectiveness of existing security protocols. Full connectivity and service availability were restored by mid-May following system validation.

The response involved coordinated efforts across multiple departments. Forensic specialists conducted granular examinations of the firewall and IT infrastructure, confirming no lateral movement or data exfiltration occurred. Management acknowledged the deliberate network shutdown as an extreme but necessary step given initial uncertainty about the attack’s scope. Sebastian Koch of AWG’s executive leadership credited the IT and electrical engineering teams for their weekend work implementing safeguards that prevented data breaches. Operational units like fleet management and customer service adapted workflows to maintain partial functionality during the outage. Koch noted widespread customer understanding despite service limitations, publicly thanking clients for their patience. Internal reviews confirmed no secondary infections or persistent threats remained post-recovery. The organization expressed satisfaction with its incident handling, particularly the decision to prioritize containment over public disclosure during active response phases.

Sources

Sources available to members: 2 sources.

CSIDB