Cyber Incident Victim: Landkreis Mayen-Koblenz
Date:
May 2023
Location:
Germany
Summary
A cyberattack disrupted street lighting systems in Mayen, affecting the municipality's core city and surrounding districts. The incident caused operational outages impacting public infrastructure, with local authorities acknowledging the disruption and requesting public understanding while addressing the issue. No further technical details about the attack vector or responsible actors were disclosed in available reports.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On May 1, 2023, the city of Mayen within Germany's Landkreis Mayen-Koblenz experienced disruptions to its street lighting infrastructure following a confirmed cyberattack. The incident impacted illumination systems across Mayen's core urban area and its surrounding districts, though the specific technical mechanism of the attack and full geographic scope remained unspecified in municipal communications. City administrators acknowledged the cyber incident as the direct cause of the outages but did not disclose whether the disruption resulted from ransomware, denial-of-service attacks, or other intrusion methods. No threat actor claimed responsibility, and officials provided no details regarding initial intrusion vectors, malware signatures, or data compromise. The outage necessitated public advisories from Mayen's city administration urging residents to exercise caution in affected areas due to reduced nighttime visibility.

The Stadtverwaltung Mayen issued a formal statement on May 1 confirming the cyberattack's role in the infrastructure failure while requesting public understanding during restoration efforts. Municipal authorities did not specify remediation timelines, containment measures, or whether backup systems were activated to restore lighting functionality. Technical details regarding affected systems—such as whether attackers compromised supervisory control and data acquisition (SCADA) systems, programmable logic controllers (PLCs), or municipal network backbones—were not disclosed. The city's communications emphasized operational impacts over forensic findings, noting only the essential fact of cyberattack causation without elaborating on incident response protocols or coordination with national cybersecurity agencies. Restoration progress remained unquantified in initial reports, leaving the duration of outages and secondary consequences like traffic safety risks unaddressed beyond the general advisory for citizen vigilance.
