CSIDB logo
Incident

Landesportal Sachsen-Anhalt

Incident posture

Attack window
Aug 2025
Location
Germany
Status
Resolved
CIA posture
Available to members
Updated
2026-08-13 04:23

Linked entities

Victim
Landesportal Sachsen-Anhalt
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jul 2025
Discovered
Undetermined
Disclosed
Aug 2025
Resolved
Aug 2025

Summary

Distributed denial of service attacks targeted several government and political websites in the region, including the Landesportal Sachsen‑Anhalt, rendering them temporarily inaccessible. The assaults flooded servers with excessive requests, prompting the responsible IT service provider to take affected systems offline and restore them after mitigation, while existing security measures continued to operate.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In July several ministry websites in Saxony‑Anhalt experienced temporary unavailability due to overload attacks, a pattern confirmed by a spokesperson from the Ministry for Infrastructure and Digital Affairs in Magdeburg who noted a corresponding alert from the Federal Office for Information Security. The attacks were identified as Distributed Denial of Service (DDoS) incidents in which servers were flooded with massive volumes of requests, rendering them intermittently unreachable. In addition to the ministry sites, the Landesportal Sachsen‑Anhalt was repeatedly affected, showing noticeable network churn and temporary inaccessibility for certain user groups. By August the wave of attacks extended to the online presences of the state parliamentary factions of the CDU, AfD and SPD, which were also reported as being temporarily offline.

The Landesportal Sachsen‑Anhalt continued to suffer intermittent outages, with the portal being unavailable for specific user groups during the August period. The CDU faction’s website, among others, was taken offline, prompting CDU parliamentary leader Guido Heuer to state that the attacks were suspected to originate from Russia and to describe coordinated action with the party’s IT service provider that included shutting down the affected server. Heuer added that the website had since been restored and was reachable again within Germany. The Greens’ parliamentary faction reported that their website was targeted on 13 August, noting that the attack was detected with the assistance of their technical provider and that the integrity of their systems was secured, although they characterized the incident as a warning shot from a pro‑Russian DDoSia network.

Response actions included the ministry’s acknowledgment of the DDoS nature of the incidents and the reference to the federal security alert, the CDU’s collaboration with its IT provider to shut down and later restore its server, and the Greens’ reliance on their technical provider to detect and mitigate the attack on 13 August. Throughout the episode, affected entities described the attacks as overload attempts that temporarily disrupted access but did not result in lasting damage to the underlying systems. The repeated targeting of the Landesportal Sachsen‑Anhalt and multiple party faction sites highlighted a sustained pattern of disruptive activity against digital infrastructure in the state during the summer months.

Sources

Sources available to members: 1 source.

CSIDB