Cyber Incident Victim: Westbahn
Date:
Oct 2023
Location:
Austria
Summary
Westbahn experienced a cyber incident that affected its IT systems, particularly administrative systems, after which attackers gained access and it could not be ruled out that business, employee and customer data were exfiltrated; the company does not process credit card data as this is handled by external payment providers, and operational rail services remained unaffected. Authorities were notified and an investigation involving internal and external experts is underway to determine the full scope and improve future defenses.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On Thursday, 19 October 2023, Westbahn experienced a cyber incident affecting its IT systems, specifically the administration division. The company reported that an unauthorized party gained access to its systems and that data exfiltration could not be ruled out. According to Westbahn, the potentially accessed information includes business, employee, and customer data, while credit card data are not processed by the company and are handled by external payment service providers. The incident did not disrupt the railway operation, and trains continued to run according to the scheduled timetable.

In response, Westbahn deployed an internal expert team that immediately took measures to stop the attack. Following the containment, the IT department, supported by external specialists, commenced a thorough investigation to determine the scope of the breach and to improve defenses against similar threats. Westbahn notified the relevant data protection authorities in accordance with legal obligations and established a dedicated hotline and email address for inquiries related to the incident. The company also published a FAQ section addressing questions about the perpetrators, the types of data involved, and the status of remedial work.
Westbahn emphasized that the operational aspects of the business, including ticket sales and train services, remained unaffected throughout the event. The organization stated that, based on the information available at the time, there was no evidence that passwords had been stolen, although it continued to monitor for any signs of misuse of the accessed data. Ongoing efforts focus on securing the affected systems and restoring full confidence in the IT environment, with further legal steps reserved as deemed necessary. The company affirmed that it would continue to update stakeholders as the investigation progresses.
