Cyber Incident Victim: Museum für Naturkunde Berlin
Date:
Oct 2023
Location:
Germany
Summary
The Museum für Naturkunde Berlin experienced a cyberattack disrupting its email systems, prompting an ongoing analysis of the incident's scope by a crisis team collaborating with investigative authorities. While staff remain reachable by phone, standard email communications are unavailable, and the institution is establishing a centralized telephone service for public inquiries while providing updates via its website.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On October 20, 2023, the Museum für Naturkunde Berlin (MfN), a Leibniz Institute for Evolution and Biodiversity Research, publicly disclosed it was affected by a cyber attack. The institution activated a crisis team to analyze the scope and severity of the incident, collaborating with relevant law enforcement agencies. While the technical nature of the attack and initial intrusion vector were not specified in the announcement, the disruption caused immediate operational consequences. The museum confirmed its employees could no longer be reached via their standard email addresses, indicating a compromise or shutdown of email systems. Phone communications remained functional, with the museum directing external contacts to find individual numbers through its team directory. Visitor inquiries faced temporary limitations, prompting the establishment of a dedicated central telephone line to address general public concerns.

The museum prioritized transparency by committing to publish ongoing updates about the situation directly on its official website, signaling an expectation of prolonged recovery or investigation efforts. No details were provided regarding potential data breaches, collection accessibility, research project impacts, or the duration of expected downtime. The immediate response focused on maintaining basic communication channels while forensic analysis proceeded. The involvement of investigative authorities suggested potential criminal attribution efforts or evidence gathering, though no suspects or motives were disclosed. The incident underscored the vulnerability of cultural and scientific institutions to cyber threats capable of disrupting core administrative functions and public engagement. Mitigation efforts centered on alternative contact methods and public advisories while internal assessments determined the full ramifications of the attack.
