CSIDB logo
Incident

Museum für Naturkunde Berlin

Incident posture

Attack window
Oct 2023
Location
Germany
Status
Historical
CIA posture
Available to members
Updated
2026-01-26 13:11

Linked entities

Victim
Museum für Naturkunde Berlin
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Museum für Naturkunde Berlin experienced a cyberattack disrupting its email systems, prompting an ongoing analysis of the incident's scope by a crisis team collaborating with investigative authorities. While staff remain reachable by phone, standard email communications are unavailable, and the institution is establishing a centralized telephone service for public inquiries while providing updates via its website.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On October 20, 2023, the Museum für Naturkunde Berlin (MfN), a Leibniz Institute for Evolution and Biodiversity Research, publicly disclosed it was affected by a cyber attack. The institution activated a crisis team to analyze the scope and severity of the incident, collaborating with relevant law enforcement agencies. While the technical nature of the attack and initial intrusion vector were not specified in the announcement, the disruption caused immediate operational consequences. The museum confirmed its employees could no longer be reached via their standard email addresses, indicating a compromise or shutdown of email systems. Phone communications remained functional, with the museum directing external contacts to find individual numbers through its team directory. Visitor inquiries faced temporary limitations, prompting the establishment of a dedicated central telephone line to address general public concerns.

The museum prioritized transparency by committing to publish ongoing updates about the situation directly on its official website, signaling an expectation of prolonged recovery or investigation efforts. No details were provided regarding potential data breaches, collection accessibility, research project impacts, or the duration of expected downtime. The immediate response focused on maintaining basic communication channels while forensic analysis proceeded. The involvement of investigative authorities suggested potential criminal attribution efforts or evidence gathering, though no suspects or motives were disclosed. The incident underscored the vulnerability of cultural and scientific institutions to cyber threats capable of disrupting core administrative functions and public engagement. Mitigation efforts centered on alternative contact methods and public advisories while internal assessments determined the full ramifications of the attack.

Sources

Sources available to members: 1 source.

CSIDB