CSIDB logo
Incident

Radio Geretsried

Incident posture

Attack window
Sep 2024
Location
Germany
Status
Unknown
CIA posture
Available to members
Updated
2025-12-27 00:00

Linked entities

Victim
Radio Geretsried
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A significant cyberattack originating from the Russian region targeted the broadcast systems of Radio Geretsried, encrypting all music files and demanding a substantial ransom payment. The attack forced the station to operate on an emergency loop while technical teams worked to restore services by exporting salvageable data and rebuilding compromised systems from scratch. Recovery efforts were expected to extend into mid-week due to the severity of the compromise, with full restoration requiring extensive reconfiguration of infrastructure. The incident caused prolonged disruption to regular programming, impacting listener access until systems could be fully reinstated.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On the night leading to Sunday, September 15, 2024, unidentified attackers originating from the Russian region launched a disruptive cyberattack against Radio Geretsried’s core broadcast infrastructure. The assailants compromised the station’s transmission systems, encrypting all stored music files and rendering them inaccessible. This sabotage forced the station to switch to an emergency broadcast loop, depriving listeners of regular programming. The attackers issued a ransom demand to the station, though the exact financial amount was not disclosed in public communications. Radio Geretsried’s management team and the executive board of Bürgernetz Isar-Loisach e.V., the parent association overseeing the station, immediately initiated crisis response protocols. Technical staff worked to isolate affected systems to prevent further spread of the encryption malware. Initial assessments confirmed the attack targeted the station’s "heart" systems, specifically the music libraries and broadcast automation tools essential for daily operations.

The station’s music editorial team began exporting surviving playlists and recoverable data from uncompromised backups or secondary storage. Leadership announced plans to completely rebuild all infected systems from the ground up rather than attempting decryption or paying the ransom. This restoration process required significant time and resources, with service disruptions projected to persist until at least midweek following the attack. Radio Geretsried prioritized transparency, pledging to provide recovery updates through its website and Facebook page once operations normalized. The incident caused sustained operational downtime, impacting the station’s ability to deliver scheduled content and maintain audience engagement. No secondary disruptions to adjacent networks or partner stations were reported, suggesting the attack’s scope remained confined to Radio Geretsried’s primary broadcast infrastructure.

Sources

Sources available to members: 1 source.

CSIDB