CSIDB logo
Incident

Hochschule Ruhr West

Incident posture

Attack window
Jan 2023
Location
Germany
Status
Historical
CIA posture
Available to members
Updated
2026-01-07 14:46

Linked entities

Victim
Hochschule Ruhr West
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hochschule Ruhr West experienced a cyberattack prompting complete disconnection of its IT systems to contain the incident, resulting in widespread service unavailability across most institutional platforms. IT teams are prioritizing system restoration while maintaining strict prohibitions against using institutional workstations or personal devices for university-related activities, with operational updates disseminated through a dedicated offline communication channel managed by an active crisis response team.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

6 techniques

Description

On January 31, 2023, Hochschule Ruhr West (HRW) experienced a significant disruption to its IT infrastructure following an external cyber attack. The institution proactively disconnected all systems from the internet as a containment measure, rendering most university services unavailable. HRW established a dedicated offline website ("HRW-offline") as its primary communication channel, emphasizing its role as the central, reliable information source for all university members during the incident. Initial updates confirmed the cyber attack's occurrence and outlined immediate operational restrictions, including a strict prohibition against powering on or using official work computers. The IT department began working intensively to restore systems but provided no specific timeline for full recovery.

The crisis management team activated promptly to coordinate response efforts, with plans to deliver phased updates to different stakeholder groups through the HRW-offline platform. As of February 3, 2023, the university reiterated that work devices remained prohibited from use and explicitly banned the utilization of personal computers for official tasks. HRW scheduled its next formal update for the following Monday, indicating an ongoing assessment process. No technical details regarding the attack vector, attacker identity, or data compromise were disclosed in the available communication. Service restoration efforts continued without public specification of affected systems beyond the broad impact on "most services." The institution maintained its focus on containment through network isolation and enforcing device usage restrictions throughout the initial response phase.

Sources

Sources available to members: 1 source.

CSIDB