CSIDB logo
Incident

Prefeitura da Cidade do Rio de Janeiro

Incident posture

Attack window
Aug 2022
Location
Brazil
Status
Historical
CIA posture
Available to members
Updated
2026-02-09 01:05

Linked entities

Victim
Prefeitura da Cidade do Rio de Janeiro
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Aug 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Prefeitura do Rio suffered a cyberattack that disrupted municipal systems and online services, prompting the city hall to take all portal services offline preventively to protect data. Officials worked to restore operations while directing citizens to alternative information channels and social media for updates on affected services. The incident was reported to specialized law enforcement for investigation, with authorities emphasizing efforts to re-establish secure systems and acknowledging inconveniences caused to residents.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On August 15, 2022, the Prefeitura do Rio (Rio de Janeiro City Hall) experienced a cyberattack targeting its systems in the early hours of the morning. The attack prompted the immediate preventive shutdown of all services on the City Hall Portal to protect data integrity. This disruption affected multiple municipal functions, though specific compromised systems or attacker methodologies were not disclosed in public statements. The City Hall confirmed the incident on its official website, displaying a denial message with a support ID (11680853147542033528) for citizens needing assistance. Officials registered the incident with the Police Department for Repression of Computer Crimes (DRCI) to initiate a criminal investigation aimed at identifying and prosecuting the perpetrators. Initial communications emphasized efforts to minimize inconvenience to residents ("cariocas") while restoring operations securely.

By August 19, 2022, the City Hall provided updates via Twitter, directing citizens to its website for guidance on accessing services impacted by the attack. The municipality acknowledged ongoing work to re-establish systems within a "secure digital environment" and reiterated regret for disruptions caused. No data theft or ransomware demands were mentioned in available sources. The DRCI’s investigation remained active, with no public attribution to threat actors. Service restoration timelines and technical mitigation details were not specified, though social media channels served as the primary outlet for public updates. The incident underscored operational dependencies on digital systems, requiring manual alternatives for some citizen interactions during the outage.

Sources

Sources available to members: 2 sources.

CSIDB