Stadt Halberstadt
Incident posture
Linked entities
- Victim
- Stadt Halberstadt
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
The internet portal of the city administration was hit by a DDoS attack that flooded the web server with automated requests from changing IP addresses, rendering the site inaccessible for several hours. The attack was detected in the morning and the service provider was notified, leading to mitigation efforts that restored regular access by the afternoon. Officials confirmed that internal IT systems were not endangered and no data breach or compromise was found. The incident was reported to CERT Nord, and further steps are being coordinated with the provider and security authorities.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On Tuesday, 29 July 2025, the internet portal of the city administration Halberstadt was inaccessible for several hours due to a targeted cyber‑attack on the technical infrastructure of the service provider that operates the web presence. The attack was identified as a distributed denial of service (DDoS) attack, in which the web server was overwhelmed by a large volume of automated requests originating from constantly changing IP addresses. The objective of the attack was to disrupt the availability of the system, not to gain unauthorized access or exfiltrate data. The city's IT department detected the incident at approximately 08:15 hours and immediately notified the responsible service provider. Upon notification, the service provider commenced defensive measures aimed at mitigating the traffic overload and restoring service availability. By around 15:00 hours, the municipal website was again regularly accessible to users.
Regional media reported that the attack was part of a coordinated action affecting multiple municipal internet presences in Saxony‑Anhalt. The internal IT systems of the city of Halberstadt were never endangered throughout the incident. Based on the current assessment and joint evaluations conducted with the service provider, there is no evidence of a compromise or any data exfiltration. Following the restoration of the portal, the city administration formally reported the incident to the Computer Emergency Response Team North (CERT Nord). The administration indicated that it will continue to coordinate further steps with the service provider and the relevant security authorities to ensure appropriate follow‑up actions.
Sources
Sources available to members: 1 source.