CSIDB logo
Incident

VUCKE

Incident posture

Attack window
Sep 2023
Location
Slovakia
Status
Unknown
CIA posture
Available to members
Updated
2026-10-04 05:12

Linked entities

Victim
VUCKE
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The regional authority reported unusual activity in its computer network that was assessed as a cybersecurity incident, suspected to be ransomware similar to an earlier attack. To prevent data loss or corruption, ICT services were temporarily shut down and external access blocked, with essential functions maintained via backup systems. The incident was forwarded to the national CSIRT and security authority for analysis, and efforts are underway to collect digital evidence and restore services safely.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Tuesday, September 5, 2023, the Office of the Košice Self-Governing Region detected unusual activities in its computer system, which were evaluated as a cybersecurity incident. The incident was identified as a ransomware attack similar to the one that occurred in October 2021. In response, the office managed the availability of its ICT systems in a controlled manner and, for preventive reasons, shut down the systems to prevent data leakage or damage. Additional operational measures were taken to protect sensitive information. The office stated that it has cyber protection measures for its electronic networks and that after the previous hacker attack a cybersecurity audit had been performed.

As a result, electronic services of the office were temporarily non‑functional, and accesses from the external environment as well as the electronic system were shut down. The shutdown also partially affected regional organizations whose systems are connected to the office. The office reported the incident to the Governmental Unit for Solving Computer Incidents (CSIRT) and to the National Security Authority, which began analysis and evaluation and secured all relevant digital traces. Thanks to a newer backup system, the office expects the restoration of systems to be faster and smoother than before, and it is working on a safe and gradual restart of the systems while apologizing to citizens for the temporary outage. Essential services continue to be provided via the backup system.

Sources

Sources available to members: 1 source.

CSIDB