Menu
Browse

Cyber Incident Victim: Scalda

Date:

Dec 2022

Location:

Netherlands

Summary

A Dutch vocational education institution experienced disruptive DDoS attacks originating from within its own network or coordinated internally, causing significant operational disruptions including canceled classes and Wi-Fi outages. The attacks overwhelmed servers, prompting technical countermeasures that inadvertently restricted legitimate network traffic. The organization filed a police report, engaged cybersecurity experts, and collaborated with its network provider to mitigate future impacts while appealing for internal information sharing. Law enforcement initiated an investigation into the incident, which critically threatened educational continuity.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 5 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On or around December 1, 2022, the vocational education institution Scalda in Vlissingen experienced disruptive distributed denial-of-service (DDoS) attacks targeting its network infrastructure. The attacks originated from one or more individuals within the school or were internally coordinated, according to Scalda's internal assessment. These attacks overwhelmed the institution's servers with excessive data traffic, degrading network accessibility for legitimate users. The disruption caused several classes to be canceled, directly impacting educational continuity. Scalda communicated via email to students and staff that the attacks were creating "major disruptions" that "seriously undermine the progress of education." Technical countermeasures implemented by the school and its network provider inadvertently affected both malicious and legitimate data traffic, resulting in additional WiFi network instability across the campus. A Scalda spokesperson later confirmed the immediate technical issues had been resolved, though the institution remained engaged with its provider to minimize future disruptions during subsequent attacks.

Cyber Incident Image

Scalda initiated a multi-faceted response, including filing a police report after consultations with law enforcement, who agreed to investigate the incident. The institution also enlisted a cybersecurity expert to assist in identifying the perpetrators. Internal outreach encouraged students and staff with relevant information to report details to mentors or team leaders. Mitigation efforts focused on refining network provider configurations to distinguish between attack traffic and legitimate educational operations, though these adjustments initially exacerbated WiFi reliability issues. Scalda emphasized the legal consequences of conducting DDoS attacks, underscoring the criminal nature of such acts under Dutch law while continuing operational recovery measures to stabilize academic activities.

Sources
Sources available to members
1 source