Cyber Incident Victim: Surahammars kommun
Date:
Nov 2024
Location:
Sweden
Summary
A phishing attack targeted Surahammars kommun, involving a malicious email distributed from an employee's account to approximately 600 recipients. The email contained a link directing users to a fraudulent login page designed to harvest credentials, aiming to compromise user accounts. The municipality responded swiftly, initiating incident management procedures, reporting the incident to law enforcement and CERT-SE. This event underscores the broader risk of credential theft through deceptive communications.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On Monday, November 25, 2024, Surahammars kommun experienced a cyberattack involving a phishing campaign originating from a compromised employee email account. The attack distributed a malicious email containing a link to a fraudulent login page designed to harvest user credentials to approximately 600 recipients. This phishing attempt aimed to deceive recipients into submitting their login information, enabling attackers to hijack user accounts. The municipality detected the incident promptly and initiated response protocols the same day. Officials characterized the event as a deliberate attempt to compromise personal credentials through social engineering rather than a technical system breach.

Surahammars kommun activated its incident response procedures immediately upon discovery, engaging in containment efforts and forensic analysis. The incident was reported to law enforcement authorities and CERT-SE, Sweden’s national computer security incident response team, as part of standard breach notification protocols. Internal communications emphasized heightened vigilance regarding unsolicited messages containing links or requests for sensitive actions. While the attack’s direct operational impact remained confined to the phishing campaign’s distribution scope, the municipality reinforced security awareness by advising recipients to scrutinize unexpected communications through a four-step protocol: pausing before reacting, verifying message legitimacy, consulting colleagues or supervisors when uncertain, and reporting or deleting suspicious messages without interacting with embedded links. No additional technical compromises or data exfiltration beyond the credential-harvesting attempt were disclosed in public statements.
