Menu
Browse

Cyber Incident Victim: Kalmar kommun

Date:

Feb 2024

Location:

Sweden

Summary

Kalmar kommunkoncern experienced a cyberattack attributed to the Russian group Akira, prompting internal system shutdowns and a police report. While critical infrastructure such as alarms, medical systems, and elevators remained unaffected, employees shifted to cloud-based workarounds. Most operations continue with adjustments, though e-services and specific platforms like Edlevo faced disruptions. The organization remains in a heightened security posture, anticipating prolonged recovery efforts.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On February 6, 2024, Kalmar kommunkoncern experienced network disruptions prompting an immediate shutdown of internal systems as a precautionary measure. Initial investigations led the organization to classify the incident as a suspected cyberattack, though critical infrastructure including safety alarms, medical cabinets, and elevators remained operational. Communication chief Nico Werge confirmed employees transitioned to cloud-based services to maintain workflow continuity while internal systems remained offline. By 11:25 that day, officials publicly confirmed the IT attack, noting that many core systems remained secure but access to critical applications required further assessment. The municipality activated its crisis management protocol, operating under the assumption that recovery efforts would extend through the week.

Cyber Incident Image

Kalmar kommun initiated police reporting procedures regarding the attack by 17:55 on February 6, while maintaining most operations through procedural adjustments. Standard communication channels such as telephones and email functioned normally, but e-services platforms and the Edlevo system experienced disruptions. Internal investigations focused on mapping system accessibility and containing the incident’s scope, with officials emphasizing that the majority of IT infrastructure was unaffected. The Russian cybercriminal group Akira was identified as the suspected perpetrator, based on attack characteristics matching their recent compromise of Tietoevry’s data center infrastructure. Ongoing updates indicated sustained operational limitations with no specified resolution timeline, though organizational functions continued under modified workflows.

Sources
Sources available to members
2 sources