Menu
Browse

Cyber Incident Victim: Styria Medien AG

Date:

Mar 2024

Location:

Austria

Summary

A cyberattack targeted a Graz-based IT firm managing approximately 80 property company databases, including customer data for Klagenfurt Wohnen, a municipal housing entity. The breach occurred over a weekend, potentially exposing sensitive client information, though the full scope and severity remain under assessment. The incident was confirmed by Klagenfurt city officials, who acknowledged the IT provider's compromised systems but emphasized ongoing evaluations to determine the extent of impacted data.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

A cyberattack occurred over the weekend of March 9-10, 2024, targeting an unnamed IT company headquartered in Graz, Styria. The company managed approximately 80 databases for real estate firms, including the customer data of Klagenfurt Wohnen, a municipal housing provider owned by the city of Klagenfurt. Initial reports from Kleine Zeitung indicated the incident potentially resulted in a significant data breach affecting these client systems. Valentin Unterkircher, head of Klagenfurt’s city communications department, acknowledged the cyber intrusion upon inquiry but stated the full scope and severity remained undetermined at the time of reporting. The IT firm’s servers were compromised through suspected criminal activity, though technical details regarding the attack vector, duration of unauthorized access, or specific data types targeted were not disclosed.

Cyber Incident Image

Klagenfurt Wohnen’s potential exposure prompted official confirmation from city authorities, with Unterkircher validating the Kleine Zeitung’s findings via an APA (Austria Press Agency) request on March 12. No evidence confirmed whether customer data was exfiltrated or merely accessed during the breach. The incident’s operational impact on Klagenfurt Wohnen’s services or the IT company’s other clients was not detailed in available reports. Similarly, containment measures, forensic investigations, or coordination with law enforcement agencies were not described. Municipal officials emphasized the ongoing assessment of consequences, leaving critical questions about data sensitivity, notification obligations, and remediation efforts unresolved in the immediate aftermath. The absence of attributed responsibility or disclosed attacker motives characterized the incident as an evolving security event with unresolved implications for data subjects and dependent organizations.

Sources
Sources available to members
2 sources