Menu
Browse

Cyber Incident Victim: Stadt Weiz

Date:

May 2020

Location:

Austria

Summary

A ransomware attack by the NetWalker group targeted an Austrian city, compromising its public service systems through COVID-19-themed phishing emails that deployed malicious VBScripts. The malware encrypted files across the Windows network, terminated critical processes, and deleted backups, disrupting municipal operations and leaking stolen data related to building applications and inspections. The city, a regional economic hub hosting major industrial firms, may have been intentionally selected due to its strategic significance, aligning with the threat actor’s pattern of focusing on high-impact sectors like healthcare.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 3 motives 2 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

On May 27, 2020, the Austrian village of Weiz experienced a ransomware attack attributed to the NetWalker group. The attackers compromised the municipality’s public service systems through phishing emails disguised as COVID-19 coronavirus information updates. Employees within Weiz’s public infrastructure clicked malicious links in these emails, triggering the deployment of ransomware. Cybersecurity firm Panda Security analyzed the attack, identifying it as a newer variant of ransomware propagating through VBScripts. Upon infection, the malware terminated Windows processes and services, encrypted files across all accessible disks, and deliberately eliminated backup data to hinder recovery efforts. This encryption disrupted municipal operations reliant on digital systems, particularly impacting building application and inspection services.

Cyber Incident Image

The attack resulted in the theft and subsequent leakage of sensitive data related to building permits and inspections. Weiz’s status as an economic center in the Oststeiermark region—hosting production plants for major corporations like Magna, Strobl Construction, and Lieb-Bau-Weiz—suggested the intrusion may have been deliberately targeted rather than opportunistic. NetWalker had previously conducted similar ransomware campaigns against healthcare institutions globally, including a March 2020 attack on Spanish hospitals that also employed COVID-19-themed phishing lures. The incident underscored the group’s focus on exploiting pandemic-related anxieties to infiltrate critical infrastructure, though specific containment measures or financial demands by Weiz authorities were not detailed in available reports. Operational disruptions and data exposure remained the primary documented consequences for the municipality.

Sources
Sources available to members
1 source