Cyber Incident Victim: Westbahn
Date:
Oct 2023
Location:
Austria
Summary
Westbahn reported a cyber incident affecting its administrative IT systems, noting that attackers gained access to internal networks and that data exfiltration cannot be ruled out. The company stated that business, employee and customer data could have been affected, while emphasizing that it does not process credit card information internally. Train operations remained unaffected and continued as normal. Authorities have been notified and an investigation is underway.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On Thursday, 19 October 2023, Westbahn experienced a cyber incident that affected the administrative portion of its IT infrastructure. The company’s internal expert team detected the activity and took immediate steps to halt the unauthorized access. Following the containment, Westbahn’s IT division commenced an investigation with the assistance of external cybersecurity specialists. The organization also reported the incident to the relevant data protection authorities in accordance with legal obligations.

The attackers managed to obtain access to systems containing business, employee and customer data, and Westbahn stated that it could not rule out the possibility that data had been exfiltrated. The company emphasized that it does not handle credit card information directly, as payment processing is performed by third‑party service providers. Although the security breach did not disrupt rail operations, trains continued to run and tickets remained available through all regular channels. Westbahn noted that compromised customer data could potentially be used for unsolicited messages such as spam or phishing attempts.
To address inquiries, Westbahn published a set of frequently asked questions on its website and provided the email address [email protected] and a dedicated telephone hotline, +43 1 361 0366 548, for further contact. The company also made available instructions for resetting the password of a “Meine Westbahn” account, noting that, based on current findings, no passwords were known to have been stolen. Westbahn indicated that it continues to work on strengthening its IT environment and has reserved the right to pursue additional legal measures related to the incident.
