Menu
Browse

Cyber Incident Victim: Westbahn

Date:

Oct 2023

Location:

Austria

Summary

Westbahn reported a cyber incident affecting its administrative IT systems, noting that attackers gained access to internal networks and that data exfiltration cannot be ruled out. The company stated that business, employee and customer data could have been affected, while emphasizing that it does not process credit card information internally. Train operations remained unaffected and continued as normal. Authorities have been notified and an investigation is underway.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On Thursday, 19 October 2023, Westbahn experienced a cyber incident that affected the administrative portion of its IT infrastructure. The company’s internal expert team detected the activity and took immediate steps to halt the unauthorized access. Following the containment, Westbahn’s IT division commenced an investigation with the assistance of external cybersecurity specialists. The organization also reported the incident to the relevant data protection authorities in accordance with legal obligations.

Cyber Incident Image

The attackers managed to obtain access to systems containing business, employee and customer data, and Westbahn stated that it could not rule out the possibility that data had been exfiltrated. The company emphasized that it does not handle credit card information directly, as payment processing is performed by third‑party service providers. Although the security breach did not disrupt rail operations, trains continued to run and tickets remained available through all regular channels. Westbahn noted that compromised customer data could potentially be used for unsolicited messages such as spam or phishing attempts.

To address inquiries, Westbahn published a set of frequently asked questions on its website and provided the email address [email protected] and a dedicated telephone hotline, +43 1 361 0366 548, for further contact. The company also made available instructions for resetting the password of a “Meine Westbahn” account, noting that, based on current findings, no passwords were known to have been stolen. Westbahn indicated that it continues to work on strengthening its IT environment and has reserved the right to pursue additional legal measures related to the incident.

Sources
Sources available to members
2 sources