Cyber Incident Victim: Parliamentary Assembly of Bosnia and Herzegovina
Date:
Sep 2022
Location:
Bosnia and Herzegovina
Summary
A cyber attack targeted the Parliamentary Assembly of Bosnia and Herzegovina, prompting the shutdown of its main server. This caused widespread disruptions, including inaccessibility to the institution’s email systems and official website. An investigation is underway to determine the attacker’s identity, the root causes of the incident, and the full scope of the damage. Authorities have committed to providing further updates as the situation develops.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 7 motives | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On September 8, 2022, the Parliamentary Assembly of Bosnia and Herzegovina experienced a cyber attack that disrupted its core information systems. The attack targeted the institution’s main server, forcing administrators to shut it down to contain the incident. This action rendered critical services inaccessible, including the official website and parliamentary email accounts, preventing users from conducting routine operations. The disruption persisted into the following day, with no immediate restoration timeline provided. The Parliamentary Assembly’s information center publicly confirmed the incident on September 9, attributing the shutdown directly to the cyber attack. No initial details were disclosed regarding the attack vector, duration, or specific systems compromised beyond the main server.

Investigations commenced immediately after the attack was identified, focusing on determining the identity of the perpetrators, the root causes of the breach, and the full scope of damage inflicted. Authorities did not publicly speculate on potential motives or attribute responsibility to any specific threat actor during the initial phase. The Parliamentary Assembly emphasized transparency, pledging to share further details with the public as the inquiry progressed. No data theft or secondary disruptions beyond the server outage were confirmed in the initial announcement. The incident underscored operational vulnerabilities, though its broader impact on legislative functions or data integrity remained unquantified in the immediate aftermath. Restoration efforts and forensic analysis continued without disclosed interim resolutions.
