CSIDB logo
Incident

Bremen

Incident posture

Attack window
Feb 2025
Location
Germany
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 13:55

Linked entities

Victim
Bremen
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

On a Wednesday morning, the Bremen public administration suffered a severe Denial-of-Service attack that bombarded its servers with up to 18,000 requests per minute, causing a temporary outage of administrative and police websites. A Russian hacker group claimed responsibility for the incident, which is being investigated by the central cybersecurity office within the Senator for Internal Affairs. Most malicious traffic was successfully blocked during the morning, restoring website availability, with the attack subsiding by evening. A separately planned system update that same evening caused an additional scheduled outage, during which the administration remained reachable via the 115 citizen hotline and police through their central emergency line. All websites have since returned to normal operation, while the investigation and forensic analysis of the incident continue.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On the morning of Wednesday, February 12, 2025, the public administration web infrastructure of the Free Hanseatic City of Bremen fell victim to a severe Denial-of-Service attack. According to information released by the Bremer Senat, the assault began at approximately 7:15 a.m. and was directed initially at the website of the Polizei Bremen. During the course of the incident, servers belonging to the Bremen city administration were bombarded with up to 18,000 requests per minute. The volume of traffic overwhelmed the systems and led to a temporary outage of the affected websites, rendering them inaccessible to members of the public seeking information or services from the police and other administrative bodies. The Bremen Senate characterized the event as a serious cyberattack, prompting an immediate official response from local cybersecurity authorities.

Responsibility for the attack was claimed by a Russian hacker group, which publicly acknowledged its role in the disruption. The investigation into the origin, scope, and methodology of the intrusion was taken up by the Zentralstelle Cybersicherheit, an office attached to the Senator für Inneres, which serves as the central coordination point for cybersecurity matters in the state. This body began examining the technical traces of the attack in order to determine the precise mechanisms used, the extent of any potential compromise beyond the initial Denial-of-Service activity, and whether any data was exfiltrated or further systems were affected. The attribution to a Russian group aligned with broader public concerns in Germany, where surveys have consistently identified Russia as the leading perceived cyber threat, though the article does not state whether the claim of responsibility was independently verified by investigators.

The operational response to the attack was led by the Kompetenzstelle CMS und Internet, a unit within the Senator für Finanzen that is responsible for the content management systems and public-facing internet presence of the Bremen administration. Throughout the morning, this office worked to filter and repel the flood of incoming requests, implementing defensive measures to separate malicious traffic from legitimate user access. As a result of these efforts, the websites of the Bremen administration became accessible again by late morning, restoring service to citizens before the end of the typical working day. By the evening hours, the intensity of the attack had subsided, although the formal investigation, forensic analysis, and evaluation of the incident continued beyond the immediate containment period and were expected to require additional time to complete.

In addition to the cyberattack, a second, planned outage occurred on the evening of Wednesday, February 12. This interruption was unrelated to the security incident and was instead the result of a routine operating system update that had been scheduled in advance. According to the administration, such updates are necessary to ensure that the underlying technical infrastructure remains current with security patches and functional improvements. To minimize disruption, these maintenance windows are typically announced well in advance so that users and dependent services can prepare accordingly. During the update window, citizens who required contact with the administration were able to reach the Bürgertelefon at the standardized service number 115, while matters concerning the police could be directed to the Zentralruf at (0421) 362-0. After the update was completed, all websites resumed normal operation and have since remained accessible to the public.

The incident occurred against a backdrop of heightened public concern about cyber threats in Germany. A representative survey conducted by the digital industry association Bitkom in the lead-up to the Munich Security Conference found that 61 percent of respondents expressed fear of state-sponsored cyberattacks aimed at disrupting, sabotaging, or destroying infrastructure, public institutions, or businesses. Within this group, 24 percent stated that they considered such an eventuality certain, while 37 percent regarded it as at least probable. Only 16 percent of those surveyed said they had no fear of cyberattacks whatsoever, with another 19 percent leaning toward that view. The poll, which gathered responses from 1,115 individuals aged 16 and over across Germany, also revealed widespread skepticism about the preparedness of public authorities. Merely 23 percent of respondents believed that German public administration, including agencies such as the police and the Bundeswehr, was well equipped to defend against cyberattacks. When asked to identify the countries posing the greatest cybersecurity threat to Germany, respondents named Russia first, with 98 percent, followed by China at 84 percent, North Korea at 44 percent, and the United States at 32 percent. The survey further indicated that foreign intelligence services were viewed as the most likely attackers by 78 percent of respondents, ahead of organized crime at 67 percent, political or religious extremists at 59 percent, and individual criminals at 41 percent.

Sources

Sources available to members: 1 source.

CSIDB