CSIDB logo
Incident

CPAS Mouscron

Incident posture

Attack window
Sep 2022
Location
Belgium
Status
Historical
CIA posture
Available to members
Updated
2025-10-17 00:00

Linked entities

Victim
CPAS Mouscron
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack caused complete IT system paralysis at a social services organization, severely hindering operations by disabling agendas, payment processing, and access to beneficiary records along with nursing home resident files. The disruption rendered case follow-ups impossible and was expected to persist for at least four days, prompting the institution to instruct individuals with appointments to postpone meetings via a designated phone number. Hackers claimed responsibility for the incident but did not issue a ransom demand.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 5, 2022, the Public Centre for Social Welfare (CPAS) of Mouscron, Belgium, experienced a debilitating cyberattack that paralyzed its entire IT infrastructure. The attack rendered all critical operational systems inaccessible, halting agenda management, electronic payment processing, and database retrieval for beneficiary records and nursing home resident files. This systemic failure severely disrupted service delivery, making case follow-ups impossible and forcing the organization into manual workarounds. The attack’s immediate aftermath left staff unable to perform routine functions, including scheduling appointments or accessing client histories. CPAS officials confirmed the incident stemmed from a deliberate hacking operation, though no ransom demand accompanied the compromise. Initial assessments indicated recovery would require a minimum of four days, extending operational disruptions through at least September 9.

In response, CPAS Mouscron activated contingency measures to manage client interactions, directing individuals with scheduled appointments to contact a dedicated phone line (056/390.450) to reschedule meetings for the following week. The center publicly acknowledged the cyberattack’s authorship by hackers but emphasized the absence of extortion attempts. No data theft or specific attacker identity was disclosed in initial communications. Service interruptions affected all CPAS-dependent facilities, including affiliated nursing homes, compounding risks for vulnerable populations reliant on timely social assistance. The organization focused on restoring basic functionality while operating under prolonged IT limitations, with no immediate resolution timeline provided beyond the initial four-day estimate.

Sources

Sources available to members: 1 source.

CSIDB