Cyber Incident Victim: Polizei Baden-Württemberg
Date:
Jan 2023
Location:
Germany
Summary
The Polizei Baden-Württemberg experienced a cyberattack targeting its websites, causing temporary unavailability due to an apparent attempt to overwhelm the server with concentrated traffic spikes. Authorities successfully repelled the attack, restoring full access shortly afterward, though the incident raised concerns about a potential nationwide campaign. The disruption followed a similar recent attack, indicating recurring targeting of the agency's online infrastructure through volumetric overload tactics.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On January 24, 2023, the internet services of the Baden-Württemberg police experienced a cyberattack that temporarily disrupted public access to their websites. The attack was successfully repelled on the same day, according to a spokesperson from the state’s Interior Ministry in Stuttgart. While the specific technical nature of this incident was not detailed in available reports, the disruption resulted in a brief period of service unavailability. Authorities confirmed that full functionality was restored without lingering restrictions following containment efforts. This marked the first of two closely timed incidents targeting the police’s digital infrastructure within days. The Südwestrundfunk media outlet initially broke news of the January 24 attack, though official statements emphasized operational recovery. No data breaches or additional compromises were publicly acknowledged in connection with this event.

A second disruptive incident occurred on January 25, 2023, when the police website (www.polizei-bw.de) became unreachable due to another cyberattack characterized by unusually high volumes of traffic directed at the server. Technical indicators suggested a distributed denial-of-service (DDoS) attack methodology, where repeated automated requests overwhelmed system capacity. The Interior Ministry noted the attack’s "stoßförmig" (surge-like) pattern, which caused abnormal traffic spikes within a compressed timeframe. While the exact duration of the outage was unspecified, the incident raised concerns about potential coordination with broader threats, as authorities indicated it might be part of a nationwide attack campaign. Both attacks collectively underscored persistent vulnerabilities in public sector web infrastructure, though neither incident disclosed evidence of data exfiltration or permanent damage to backend systems.
