CSIDB logo
Incident

City of Dresden

Incident posture

Attack window
Oct 2023
Location
Germany
Status
Historical
CIA posture
Available to members
Updated
2026-01-27 04:08

Linked entities

Victim
City of Dresden
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack temporarily disrupted access to Dresden's municipal website, causing intermittent outages and partial unavailability during the incident. The city's IT department successfully mitigated the distributed denial-of-service (DDoS) attack, which overwhelmed the site with excessive traffic to overload its systems. Security measures prevented further damage or external manipulation, and full service was restored within hours. The attack's impact remained limited to temporary operational disruption without lasting effects on the platform.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On October 12, 2023, the official website of Dresden, Saxony (dresden.de), experienced a cyberattack that disrupted public access to its services. The incident began when attackers launched a Distributed Denial of Service (DDoS) attack against the city's web infrastructure, overwhelming servers with excessive traffic. This caused intermittent outages starting Thursday afternoon, with the website becoming partially or completely unreachable for an unspecified period. Municipal authorities detected the attack in progress and activated defensive protocols to contain the impact. By approximately 3:30 PM local time, technicians successfully restored full functionality to dresden.de after mitigating the malicious traffic flood. The attack did not compromise internal city systems or sensitive data, as the targeting remained confined to public-facing web servers.

Prof. Dr. Michael Breidung, head of Dresden's municipal IT service (Eigenbetrieb IT), confirmed all implemented security measures effectively neutralized the attack and prevented escalation. The defensive response included traffic filtering and infrastructure scaling to absorb the volumetric assault characteristic of DDoS campaigns. No secondary intrusion attempts or data breaches occurred during or after the incident. Service disruption remained limited to temporary accessibility issues for residents attempting to access the city portal, with no reported downstream effects on other municipal operations. The city characterized the attack’s consequences as short-term operational degradation without lasting damage to systems or services.

Sources

Sources available to members: 1 source.

CSIDB