S-Bahn Hannover
Incident posture
Linked entities
- Victim
- S-Bahn Hannover
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
The S-Bahn Hannover website was hit by an overload attack that made it unreachable. The attack flooded the site with external requests, causing a bad gateway error and preventing normal access. IT specialists responded by activating traffic filters, which restored service after a couple of hours but occasionally flagged legitimate users as attackers. Other web presences within the Transdev group experienced similar disruptions during the incident. A comparable disruption had occurred earlier, affecting the same site for several hours before filters were applied. The operator informed passengers through social media channels while the issue persisted.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On July 9, 2025, the website of S-Bahn Hannover became the target of an external overload attack that restricted its accessibility. Visitors to the site encountered a 'bad gateway' error, indicating that the server was not responding to requests. The attack was described as a volumetric overload in which attackers generated excessive external calls to overwhelm the web service. In response, the Transdev Hannover IT department activated defensive filters to mitigate the traffic surge. While the filters helped restore service, they also introduced the possibility of further impairments and could cause legitimate users to be mistakenly identified as attackers and blocked.
A second overload incident occurred on July 24, 2025, marking the second time that month the S-Bahn Hannover website was unavailable. According to reports, the problem began early Thursday morning when hackers again directed a flood of external calls at the site, causing an overload that prevented normal access. The disruption extended to other web properties within the Transdev group, indicating a broader impact beyond the S-Bahn portal. After approximately two hours, IT experts enabled filters that curtailed the malicious traffic and brought the website back online. Despite the restoration, some users continued to experience difficulties, and there remained a risk that innocent visitors could be incorrectly flagged as attackers by the filtering mechanisms.
The repeated overload attacks resulted in a denial‑of‑service condition for the S-Bahn Hannover online presence, disrupting the ability of passengers to obtain schedule and service information via the website. The defensive response relied on activating network‑level filters, a measure that, while effective at curbing the attack traffic, carried the side effect of potentially blocking legitimate users and causing ancillary service degradations. Transdev Hannover communicated updates to affected passengers through its social‑media channels during both incidents. The episodes highlighted how external volumetric attacks can repeatedly impair a public‑transport operator’s web infrastructure within a short timeframe.
Sources
Sources available to members: 2 sources.