CSIDB logo
Incident

Landratsamt Bodenseekreis

Incident posture

Attack window
May 2025
Location
Germany
Status
Unknown
CIA posture
Available to members
Updated
2026-06-19 02:53

Linked entities

Victim
Landratsamt Bodenseekreis
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Landratsamt Bodenseekreis reported that a software tool used to manage its service smartphones and mobile devices was compromised by a hacker attack. Upon discovering the vulnerability, the administration’s IT department isolated all approximately six hundred mobile devices from the network and notified the Cyber Security Baden‑Württemberg agency. Specialists are now conducting forensic examinations of the affected systems together with the internal IT team. Current assessments indicate that no sensitive data has been accessed, altered, or damaged, and that information belonging to citizens, customers, and partners remains unaffected. Administrative operations continue without restriction.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On Wednesday, 21 May 2025, the IT department of the Landratsamt Bodenseekreis discovered a vulnerability in the software product used for managing service mobile phones and mobile devices. The discovery was made after the program was identified as the target of a hacker attack. Upon detecting the breach, the IT team immediately disconnected all approximately six hundred mobile devices belonging to the district administration from the data network. The incident was reported without delay to the Cyber Security Baden‑Württemberg authority in accordance with regulatory requirements. These actions were taken as immediate containment measures to prevent further unauthorized access.

Specialists from the Cyber Security Baden‑Württemberg unit are now working together with the Landratsamt’s IT team to conduct extensive forensic analyses of all relevant systems. At present, there are no indications that sensitive data have been accessed, altered, or damaged as a result of the attack. According to the current assessment, data belonging to citizens, customers, and business partners of the district are not endangered. The district office reports that its operational functions continue without restriction despite the disconnection of the mobile devices. The ongoing investigation aims to determine the full scope of the incident while maintaining normal service delivery.

Sources

Sources available to members: 1 source.

CSIDB