Cyber Incident Victim: Landratsamt Bodenseekreis
Date:
May 2025
Location:
Germany
Summary
The Landratsamt Bodenseekreis reported that a software tool used to manage its service smartphones and mobile devices was compromised by a hacker attack. Upon discovering the vulnerability, the administration’s IT department isolated all approximately six hundred mobile devices from the network and notified the Cyber Security Baden‑Württemberg agency. Specialists are now conducting forensic examinations of the affected systems together with the internal IT team. Current assessments indicate that no sensitive data has been accessed, altered, or damaged, and that information belonging to citizens, customers, and partners remains unaffected. Administrative operations continue without restriction.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On Wednesday, 21 May 2025, the IT department of the Landratsamt Bodenseekreis discovered a vulnerability in the software product used for managing service mobile phones and mobile devices. The discovery was made after the program was identified as the target of a hacker attack. Upon detecting the breach, the IT team immediately disconnected all approximately six hundred mobile devices belonging to the district administration from the data network. The incident was reported without delay to the Cyber Security Baden‑Württemberg authority in accordance with regulatory requirements. These actions were taken as immediate containment measures to prevent further unauthorized access.

Specialists from the Cyber Security Baden‑Württemberg unit are now working together with the Landratsamt’s IT team to conduct extensive forensic analyses of all relevant systems. At present, there are no indications that sensitive data have been accessed, altered, or damaged as a result of the attack. According to the current assessment, data belonging to citizens, customers, and business partners of the district are not endangered. The district office reports that its operational functions continue without restriction despite the disconnection of the mobile devices. The ongoing investigation aims to determine the full scope of the incident while maintaining normal service delivery.
