Menu
Browse

Cyber Incident Victim: COUNT+CARE GmbH

Date:

Jun 2022

Location:

Germany

Summary

A cyberattack targeting a shared IT service provider disrupted operations for multiple organizations, including COUNT+CARE GmbH (FES), leading to precautionary server disconnections. While critical municipal services like waste management, street cleaning, and utility operations remained unaffected, customer-facing systems such as online bulky waste registration portals and internal email servers became inaccessible. The incident also impacted other entities relying on the same provider, causing website outages and email disruptions, though critical infrastructure segments like energy and water networks remained secure. No customer data compromise was reported, with operational continuity maintained through contingency plans while recovery efforts depended on the provider restoring its data center operations.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On June 12, 2022, a cyberattack targeted an IT service provider shared by multiple German municipal service companies, including Frankfurt-based waste management firm FES (Frankfurter Entsorgungs- und Service-Gruppe) and Darmstadt energy provider Entega. The attack compromised systems at the shared IT provider, prompting FES to proactively disconnect all servers linked to the service as a containment measure. This action disrupted FES's online platforms for bulk waste pickup scheduling and customer portal access, though core operational services like trash collection, street cleaning, and waste incineration plant functions remained unaffected. Simultaneously, Entega reported widespread email system outages affecting all 2,000 employees and took corporate websites offline, while emphasizing no disruptions to electricity, gas, or water delivery. The incident's scope expanded when Mainz utility provider Mainzer Stadtwerke confirmed identical impacts on their public-facing websites, email servers, and swimming pool booking systems due to their reliance on the same compromised IT provider.

Cyber Incident Image

All affected organizations maintained segregated protections for critical infrastructure, preventing operational impacts on power grids, water networks, or gas distribution systems. FES emphasized preparedness through contingency plans allowing continued service delivery via manual processes during IT outages. Recovery timelines depended entirely on the third-party IT provider's ability to restore its Darmstadt data center operations, with no public disclosure of restoration milestones. Investigations by Hesse State Criminal Police found no immediate evidence attributing the attack to specific threat actors or establishing motives. The incident highlighted supply chain vulnerabilities in municipal service ecosystems, with coordinated response measures successfully preventing data breaches or essential service interruptions despite prolonged ancillary system downtime.

Sources
Sources available to members
1 source