Menu
Browse
Date:

Jan 2023

Location:

Germany

Summary

Unknown attackers targeted servers at seven schools, deploying malware and encrypting system data. The city's IT office initiated an investigation with external cybersecurity experts, disconnecting all potentially affected school servers as a precaution, with plans to restore them after verification. Vocational schools remained unaffected due to differing systems. The incident caused significant disruptions to educational and administrative operations, prompting a criminal complaint and notification of the state data protection authority.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On or around January 28-29, 2023, unidentified threat actors conducted a cyberattack targeting servers belonging to seven schools in Karlsruhe, Baden-Württemberg, Germany. The attackers gained unauthorized access to the schools' IT infrastructure, deploying malicious software (Schadsoftware) and encrypting system data. The affected institutions included the Adam-Remmele-Schule, Hardtschule, Schule am Turmberg, Grundschule Wolfartsweier, Markgrafen-Gymnasium, Realschule Neureut, and Erich-Kästner-Schule. The intrusion was detected following the incident, prompting immediate action by Karlsruhe's Office for Information Technology and Digitalization (Amt für Informationstechnologie und Digitalisierung). Vocational schools in Karlsruhe remained unaffected due to their use of separate IT systems unrelated to the compromised infrastructure.

Cyber Incident Image

The city's IT office initiated forensic investigations with support from external cybersecurity experts and implemented containment measures by disconnecting all potentially impacted school servers from the network. This preventative isolation aimed to limit further damage while systems underwent security reviews. Operational disruptions occurred across pedagogical activities and administrative functions at the targeted schools during the outage and investigation period. Karlsruhe authorities filed a criminal complaint against unknown perpetrators and formally notified the State Data Protection Commissioner (Landesdatenschutzbeauftragten) of the breach. No data theft or additional attacker objectives were disclosed in initial reports. Restoration efforts involved methodical server reactivations only after completing security validations and clearance procedures.

Sources
Sources available to members
1 source