Cyber Incident Victim: Haute Ecole Arc
Date:
Jul 2022
Location:
Switzerland
Summary
A cyberattack targeted the University of Applied Sciences and Arts Western Switzerland (Haute Ecole Arc) in Neuenburg, prompting protective measures including the shutdown of all server access and blocking of email communications to safeguard infrastructure and data. The institution indicated it would establish a new email address pending investigation outcomes, following disruptions to its systems. This incident occurred shortly after another nearby university faced similar security compromises.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 4, 2022, the University of Applied Sciences and Arts Western Switzerland (Haute Ecole Arc) in Neuenburg experienced a cyberattack, marking the second such incident targeting a higher education institution in the city that year following a February attack on the University of Neuenburg. The institution announced near the editorial deadline of that day its decision to proactively disable access to all servers and block email communications as protective measures. This action was implemented to safeguard institutional infrastructure and data integrity amid the ongoing security incident. The announcement did not specify the attack vector or identify threat actors but framed the server and email shutdowns as containment protocols. No details were provided regarding initial detection methods or whether data exfiltration occurred prior to the response.

The immediate operational impact included the suspension of all server-dependent services and electronic communications through institutional email systems. The university committed to establishing a replacement email address for external communications once investigative findings became available, though no timeline was disclosed for service restoration or investigation completion. Public statements emphasized defensive priorities over operational continuity, reflecting a risk-averse containment strategy. The incident occurred without prior warning according to available reporting, and the institution did not disclose whether the attack shared characteristics with the earlier University of Neuenburg breach. No information was released regarding affected user accounts, research data, or financial systems, with communications strictly limited to infrastructure protection measures and temporary communication alternatives.
