Menu
Browse

Cyber Incident Victim: Canton of Bern

Date:

Nov 2023

Location:

Switzerland

Summary

A ransomware attack targeted the municipal administration of Zollikofen, encrypting critical data and forcing the complete shutdown of all ICT systems. This caused widespread operational disruption and rendered employees unreachable via email or telephone, with authorities initiating an investigation alongside external cybersecurity specialists to address the incident.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On November 22, 2023, the municipal administration of Zollikofen, Switzerland, experienced a disruptive ransomware attack that encrypted critical data and forced the complete shutdown of all ICT systems. The attack rendered essential digital services inoperable, severely impairing routine municipal operations. Employees became unreachable through standard communication channels, including email and telephone systems, indicating widespread infrastructure compromise. Municipal authorities initiated an immediate containment response by powering down affected systems to prevent further encryption or lateral movement by attackers. This operational suspension created significant service delivery disruptions for residents and businesses reliant on municipal functions. No specifics regarding the ransomware variant, initial attack vector, or ransom demands were disclosed in available reporting.

Cyber Incident Image

The municipality engaged an external cybersecurity service provider to conduct forensic analysis and assist with recovery efforts, though investigation findings remained undisclosed at the time of reporting. Operational continuity challenges persisted due to the prolonged system downtime required for remediation. The incident occurred amid heightened concern about cyber risks among Bernese small and medium enterprises, as documented in a contemporaneous survey by the Berner Gewerbeverband highlighting regional anxiety about inadequate cybersecurity preparedness. Zollikofen's experience demonstrated ransomware's capacity to disrupt critical public services through digital infrastructure compromise, though the full scope of data impact and restoration timelines were not publicly verified. Municipal authorities maintained operational silence regarding recovery progress beyond confirming the attack's occurrence and their engagement of specialist response resources.

Sources
Sources available to members
1 source