CSIDB logo
Incident

Stadtgemeinde Tulln

Incident posture

Attack window
Feb 2025
Location
Austria
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 14:05

Linked entities

Victim
Stadtgemeinde Tulln
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack encrypted data across the municipal server infrastructure of Stadtgemeinde Tulln, with the incident discovered on a Monday. The entire server environment was affected, alongside approximately 200 individual workstations requiring forensic review. Internal IT staff and external specialists worked closely with federal and state security authorities to analyze the damage, while critical infrastructure such as water and sewage systems remained fully operational. The municipality quickly established workaround solutions to maintain essential citizen services, including registrations, re-registrations, and certifications, though electronic processing of official notices and cashless payment options at leisure facilities remained temporarily unavailable. Following thorough security verification of existing server backups, a gradual restoration process was initiated under continuous specialist monitoring to detect any suspicious activity. Data lost from the backup restoration was limited to staff work activity from the Monday of the attack week, while an extensive investigation into potential data exfiltration remained ongoing, and the municipality had initiated contact with the attackers without receiving a response.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 11, 2025, the Stadtgemeinde Tulln publicly disclosed that it had fallen victim to a cyberattack. The incident affected the entire server infrastructure of the municipal administration, with stored data having been encrypted by the attackers. From the early stages of the incident, the city's internal IT team worked alongside external IT specialists to analyze the damage and begin remediation. In addition to the core server systems, approximately 200 individual workstations had to be examined as part of the broader technical investigation. The analysis and all related investigative measures were carried out in close cooperation with federal and state security authorities.

The operational impact of the attack extended across a wide range of municipal services. Critical infrastructure such as water supply and wastewater systems continued to function without disruption. However, many administrative services that depend on stored data were temporarily unavailable. City officials moved quickly to establish workaround solutions for core citizen-facing services, allowing registration matters, change-of-address notifications, and notarial acts to be processed during the outage. Building permit procedures, which are normally handled quickly by the municipality, were still expected to be completed within their legally mandated deadlines despite the exceptional circumstances. Recreational facilities operated by the city remained accessible to the public, although cashless payment options at these venues were not functioning in the immediate aftermath of the attack.

By February 12, 2025, the city confirmed that the cyberattack had encrypted data across the server infrastructure and that comprehensive recovery efforts were in progress. Services that required direct access to stored records, such as the electronic generation of official notices and various administrative inquiries, remained unavailable at that time. Work continued on developing bridging solutions to maintain as many citizen services as possible while restoration activities proceeded.

An update issued on February 17, 2025 indicated substantial progress in restoring normal operations. The municipal administration reported that services for residents were once again running with nearly no limitations. Many systems had been brought back online, and temporary solutions had been implemented for others. For example, the city's accounting department was able to resume processing outgoing payments. Some specific functions remained under repair, including the ability to pay by bank card at the indoor swimming pool. Following a thorough review of the existing server backups for security integrity, those backups were being systematically reintroduced into the production environment. Officials projected that within the same week, all of the city's IT systems could be returned to operation. The restoration process was being monitored closely by specialists for any signs of suspicious activity.

Regarding data loss, the encrypted files were expected to be nearly fully reconstructed from the available backups. According to the update, the only data not preserved related to work performed by municipal employees on Monday, February 10, 2025, the day before the public disclosure. The detailed review to determine whether any data had been exfiltrated by the attackers was described as extensive and still ongoing. The city had established contact with the criminals responsible, though no response had been received from them as of the February 17 update.

Sources

Sources available to members: 1 source.

CSIDB