CSIDB logo
Incident

Bjuvs kommun

Incident posture

Attack window
Jan 2024
Location
Sweden
Status
Historical
CIA posture
Available to members
Updated
2026-01-04 18:24

Linked entities

Victim
Bjuvs kommun
Threat actors
0 actors
Sources
3 sources

Timeline

Occurred
Jan 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

An IT attack targeted Bjuvs kommun's IT environment overnight between Friday and Saturday, disrupting operational systems and employee computer logins. The incident caused partial inaccessibility to digital services and temporary email outages, though phone and social media communications remained functional. Shared IT provider EttIT, serving multiple municipalities including unaffected Örkelljunga and Åstorp, responded immediately by manually managing vulnerable systems to prevent broader impact. Personnel from EttIT and the municipality worked intensively to troubleshoot, minimize damage, and restore services, identifying a solution that enabled most systems and computers to resume operations by Monday morning. The attack was reported to police, with ongoing coordination to monitor the situation.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

3 techniques

Description

The IT attack against Bjuvs kommun occurred between the night of Friday, January 19, and Saturday, January 20, 2024, targeting the municipality's IT environment. The intrusion disrupted operational systems and compromised employee access to work computers, impairing core administrative functions. Bjuvs kommun's shared IT department, EttIT—which also serves Örkelljunga, Klippan, Perstorp, and Åstorp kommuner—immediately initiated manual management of potentially vulnerable segments of the shared infrastructure to prevent cross-municipality spread. While Bjuv's systems were directly compromised, all other municipalities in the EttIT collaboration confirmed their environments remained unaffected. By Sunday, January 21, EttIT and Bjuvs kommun personnel identified a remediation strategy, enabling the restoration of most operational systems and computers by Monday morning, January 22.

Despite this recovery, residual disruptions persisted in Bjuvs kommun’s digital services as of January 22, including intermittent inaccessibility of the [email protected] email platform. Citizens were advised to use telephone or social media for communication during the outage. EttIT maintained continuous coordination with all partner municipalities to monitor the situation, while Bjuvs kommun internally prioritized damage assessment and system stabilization. The municipality formally initiated a police investigation into the attack, though no details regarding the threat actor’s identity, intrusion methods, or data compromise were disclosed in the available reports. No ransomware or financial motives were mentioned, and restoration efforts focused on operational continuity rather than publicly disclosed forensic analysis.

Sources

Sources available to members: 3 sources.

CSIDB