Cyber Incident Victim: Paris Lodron Universität Salzburg
Date:
Mar 2022
Location:
Austria
Summary
A cyberattack targeted Paris Lodron Universität Salzburg, compromising approximately 3,000 employee email addresses with the @plus.ac.at domain. The institution promptly disconnected the affected mail server to contain the breach, with internal and external IT teams mobilized to address the damage. Online teaching platforms and student email accounts remained operational during the incident. While leadership asserted control over the situation, investigators had not yet determined the attack's origin or whether data exfiltration occurred. This incident followed a pattern of recent cyber intrusions affecting organizations in the region, though specific attribution or motives remained unclear at the time of reporting.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On the night leading to Monday, March 28, 2022, Paris Lodron Universität Salzburg (PLUS) experienced a disruptive cyberattack that triggered an IT security alarm. The attack specifically targeted the university's email infrastructure, prompting immediate intervention from technical experts who disconnected the affected mail server from the network to contain the breach. Compromised accounts included all employee email addresses using the @plus.ac.at domain, estimated to total approximately 3,000 individual addresses. University leadership confirmed that student email accounts and online teaching platforms remained unaffected throughout the incident. Rector Hendrik Lehnert publicly stated the institution had control over the situation, emphasizing operational continuity despite the disruption. Internal IT staff collaborated with external cybersecurity specialists to prioritize damage assessment and system restoration efforts.

The full scope and motivation behind the attack remained undetermined at the time of reporting, with investigators unable to confirm whether data exfiltration had occurred. Response teams focused on forensic analysis and remediation while maintaining core university functions unrelated to the compromised email system. This incident occurred within a broader regional context of heightened cyber threats, as Salzburg had experienced multiple high-profile attacks in preceding months. Notably, hackers had successfully paralyzed the entire IT infrastructure of Salzburg Milch during a separate incident the previous year. The university's containment strategy centered on isolating critical systems, though the persistence of vulnerabilities in institutional or regional networks was not addressed in available communications.
