Cyber Incident Victim: Flemish Region
Date:
Apr 2024
Location:
Belgium
Summary
A cyberattack targeted municipal services in Deinze, Belgium, compromising an employee's email account to distribute fraudulent messages containing malicious links to approximately 300 recipients. The incident was rapidly detected and mitigated within an hour, with the compromised account blocked and all affected parties notified. Officials confirmed no unauthorized access to backend systems, servers, or databases occurred. Security measures including anti-spam filters, antivirus software, and mandatory multifactor authentication for staff were in place, though the breach was attributed to human error. The municipality's IT department is evaluating enhancements to existing security protocols.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On April 24, 2024, the municipal services of Deinze, Belgium, experienced a cyberattack involving unauthorized access to an employee’s email account. Attackers compromised the account and used it to send approximately 300 fraudulent emails impersonating the employee. These emails contained a link urging recipients to open a file, consistent with a phishing campaign. The incident was detected swiftly by city IT personnel, with additional reporting by Bart Vermaercke, a local council member from the N-VA party, accelerating the response. Within one hour of detection, the city’s IT team fully blocked the compromised account, halting further dissemination of malicious emails. Officials confirmed the attack was isolated to the email account, with no evidence of unauthorized access to backend systems such as servers or databases containing sensitive data. All affected email recipients were contacted directly by the IT department head to warn them about the fraudulent messages.

The city’s existing security infrastructure, including anti-spam filters and antivirus software, remained operational during the incident. All municipal employees utilized multifactor authentication (MFA) for system access, a measure implemented to reduce the risk of such breaches. Authorities attributed the breach to human error rather than a systemic failure of technical safeguards. In response, the IT department initiated a review of security protocols to identify potential enhancements, though no specific vulnerabilities or planned changes were disclosed publicly. Burgemeester Jan Vermeulen emphasized the effectiveness of the rapid containment and reiterated that no data stored on secured servers or databases was compromised. The incident did not disrupt municipal operations beyond the temporary email account suspension and notification efforts.
