CSIDB logo
Incident

Luxembourg City

Incident posture

Attack window
Jan 2025
Location
Luxembourg
Status
Unknown
CIA posture
Available to members
Updated
2026-01-23 09:07

Linked entities

Victim
Luxembourg City
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Luxembourg government websites experienced a distributed denial-of-service (DDoS) attack, rendering several critical online services including MyGuichet and LuxTrust inaccessible for approximately two hours. The State Information Technology Centre confirmed the incident but did not identify the perpetrators, noting it as part of a recurring pattern of cyberattacks targeting the country's digital infrastructure. Previous sustained attacks had disrupted multiple ministries and agencies for extended periods, with pro-Russian hacker groups claiming responsibility for an earlier incident. The government has denied geopolitical motivations behind these disruptions while refusing to disclose attack origins. This aligns with broader regional trends of escalating cyber threats, particularly against financial sectors.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 10, 2025, multiple Luxembourg government websites experienced a Distributed Denial-of-Service (DDoS) attack beginning at approximately 13:00 local time. The State Information Technology Centre (CTIE) confirmed the incident, which rendered critical online services—including MyGuichet and LuxTrust—inaccessible for approximately two hours. Attackers overwhelmed the target servers with automated requests, preventing legitimate user access. CTIE restored functionality by 15:00 but declined to disclose technical specifics or attribute responsibility, citing an ongoing investigation. This marked the third major cyber disruption targeting Luxembourg’s digital infrastructure within a year, following similar incidents in October 2024 and a prolonged attack during March-April 2024. No data breaches or system compromises were reported in the January event, though service interruptions disrupted public access to administrative and authentication platforms.

The spring 2024 attack referenced by CTIE involved a two-week disruption affecting high-profile entities including the Ministries of Finance and Justice, national statistics agency Statec, and health fund CNS. Pro-Russian hacker groups claimed responsibility via Telegram, framing it as a coordinated action with allied cyber collectives. Luxembourg’s government publicly rejected any connection between the attack and its geopolitical stance on Ukraine while withholding forensic conclusions about its origin. Cybersecurity firm Check Point documented an 82% year-over-year increase in attacks against organizations globally during Q3 2024, with financial institutions averaging 723 weekly attacks—contextualizing Luxembourg’s recurring vulnerabilities. CTIE’s January 2025 response mirrored its prior strategy: restoring services without confirming adversary identities or revealing mitigation tactics.

Sources

Sources available to members: 1 source.

CSIDB