CSIDB logo
Incident

Landkreis München-Land

Incident posture

Attack window
Feb 2025
Location
Germany
Status
Unknown
CIA posture
Available to members
Updated
2026-08-28 11:41

Linked entities

Victim
Landkreis München-Land
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Feb 2025
Discovered
Feb 2025
Disclosed
Feb 2025
Resolved
Pending

Summary

The Munich district office’s website was rendered inaccessible by a distributed denial‑of‑service attack that also affected the city of Garching’s online presence, with both services experiencing temporary outages while their technical providers worked to restore normal operation. Investigators linked the activity to suspected prorussian hacktivist groups, noting that no data were exfiltrated or encrypted and that the incident was subsequently handed over to police for further investigation.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On the morning of February 13, 2025, the homepage of the city of Garching became inaccessible due to a cyberattack that lasted several hours, as reported by local news. The attack was identified as a distributed denial‑of‑service (DDoS) effort that overwhelmed the server with excessive requests, causing the service to be denied. According to the city’s statement, the technical service provider that hosts the site began working intensively to restore access and set up a temporary redirect so that visitors to www.garching.de could still view the municipal page. An update on February 14 noted that the website of the Munich district office (Landratsamt München‑Land) had also been affected, with the domain www.landkreis-muenchen.de intermittently unreachable since the previous day.

A separate report from the same day described a broader hacker incident targeting the Bavarian state government, in which the state’s IT security agency indicated that a prorussian hacktivist motive was suspected. The state government’s websites, including the Staatskanzlei and the Ministry for Digital Affairs, were hit on the preceding Thursday, but officials confirmed that no data were exfiltrated, encrypted, or otherwise damaged. The report also noted that the Munich district office and the city of Garching experienced website outages lasting roughly one day. Investigations into the incidents were said to be ongoing, with the state’s IT security agency planning to hand the case over to police after completing its analysis.

As a result of the DDoS pressure, both the district office and Garching websites remained unavailable to users for extended periods, disrupting public access to online information and services. The hosting provider’s mitigation efforts, which included the temporary redirect for Garching, gradually restored normal operation, though the district office’s site continued to depend on the upstream network provider’s stability. No breach of confidential data, alteration of content, or financial loss was reported for either entity, and the attacks were confined to service availability. Authorities emphasized that the response was focused on restoring service, gathering forensic evidence, and preparing the case for potential criminal proceedings.

Sources

Sources available to members: 2 sources.

CSIDB