Menu
Browse

Cyber Incident Victim: Landespolizei Mecklenburg-Vorpommern

Date:

Jun 2025

Location:

Germany

Summary

An attempted hacker attack on the service smartphones of the Landespolizei Mecklenburg-Vorpommern via the server that connects these devices prompted investigations and analyses on the computers that manage and protect the phones. As a result, the mPol handsets could not be used fully for several days, forcing officers to revert to radio‑based queries for vehicle registrations and identification checks while still being able to use the phones for calls. The state data protection commissioner was informed and an investigative procedure was initiated.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On June 1, 2025, a press release from the Mecklenburg-Vorpommern state government reported an attempted hacker attack on the service smartphones of the Landespolizei Mecklenburg-Vorpommern. The attack targeted the server that networks these smartphones. As a result, investigations and analyses were launched on the computer servers that control and protect the police service smartphones. During the ongoing investigations, the so‑called mPol (mobile police) devices could not be used to their full extent for several days. While the mPol phones remained capable of making and receiving telephone calls, their online query functions were unavailable. Officers therefore had to revert to the pre‑mPol method of submitting vehicle license plate numbers or identification checks via radio to the police station, where the information was retrieved on a desktop computer and returned by radio.

Cyber Incident Image

The state’s data protection and freedom of information commissioner was notified of the incident. An official investigative procedure was initiated following the notification. Technical teams continued to examine the affected servers to determine the scope and nature of the attempted intrusion. Containment measures ensured that the smartphones could still be used for voice communications while the online services were restricted. No further details about the attacker or the specific vulnerability were disclosed in the release. The situation remained under review until the investigations were completed and normal mPol functionality could be restored.

Sources
Sources available to members
1 source