Wirtschaftsförderung Bremen
Incident posture
Linked entities
- Victim
- Wirtschaftsförderung Bremen
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
A pro-Russian hacker group known as "NoName057(16)" claimed responsibility for a series of Distributed Denial-of-Service (DDoS) attacks targeting public authority websites in Bremen, including those of the Police, the Health Senator's office, and the Wirtschaftsförderung. While earlier attempts against the health and economic development sites in January had no impact, an attack successfully overwhelmed the Police website's contact form with up to 18,000 requests per minute, rendering several administrative pages inaccessible or difficult to reach for over an hour. The federal police (Bundeskriminalamt) initiated central investigations into the hacker collective. Although no data was stolen or compromised, authorities deployed a software update to automatically throttle or deactivate search and contact functions during heavy traffic to prevent future successful incidents.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In January 2025, two distributed denial-of-service (DDoS) attacks were directed at websites of Bremen authorities, including the site of Wirtschaftsförderung Bremen and the site of the Gesundheitssenatorin (Health Senator). These attacks followed the same pattern that had been observed in earlier incidents: large volumes of simultaneous requests were sent to the targeted web servers in an attempt to overwhelm them. According to the Senate's response to a small inquiry filed by the CDU parliamentary group, neither attack had any actual impact on the availability or functionality of the affected sites. The Senate emphasized that these attempts were unsuccessful, in contrast to the later February attack on the Bremen Police website, which was the first to achieve a disruptive effect. Bremen as a whole is considered a significant target for various forms of cyberattacks, and DDoS attempts against public-sector websites are part of a broader pattern of activity directed at German institutions.
A more consequential DDoS attack occurred on February 12, 2025, targeting the Bremen Police website. The contact form embedded on the police site was bombarded with requests at a rate of up to 18,000 requests per minute. The volume of incoming traffic exceeded the capacity of the underlying server, causing it to fail. As a result, the websites of the entire Bremen administration became partially unreachable or only accessible with significant delays between approximately 7:00 a.m. and 8:30 a.m. Although the attack itself continued until the evening of that day, the Senate indicated that defensive measures successfully mitigated the disruption after roughly two hours. The IT service provider Dataport, which is responsible for the information technology infrastructure of Bremen's authorities, identified the contact form and the local search function on the police website as the entry points used by the attackers and subsequently disabled both features.
Almost simultaneously with the unfolding attack, around 9:00 a.m., the Bremen authorities received a warning from the German Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI) regarding the impending incident. The source of this advance warning was the public messaging activities of the pro-Russian hacker group "NoName057(16)" on the Telegram messaging service, where the group regularly publishes its current attack targets. The group claimed responsibility for the cyberattack on the same day. NoName057(16) has been active since the onset of the war against Ukraine and has been linked to multiple cyber operations against targets in Ukraine, the United States, and several European countries. The group's stated objectives include impairing the operational capacity of entities that support Ukraine and disseminating Russian propaganda. Following the incident, the German Federal Criminal Police Office (Bundeskriminalamt, BKA) took over the central investigation into the activities of the hacker group.
In response to the February attack, Dataport deployed a software update later in the same month aimed at preventing similar future incidents. The update introduced an automatic throttling mechanism for incoming requests directed at internal search functions and contact forms. In cases of repeated or excessive requests, the system can now throttle the request rate and, if necessary, completely deactivate the affected functions. The Senate confirmed that, despite the disruption, the February attack did not result in any data theft, data loss, or compromise of information. Additional unrelated incidents were also reported in Bremen's administrative IT environment during this period. In late February, a phishing attack targeting employees of the school administration (Schulverwaltung) succeeded in compromising two accounts of the mail system. The compromised accounts were subsequently used to distribute spam emails using the sender address @schulverwaltung.bremen.de. Earlier, in mid-December 2024, an incident described as botnet spamming had already occurred, in which contact forms on affected websites were manipulated to send out large volumes of unsolicited messages.
Sources
Sources available to members: 1 source.