CSIDB logo
Incident

Върховен административен съд

Incident posture

Attack window
Jan 2025
Location
Bulgaria
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-02 19:03

Linked entities

Victim
Върховен административен съд
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2025
Discovered
Undetermined
Disclosed
Jan 2025
Resolved
Pending

Summary

The Supreme Administrative Court was hit by a ransomware attack that encrypted its administrative and informational data, with the perpetrators demanding a ransom. According to the court’s acting chairman, one third of the system has been fully restored and no information has been lost or altered, noting that paper records prevent any data tampering. The justice minister said the institution will not pay the ransom, labeling the act a criminal offense, and that an investigation is underway by the relevant authorities.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

During the week of the attack, hackers targeted the Върховен административен съд and demanded a ransom. The acting chairman of the court, Georgi Cholakov, stated that one third of the system had been fully restored. He also said that no information had been lost as a result of the incident. Cholakov explained that software had entered the court’s system and subsequently encrypted all of its business‑information data. He suggested that the possible cause might be human error. He noted that tampering with data could not occur because paper records are also used when reviewing cases.

The Minister of Justice, Georgi Georgiev, said he would request a check of the incident. Cholakov added that paying a ransom was impossible and that such an act could only yield results in private companies, not in state institutions. He characterized the event as a completed crime and said an investigation was underway in the ГДБОП. Georgiev urged for urgent measures and a technological audit to identify what was not functioning properly. He observed that cyberattacks against government institutions occur worldwide. The statement concluded with the remark that no further information could be provided at that time.

Sources

Sources available to members: 1 source.

CSIDB