Menu
Browse

Cyber Incident Victim: Kumla kommun

Date:

Nov 2024

Location:

Sweden

Summary

A cyberattack targeted Kumla kommun, resulting in unauthorized access to nearly all its systems and the theft of a significant volume of data, which was subsequently published on Darknet. The municipality shut down its IT infrastructure, transitioned to analog operations, and received a ransom demand, though the specific nature of the compromised information remains unclear. Following the breach, external connections were restricted to prevent further data exfiltration, and the incident was reported to relevant authorities including the police and data protection agencies. Efforts are underway to gradually restore system functionality while assessing the scope of the published data, which is acknowledged to likely include all stolen information from the attack.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In early November 2024, Kumla kommun experienced a significant cyberattack that compromised its IT infrastructure. The attack, occurring at the start of the week preceding November 4, allowed threat actors to access nearly all systems within the municipal environment, as confirmed by Kommundirektör Gunilla Mueller Prabin. Following the breach, the municipality took immediate containment measures by shutting down its entire IT network and transitioning to analog operations to prevent further unauthorized access. Attackers issued a ransom demand, though the specific nature of the compromised data remained unclear at this initial stage. The disruption forced municipal services to operate without digital systems, significantly impacting administrative functions and service delivery.

Cyber Incident Image

By November 15, Kumla kommun confirmed that a substantial volume of stolen data had been published on Darknet, likely representing all information exfiltrated during the attack. Municipal Director Gabriella Mueller Prabin acknowledged the severity of the incident, emphasizing the potential distress caused to employees and citizens by the exposure of sensitive data. The municipality reported the breach to the Swedish Authority for Privacy Protection (IMY), the Swedish Civil Contingencies Agency (MSB), and the Police, fulfilling regulatory obligations. Technical countermeasures included restricting external network connections to block attackers from stealing additional data. Recovery efforts progressed gradually, with the municipality announcing on November 15 that it had begun systematically restoring access to its systems while continuing to assess the full scope of the data exposure. The incident underscored operational vulnerabilities and highlighted the broader societal risks associated with municipal cyberattacks.

Sources
Sources available to members
1 source